2016 CVE Vulnerabilities

10,645 CVEs published in 2016.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2016-10951HIGH7.2The fs-shopping-cart plugin 2.07.02 for WordPress has SQL injection via the pid parameter.
CVE-2016-10950HIGH8.8The sirv plugin before 1.3.2 for WordPress has SQL injection via the id parameter.
CVE-2016-10949HIGH8.8The Relevanssi Premium plugin before 1.14.6.1 for WordPress has SQL injection with resultant unsafe unserialization.
CVE-2016-10948HIGH8.1The Post Indexer plugin before 3.0.6.2 for WordPress has incorrect handling of data passed to the unserialize function.
CVE-2016-10947HIGH7.2The Post Indexer plugin before 3.0.6.2 for WordPress has SQL injection via the period parameter by a super admin.
CVE-2016-10946HIGH8.8The wp-d3 plugin before 2.4.1 for WordPress has CSRF.
CVE-2016-10945HIGH8.8The PageLines theme 1.1.4 for WordPress has wp-admin/admin-post.php?page=pagelines CSRF.
CVE-2016-10944HIGH8.8The multisite-post-duplicator plugin before 1.1.3 for WordPress has wp-admin/tools.php?page=mpd CSRF.
CVE-2016-10943HIGH7.2The zx-csv-upload plugin 1 for WordPress has SQL injection via the id parameter.
CVE-2016-10940HIGH7.2The zm-gallery plugin 1.0 for WordPress has SQL injection via the order parameter.
CVE-2016-10939HIGH7.2The xtremelocator plugin 1.5 for WordPress has SQL injection via the id parameter.
CVE-2016-10937HIGH7.5IMAPFilter through 2.6.12 does not validate the hostname in an SSL certificate.
CVE-2016-10905HIGH7.8An issue was discovered in fs/gfs2/rgrp.c in the Linux kernel before 4.8. A use-after-free is caused by the functions gf...
CVE-2016-10884HIGH8.8The simple-membership plugin before 3.3.3 for WordPress has multiple CSRF issues.
CVE-2016-10874HIGH8.8The wp-database-backup plugin before 4.3.3 for WordPress has CSRF.
CVE-2016-5431HIGH7.5The PHP JOSE Library by Gree Inc. before version 2.2.1 is vulnerable to key confusion/algorithm substitution in the JWS ...
CVE-2016-10766HIGH8.8edx-platform before 2016-06-06 allows CSRF.
CVE-2016-1573HIGH7.8Versions of Unity8 before 8.11+16.04.20160122-0ubuntu1 file plugins/Dash/CardCreator.js will execute any code found in p...
CVE-2016-2123HIGH8.8A flaw was found in samba versions 4.0.0 to 4.5.2. The Samba routine ndr_pull_dnsp_name contains an integer wrap problem...
CVE-2016-6328HIGH8.1A vulnerability was found in libexif. An integer overflow when parsing the MNOTE entry data of the input file. This can ...
CVE-2016-9045HIGH8.8A code execution vulnerability exists in ProcessMaker Enterprise Core 3.0.1.7-community. A specially crafted web request...
CVE-2016-9048HIGH7.4Multiple exploitable SQL Injection vulnerabilities exists in ProcessMaker Enterprise Core 3.0.1.7-community. Specially c...
CVE-2016-9044HIGH8.8An exploitable command execution vulnerability exists in Information Builders WebFOCUS Business Intelligence Portal 8.1 ...
CVE-2016-7048HIGH8.1The interactive installer in PostgreSQL before 9.3.15, 9.4.x before 9.4.10, and 9.5.x before 9.5.5 might allow remote at...
CVE-2016-9487HIGH7.8EpubCheck 4.0.1 does not properly restrict resolving external entities when parsing XML in EPUB files during validation....

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now