2016 CVE Vulnerabilities

10,647 CVEs published in 2016.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2016-11000CRITICAL9.8The wp-ultimate-exporter plugin through 1.1 for WordPress has SQL injection via the export_type_name parameter.
CVE-2016-10995CRITICAL9.8The Tevolution plugin before 2.3.0 for WordPress has arbitrary file upload via single_upload.php or single-upload.php.
CVE-2016-10972CRITICAL9.8The newspaper theme before 6.7.2 for WordPress has a lack of options access control via td_ajax_update_panel.
CVE-2016-10971CRITICAL9.8The MemberSonic Lite plugin before 1.302 for WordPress has incorrect login access control because only knowlewdge of an ...
CVE-2016-10955CRITICAL9.8The cysteme-finder plugin before 1.4 for WordPress has unrestricted file upload because of incorrect session tracking.
CVE-2016-10954CRITICAL9.8The Neosense theme before 1.8 for WordPress has qquploader unrestricted file upload.
CVE-2016-10942CRITICAL9.8The podlove-podcasting-plugin-for-wordpress plugin before 2.3.16 for WordPress has SQL injection via the insert_id param...
CVE-2016-7398CRITICAL9.8A type confusion vulnerability in the merge_param() function of php_http_params.c in PHP's pecl-http extension 3.1.0beta...
CVE-2016-10764CRITICAL9.8In the Linux kernel before 4.9.6, there is an off by one in the drivers/mtd/spi-nor/cadence-quadspi.c cqspi_setup_flash(...
CVE-2016-10749CRITICAL9.8parse_string in cJSON.c in cJSON before 2016-10-02 has a buffer over-read, as demonstrated by a string that begins with ...
CVE-2016-1585CRITICAL9.8In all versions of AppArmor mount rules are accidentally widened when compiled.
CVE-2016-9063CRITICAL9.8An integer overflow during the parsing of XML using the Expat library. This vulnerability affects Firefox < 50.
CVE-2016-10541CRITICAL9.8The npm module "shell-quote" 1.6.0 and earlier cannot correctly escape ">" and "<" operator used for redirection in shel...
CVE-2016-10722CRITICAL9.8partclone.fat in Partclone before 0.2.88 is prone to a heap-based buffer overflow vulnerability due to insufficient vali...
CVE-2016-8717CRITICAL9.8An exploitable Use of Hard-coded Credentials vulnerability exists in the Moxa AWK-3131A Wireless Access Point running fi...
CVE-2016-0898CRITICAL10MySQL for PCF tiles 1.7.x before 1.7.10 were discovered to log the AWS access key in plaintext. These credentials were l...
CVE-2016-6813CRITICAL9.8Apache CloudStack 4.1 to 4.8.1.0 and 4.9.0.0 contain an API call designed to allow a user to register for the developer ...
CVE-2016-1265CRITICAL9.8A remote unauthenticated network based attacker with access to Junos Space may execute arbitrary code on Junos Space or ...
CVE-2016-5018CRITICAL9.1In Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 a malici...
CVE-2016-8731CRITICAL9.8Hard-coded FTP credentials (r:r) are included in the Foscam C1 running firmware 1.9.1.12. Knowledge of these credentials...
CVE-2016-7836CRITICAL9.8SKYSEA Client View Ver.11.221.03 and earlier allows remote code execution via a flaw in processing authentication on the...
CVE-2016-6087CRITICAL9.8IBM Domino 8.5 and 9.0 could allow an attacker to steal credentials using multiple sessions and large amounts of data us...
CVE-2016-0761CRITICAL9.8Cloud Foundry Garden-Linux versions prior to v0.333.0 and Elastic Runtime 1.6.x version prior to 1.6.17 contain a flaw i...
CVE-2016-9843CRITICAL9.8The crc32_big function in crc32.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via v...
CVE-2016-9841CRITICAL9.8inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointe...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now