2016 CVE Vulnerabilities

10,648 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-10761——Logitech Unifying devices before 2016-02-26 allow keystroke injection, bypassing encryption, aka MouseJack.
CVE-2016-7404——OpenStack Magnum passes OpenStack credentials into the Heat templates creating its instances. While these should just be...
CVE-2016-10760——On Seowon Intech routers, there is a Command Injection vulnerability in diagnostic.cgi via shell metacharacters in the p...
CVE-2016-10759——The Xinha plugin in Precurio 2.1 allows Directory Traversal, with resultant arbitrary code execution, via ExtendedFileMa...
CVE-2016-10758——PHPKIT 1.6.6 allows arbitrary File Upload, as demonstrated by a .php file to pkinc/admin/mediaarchive.php and pkinc/func...
CVE-2016-10757——In Redaxo 5.2.0, the cron management of the admin panel suffers from CSRF that leads to arbitrary Remote Code Execution ...
CVE-2016-10756——Kliqqi 3.0.0.5 allows CSRF with resultant Arbitrary File Upload because module.php?module=upload can be used to configur...
CVE-2016-10755——AbanteCart 1.2.8 allows SQL Injection via the source_language parameter to admin/controller/pages/localisation/language....
CVE-2016-10754——modules/Calendar/Activity.php in Vtiger CRM 6.5.0 allows SQL injection via the contactidlist parameter.
CVE-2016-10753——e107 2.1.2 allows PHP Object Injection with resultant SQL injection, because usersettings.php uses unserialize without a...
CVE-2016-10752——serendipity_moveMediaDirectory in Serendipity 2.0.3 allows remote attackers to upload and execute arbitrary PHP code bec...
CVE-2016-10751——osClass 3.6.1 allows oc-admin/plugins.php Directory Traversal via the plugin parameter. This is exploitable for remote P...
CVE-2016-8900——Exponent CMS version 2.3.9 suffers from a Object Injection vulnerability in framework/modules/core/controllers/expTagCon...
CVE-2016-8898——Exponent CMS version 2.3.9 suffers from a sql injection vulnerability in framework/modules/ecommerce/controllers/cartCon...
CVE-2016-10245——Insufficient sanitization of the query parameter in templates/html/search_opensearch.php could lead to reflected cross-s...
CVE-2016-8899——Exponent CMS version 2.3.9 suffers from a Object Injection vulnerability in framework/modules/core/controllers/expCatCon...
CVE-2016-8897——Exponent CMS version 2.3.9 suffers from a sql injection vulnerability in framework/modules/help/controllers/helpControll...
CVE-2016-7550——asterisk 13.10.0 is affected by: denial of service issues in asterisk. The impact is: cause a denial of service (remote)...
CVE-2016-9969——In libwebp 0.5.1, there is a double free bug in libwebpmux.
CVE-2016-8901——b2evolution 6.7.6 suffer from an Object Injection vulnerability in /htsrv/call_plugin.php.
CVE-2016-10750——In Hazelcast before 3.11, the cluster join procedure is vulnerable to remote code execution via Java deserialization. If...
CVE-2016-7043MEDIUM5.9It has been reported that KIE server and Busitess Central before version 7.21.0.Final contain username and password as p...
CVE-2016-7151——Capstone 3.0.4 has an out-of-bounds vulnerability (SEGV caused by a read memory access) in X86_insn_reg_intel in arch/X8...
CVE-2016-10719——TP-Link Archer CR-700 1.0.6 devices have an XSS vulnerability that can be introduced into the admin account through a DH...
CVE-2016-1600——The ServiceNow driver in NetIQ Identity Manager versions prior to 4.6 are susceptible to an information disclosure vulne...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now