2016 CVE Vulnerabilities

10,647 CVEs published in 2016.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2016-10965HIGH7.5The real3d-flipbook-lite plugin 1.0 for WordPress has deleteBook=../ directory traversal for file deletion.
CVE-2016-10960HIGH8.8The wsecure plugin before 2.4 for WordPress has remote code execution via shell metacharacters in the wsecure-config.php...
CVE-2016-10958HIGH7.5The estatik plugin before 2.3.0 for WordPress has unauthenticated arbitrary file upload via es_media_images[] to wp-admi...
CVE-2016-10956HIGH7.5The mail-masta plugin 1.0 for WordPress has local file inclusion in count_of_send.php and csvexport.php.
CVE-2016-10951HIGH7.2The fs-shopping-cart plugin 2.07.02 for WordPress has SQL injection via the pid parameter.
CVE-2016-10950HIGH8.8The sirv plugin before 1.3.2 for WordPress has SQL injection via the id parameter.
CVE-2016-10949HIGH8.8The Relevanssi Premium plugin before 1.14.6.1 for WordPress has SQL injection with resultant unsafe unserialization.
CVE-2016-10948HIGH8.1The Post Indexer plugin before 3.0.6.2 for WordPress has incorrect handling of data passed to the unserialize function.
CVE-2016-10947HIGH7.2The Post Indexer plugin before 3.0.6.2 for WordPress has SQL injection via the period parameter by a super admin.
CVE-2016-10946HIGH8.8The wp-d3 plugin before 2.4.1 for WordPress has CSRF.
CVE-2016-10945HIGH8.8The PageLines theme 1.1.4 for WordPress has wp-admin/admin-post.php?page=pagelines CSRF.
CVE-2016-10944HIGH8.8The multisite-post-duplicator plugin before 1.1.3 for WordPress has wp-admin/tools.php?page=mpd CSRF.
CVE-2016-10943HIGH7.2The zx-csv-upload plugin 1 for WordPress has SQL injection via the id parameter.
CVE-2016-10940HIGH7.2The zm-gallery plugin 1.0 for WordPress has SQL injection via the order parameter.
CVE-2016-10939HIGH7.2The xtremelocator plugin 1.5 for WordPress has SQL injection via the id parameter.
CVE-2016-10937HIGH7.5IMAPFilter through 2.6.12 does not validate the hostname in an SSL certificate.
CVE-2016-10905HIGH7.8An issue was discovered in fs/gfs2/rgrp.c in the Linux kernel before 4.8. A use-after-free is caused by the functions gf...
CVE-2016-10884HIGH8.8The simple-membership plugin before 3.3.3 for WordPress has multiple CSRF issues.
CVE-2016-10874HIGH8.8The wp-database-backup plugin before 4.3.3 for WordPress has CSRF.
CVE-2016-5431HIGH7.5The PHP JOSE Library by Gree Inc. before version 2.2.1 is vulnerable to key confusion/algorithm substitution in the JWS ...
CVE-2016-10766HIGH8.8edx-platform before 2016-06-06 allows CSRF.
CVE-2016-1587HIGH7.1The Snapweb interface before version 0.21.2 was exposing controls to install or remove snap packages without controlling...
CVE-2016-1573HIGH7.8Versions of Unity8 before 8.11+16.04.20160122-0ubuntu1 file plugins/Dash/CardCreator.js will execute any code found in p...
CVE-2016-9778HIGH7.5An error in handling certain queries can cause an assertion failure when a server is using the nxdomain-redirect feature...
CVE-2016-2123HIGH8.8A flaw was found in samba versions 4.0.0 to 4.5.2. The Samba routine ndr_pull_dnsp_name contains an integer wrap problem...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now