2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-15057 | CRITICAL | 9.9 | 3.7% | Jan 26, 2026 | ** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in a Command ('Command Injection') vuln... |
| CVE-2016-20023 | MEDIUM | 6.5 | 0.3% | Dec 5, 2025 | In CKSource CKFinder before 2.5.0.1 for ASP.NET, authenticated users could download any file from the server if the corr... |
| CVE-2016-15056 | HIGH | 8.7 | 0.6% | Nov 14, 2025 | Ubee EVW3226 cable modem/routers firmware versions up to and including 1.0.20 store configuration backup files in the we... |
| CVE-2016-15055 | HIGH | 8.7 | 0.8% | Nov 12, 2025 | JVC VN-T IP-camera models firmware versions up to 2016-08-22 (confirmed on the VN-T216VPRU model) contain a directory tr... |
| CVE-2016-15054 | — | — | — | Nov 3, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as it is a downstream effect ... |
| CVE-2016-15053 | MEDIUM | 5.4 | 0.4% | Oct 30, 2025 | Nagios XI versions prior to 5.2.4 are vulnerable to cross-site scripting (XSS) via the “My Reports” listing of the web i... |
| CVE-2016-15052 | MEDIUM | 5.4 | 0.4% | Oct 30, 2025 | Nagios XI versions prior to 5.2.4 are vulnerable to cross-site scripting (XSS) via the Menu System of the web interface.... |
| CVE-2016-15051 | MEDIUM | 5.4 | 0.4% | Oct 30, 2025 | Nagios XI versions prior to 5.2.4 are vulnerable to cross-site scripting (XSS) via the Reports interface through values ... |
| CVE-2016-15050 | HIGH | 8.8 | 1.0% | Oct 30, 2025 | Nagios XI versions prior to 5.2.4 contain a SQL injection vulnerability in the notification search functionality. User-s... |
| CVE-2016-15049 | MEDIUM | 5.4 | 0.5% | Oct 30, 2025 | Nagios Log Server versions prior to 1.4.2 are vulnerable to cross-site scripting (XSS) in the Dashboards section when re... |
| CVE-2016-15048 | CRITICAL | 9.8 | 7.2% | Oct 22, 2025 | AMTT Hotel Broadband Operation System (HiBOS) contains an unauthenticated command injection vulnerability in the /manage... |
| CVE-2016-15047 | HIGH | 8.7 | 4.0% | Oct 9, 2025 | AVTECH devices that include the CloudSetup.cgi management endpoint are vulnerable to authenticated OS command injection.... |
| CVE-2016-15046 | HIGH | 8.6 | 0.9% | Jul 25, 2025 | A client-side remote code execution vulnerability exists in Hanwha Techwin Smart Security Manager (SSM) versions 1.32 an... |
| CVE-2016-15044 | CRITICAL | 9.3 | 1.4% | Jul 23, 2025 | A remote code execution vulnerability exists in Kaltura versions prior to 11.1.0-2 due to unsafe deserialization of user... |
| CVE-2016-15045 | HIGH | 8.5 | 0.4% | Jul 23, 2025 | A local privilege escalation vulnerability exists in lastore-daemon, the system package manager daemon used in Deepin Li... |
| CVE-2016-15043 | CRITICAL | 9.8 | 10.0% | Jul 19, 2025 | The WP Mobile Detector plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation ... |
| CVE-2016-3399 | — | — | — | Jun 19, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2016-10408 | HIGH | 7.8 | 0.1% | Nov 26, 2024 | QSEE will randomly experience a fatal error during execution due to speculative instruction fetches from device memory. ... |
| CVE-2016-10394 | HIGH | 7.8 | 0.1% | Nov 26, 2024 | Initial xbl_sec revision does not have all the debug policy features and critical checks. |
| CVE-2016-15042 | CRITICAL | 9.8 | 5.5% | Oct 16, 2024 | The Frontend File Manager (versions < 4.0), N-Media Post Front-end Form (versions < 1.1) plugins for WordPress are vulne... |
| CVE-2016-15041 | MEDIUM | 6.1 | 1.2% | Oct 16, 2024 | The MainWP Dashboard – The Private WordPress Manager for Multiple Website Maintenance plugin for WordPress is vulnerable... |
| CVE-2016-15040 | CRITICAL | 9.8 | 0.5% | Oct 16, 2024 | The Kento Post View Counter plugin for WordPress is vulnerable to SQL Injection via the 'kento_pvc_geo' parameter in ver... |
| CVE-2016-15039 | MEDIUM | 6.3 | 0.4% | Jul 11, 2024 | A vulnerability classified as critical was found in mhuertos phpLDAPadmin up to 665dbc2690ebeb5392d38f1fece0a654225a0b38... |
| CVE-2016-20022 | HIGH | 8.4 | 0.2% | Jun 27, 2024 | In the Linux kernel before 4.8, usb_parse_endpoint in drivers/usb/core/config.c does not validate the wMaxPacketSize fie... |
| CVE-2016-15038 | MEDIUM | 6.5 | 0.8% | Apr 1, 2024 | A vulnerability, which was classified as critical, was found in NUUO NVRmini 2 up to 3.0.8. Affected is an unknown funct... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now