2016 CVE Vulnerabilities

10,645 CVEs published in 2016.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2016-10995CRITICAL9.8The Tevolution plugin before 2.3.0 for WordPress has arbitrary file upload via single_upload.php or single-upload.php.
CVE-2016-10972CRITICAL9.8The newspaper theme before 6.7.2 for WordPress has a lack of options access control via td_ajax_update_panel.
CVE-2016-10971CRITICAL9.8The MemberSonic Lite plugin before 1.302 for WordPress has incorrect login access control because only knowlewdge of an ...
CVE-2016-10955CRITICAL9.8The cysteme-finder plugin before 1.4 for WordPress has unrestricted file upload because of incorrect session tracking.
CVE-2016-10954CRITICAL9.8The Neosense theme before 1.8 for WordPress has qquploader unrestricted file upload.
CVE-2016-10942CRITICAL9.8The podlove-podcasting-plugin-for-wordpress plugin before 2.3.16 for WordPress has SQL injection via the insert_id param...
CVE-2016-7398CRITICAL9.8A type confusion vulnerability in the merge_param() function of php_http_params.c in PHP's pecl-http extension 3.1.0beta...
CVE-2016-10764CRITICAL9.8In the Linux kernel before 4.9.6, there is an off by one in the drivers/mtd/spi-nor/cadence-quadspi.c cqspi_setup_flash(...
CVE-2016-10749CRITICAL9.8parse_string in cJSON.c in cJSON before 2016-10-02 has a buffer over-read, as demonstrated by a string that begins with ...
CVE-2016-1585CRITICAL9.8In all versions of AppArmor mount rules are accidentally widened when compiled.
CVE-2016-9063CRITICAL9.8An integer overflow during the parsing of XML using the Expat library. This vulnerability affects Firefox < 50.
CVE-2016-10541CRITICAL9.8The npm module "shell-quote" 1.6.0 and earlier cannot correctly escape ">" and "<" operator used for redirection in shel...
CVE-2016-10722CRITICAL9.8partclone.fat in Partclone before 0.2.88 is prone to a heap-based buffer overflow vulnerability due to insufficient vali...
CVE-2016-8717CRITICAL9.8An exploitable Use of Hard-coded Credentials vulnerability exists in the Moxa AWK-3131A Wireless Access Point running fi...
CVE-2016-0898CRITICAL10MySQL for PCF tiles 1.7.x before 1.7.10 were discovered to log the AWS access key in plaintext. These credentials were l...
CVE-2016-6813CRITICAL9.8Apache CloudStack 4.1 to 4.8.1.0 and 4.9.0.0 contain an API call designed to allow a user to register for the developer ...
CVE-2016-5018CRITICAL9.1In Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 a malici...
CVE-2016-8731CRITICAL9.8Hard-coded FTP credentials (r:r) are included in the Foscam C1 running firmware 1.9.1.12. Knowledge of these credentials...
CVE-2016-7836CRITICAL9.8SKYSEA Client View Ver.11.221.03 and earlier allows remote code execution via a flaw in processing authentication on the...
CVE-2016-6087CRITICAL9.8IBM Domino 8.5 and 9.0 could allow an attacker to steal credentials using multiple sessions and large amounts of data us...
CVE-2016-0761CRITICAL9.8Cloud Foundry Garden-Linux versions prior to v0.333.0 and Elastic Runtime 1.6.x version prior to 1.6.17 contain a flaw i...
CVE-2016-9843CRITICAL9.8The crc32_big function in crc32.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via v...
CVE-2016-9841CRITICAL9.8inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointe...
CVE-2016-2173CRITICAL9.8org.springframework.core.serializer.DefaultDeserializer in Spring AMQP before 1.5.5 allows remote attackers to execute a...
CVE-2016-1555CRITICAL9.8(1) boardData102.php, (2) boardData103.php, (3) boardDataJP.php, (4) boardDataNA.php, and (5) boardDataWW.php in Netgear...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now