2016 CVE Vulnerabilities

10,645 CVEs published in 2016.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2016-2032HIGH7.5A vulnerability exists in the Aruba AirWave Management Platform 8.x prior to 8.2 in the management interface of an under...
CVE-2016-4761HIGH8.8WebKitGTK+ before 2.14.0: A use-after-free vulnerability can allow remote attackers to cause a DoS
CVE-2016-6592HIGH7.8A vulnerability was found in Symantec Norton Download Manager versions prior to 5.6. A remote user can create a speciall...
CVE-2016-5311HIGH7.8A Privilege Escalation vulnerability exists in Symantec Norton Antivirus, Norton AntiVirus with Backup, Norton Security,...
CVE-2016-6593HIGH7.8A code-execution vulnerability exists during startup in jhi.dll and otpiha.dll in Symantec VIP Access Desktop before 2.2...
CVE-2016-6591HIGH7.1A security bypass vulnerability exists in Symantec Norton App Lock 1.0.3.186 and earlier if application pinning is enabl...
CVE-2016-6590HIGH7.8A privilege escalation vulnerability exists when loading DLLs during boot up and reboot in Symantec IT Management Suite ...
CVE-2016-1000104HIGH8.8A security Bypass vulnerability exists in the FcgidPassHeader Proxy in mod_fcgid through 2016-07-07.
CVE-2016-5724HIGH7.5Cloudera CDH before 5.9 has Potentially Sensitive Information in Diagnostic Support Bundles.
CVE-2016-4572HIGH8.8In Cloudera CDH before 5.7.1, Impala REVOKE ALL ON SERVER commands do not revoke all privileges.
CVE-2016-5285HIGH7.5A Null pointer dereference vulnerability exists in Mozilla Network Security Services due to a missing NULL check in PK11...
CVE-2016-11004HIGH8.8The Elegant Themes Monarch plugin before 1.2.7 for WordPress has privilege escalation.
CVE-2016-11003HIGH8.8The Elegant Themes Bloom plugin before 1.1.1 for WordPress has privilege escalation.
CVE-2016-11002HIGH8.8The Elegant Themes Extra theme before 1.2.4 for WordPress has privilege escalation.
CVE-2016-10991HIGH7.5The imdb-widget plugin before 1.0.9 for WordPress has Local File Inclusion.
CVE-2016-10989HIGH8.8The leenkme plugin before 2.6.0 for WordPress has wp-admin/admin.php?page=leenkme_facebook CSRF.
CVE-2016-10982HIGH8.8The kento-post-view-counter plugin through 2.8 for WordPress has wp-admin/admin.php?page=kentopvc_settings CSRF.
CVE-2016-10978HIGH8.8The fossura-tag-miner plugin before 1.1.5 for WordPress has CSRF.
CVE-2016-10974HIGH8.8The fluid-responsive-slideshow plugin before 2.2.7 for WordPress has frs_save CSRF with resultant stored XSS.
CVE-2016-10968HIGH8.8The peepso-core plugin before 1.6.1 for WordPress has PeepSoProfilePreferencesAjax->save() privilege escalation.
CVE-2016-10966HIGH7.5The real3d-flipbook-lite plugin 1.0 for WordPress has bookName=../ directory traversal for file upload.
CVE-2016-10965HIGH7.5The real3d-flipbook-lite plugin 1.0 for WordPress has deleteBook=../ directory traversal for file deletion.
CVE-2016-10960HIGH8.8The wsecure plugin before 2.4 for WordPress has remote code execution via shell metacharacters in the wsecure-config.php...
CVE-2016-10958HIGH7.5The estatik plugin before 2.3.0 for WordPress has unauthenticated arbitrary file upload via es_media_images[] to wp-admi...
CVE-2016-10956HIGH7.5The mail-masta plugin 1.0 for WordPress has local file inclusion in count_of_send.php and csvexport.php.

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now