2016 CVE Vulnerabilities

10,647 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-15057CRITICAL9.9** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in a Command ('Command Injection') vuln...
CVE-2016-20023MEDIUM6.5In CKSource CKFinder before 2.5.0.1 for ASP.NET, authenticated users could download any file from the server if the corr...
CVE-2016-15056HIGH8.7Ubee EVW3226 cable modem/routers firmware versions up to and including 1.0.20 store configuration backup files in the we...
CVE-2016-15055HIGH8.7JVC VN-T IP-camera models firmware versions up to 2016-08-22 (confirmed on the VN-T216VPRU model) contain a directory tr...
CVE-2016-15054Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as it is a downstream effect ...
CVE-2016-15053MEDIUM5.4Nagios XI versions prior to 5.2.4 are vulnerable to cross-site scripting (XSS) via the “My Reports” listing of the web i...
CVE-2016-15052MEDIUM5.4Nagios XI versions prior to 5.2.4 are vulnerable to cross-site scripting (XSS) via the Menu System of the web interface....
CVE-2016-15051MEDIUM5.4Nagios XI versions prior to 5.2.4 are vulnerable to cross-site scripting (XSS) via the Reports interface through values ...
CVE-2016-15050HIGH8.8Nagios XI versions prior to 5.2.4 contain a SQL injection vulnerability in the notification search functionality. User-s...
CVE-2016-15049MEDIUM5.4Nagios Log Server versions prior to 1.4.2 are vulnerable to cross-site scripting (XSS) in the Dashboards section when re...
CVE-2016-15048CRITICAL9.8AMTT Hotel Broadband Operation System (HiBOS) contains an unauthenticated command injection vulnerability in the /manage...
CVE-2016-15047HIGH8.7AVTECH devices that include the CloudSetup.cgi management endpoint are vulnerable to authenticated OS command injection....
CVE-2016-15046HIGH8.6A client-side remote code execution vulnerability exists in Hanwha Techwin Smart Security Manager (SSM) versions 1.32 an...
CVE-2016-15044CRITICAL9.3A remote code execution vulnerability exists in Kaltura versions prior to 11.1.0-2 due to unsafe deserialization of user...
CVE-2016-15045HIGH8.5A local privilege escalation vulnerability exists in lastore-daemon, the system package manager daemon used in Deepin Li...
CVE-2016-15043CRITICAL9.8The WP Mobile Detector plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation ...
CVE-2016-3399Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2016-10408HIGH7.8QSEE will randomly experience a fatal error during execution due to speculative instruction fetches from device memory. ...
CVE-2016-10394HIGH7.8Initial xbl_sec revision does not have all the debug policy features and critical checks.
CVE-2016-15042CRITICAL9.8The Frontend File Manager (versions < 4.0), N-Media Post Front-end Form (versions < 1.1) plugins for WordPress are vulne...
CVE-2016-15041MEDIUM6.1The MainWP Dashboard – The Private WordPress Manager for Multiple Website Maintenance plugin for WordPress is vulnerable...
CVE-2016-15040CRITICAL9.8The Kento Post View Counter plugin for WordPress is vulnerable to SQL Injection via the 'kento_pvc_geo' parameter in ver...
CVE-2016-15039MEDIUM6.3A vulnerability classified as critical was found in mhuertos phpLDAPadmin up to 665dbc2690ebeb5392d38f1fece0a654225a0b38...
CVE-2016-20022HIGH8.4In the Linux kernel before 4.8, usb_parse_endpoint in drivers/usb/core/config.c does not validate the wMaxPacketSize fie...
CVE-2016-15038MEDIUM6.5A vulnerability, which was classified as critical, was found in NUUO NVRmini 2 up to 3.0.8. Affected is an unknown funct...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now