2016 CVE Vulnerabilities

10,645 CVEs published in 2016.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2016-1000107MEDIUM6.1inets in Erlang possibly 22.1 and earlier follows RFC 3875 section 4.1.18 and therefore does not protect applications fr...
CVE-2016-1000108MEDIUM6.1yaws before 2.0.4 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect...
CVE-2016-1000110MEDIUM6.1The CGIHandler class in Python before 2.7.12 does not protect against the HTTP_PROXY variable name clash in a CGI script...
CVE-2016-9271MEDIUM5.4Cloudera Manager 5.7.x before 5.7.6, 5.8.x before 5.8.4, and 5.9.x before 5.9.1 allows XSS in the help search feature.
CVE-2016-6353MEDIUM6.5Cloudera Search in CDH before 5.7.0 allows unauthorized document access because Solr Queries by document id can bypass S...
CVE-2016-3192MEDIUM6.5Cloudera Manager 5.x before 5.7.1 places Sensitive Data in cleartext Readable Files.
CVE-2016-3131MEDIUM6.5Cloudera CDH before 5.6.1 allows authorization bypass via direct internal API calls.
CVE-2016-1000236MEDIUM4.4Node-cookie-signature before 1.0.6 is affected by a timing attack due to the type of comparison used.
CVE-2016-1000037MEDIUM6.1Pagure: XSS possible in file attachment endpoint
CVE-2016-4289MEDIUM5.5A stack based buffer overflow vulnerability exists in the method receiving data from SysTreeView32 control of the GMER 2...
CVE-2016-11016MEDIUM6.1NETGEAR JNR1010 devices before 1.0.0.32 allow webproc?getpage= XSS.
CVE-2016-11015MEDIUM6.5NETGEAR JNR1010 devices before 1.0.0.32 allow cgi-bin/webproc CSRF via the :InternetGatewayDevice.X_TWSZ-COM_URL_Filter....
CVE-2016-11013MEDIUM6.1The wp-listings plugin before 2.0.2 for WordPress has includes/views/single-listing.php XSS.
CVE-2016-11012MEDIUM5.4The sola-support-tickets plugin before 3.13 for WordPress has incorrect access control for /wp-admin with resultant XSS.
CVE-2016-11011MEDIUM6.5The wp-invoice plugin before 4.1.1 for WordPress has wpi_update_user_option privilege escalation.
CVE-2016-11010MEDIUM5.3The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_twocheckout payer metadata update...
CVE-2016-11009MEDIUM5.3The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_interkassa payer metadata updates...
CVE-2016-11008MEDIUM5.3The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_paypal payer metadata updates.
CVE-2016-11007MEDIUM5.3The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control over wpi_user_id for invoice retrieval.
CVE-2016-11006MEDIUM5.3The wp-invoice plugin before 4.1.1 for WordPress has incorrect access control for admin_init settings changes.
CVE-2016-11005MEDIUM6.1The instalinker plugin before 1.1.2 for WordPress has includes/instalinker-admin-preview.php?client_id= XSS.
CVE-2016-11001MEDIUM6.1The user-submitted-posts plugin before 20160215 for WordPress has XSS via the user-submitted-content field.
CVE-2016-10999MEDIUM6.1The Goodnews theme through 2016-02-28 for WordPress has XSS via the s parameter.
CVE-2016-10998MEDIUM6.1The ocim-mp3 plugin through 2016-03-07 for WordPress has wp-content/plugins/ocim-mp3/source/pages.php?id= XSS.
CVE-2016-10997MEDIUM6.5The beauty-premium theme 1.0.8 for WordPress has CSRF with resultant arbitrary file upload in includes/sendmail.php.

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now