2016 CVE Vulnerabilities

10,645 CVEs published in 2016.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2016-1000113CRITICAL9.8XSS and SQLi in huge IT gallery v1.1.5 for Joomla
CVE-2016-1000112CRITICAL9.1Unauthenticated remote .jpg file upload in contus-video-comments v1.0 wordpress plugin
CVE-2016-1453CRITICAL9.8Buffer overflow in the Overlay Transport Virtualization (OTV) GRE feature in Cisco NX-OS 5.0 through 7.3 on Nexus 7000 a...
CVE-2016-7161CRITICAL9.8Heap-based buffer overflow in the .receive callback of xlnx.xps-ethernetlite in QEMU (aka Quick Emulator) allows attacke...
CVE-2016-5180CRITICAL9.8Heap-based buffer overflow in the ares_create_query function in c-ares 1.x before 1.12.0 allows remote attackers to caus...
CVE-2016-4303CRITICAL9.8The parse_string function in cjson.c in the cJSON library mishandles UTF8/16 strings, which allows remote attackers to c...
CVE-2016-6531CRITICAL9.8Open Dental 16.1 and earlier has a hardcoded MySQL root password, which allows remote attackers to obtain administrative...
CVE-2016-6374CRITICAL9.8Cisco Cloud Services Platform (CSP) 2100 2.0 allows remote attackers to execute arbitrary code via a crafted dnslookup c...
CVE-2016-6303CRITICAL9.8Integer overflow in the MDC2_Update function in crypto/mdc2/mdc2dgst.c in OpenSSL before 1.1.0 allows remote attackers t...
CVE-2016-7126CRITICAL9.8The imagetruecolortopalette function in ext/gd/gd.c in PHP before 5.6.25 and 7.x before 7.0.10 does not properly validat...
CVE-2016-5344CRITICAL9.8Multiple integer overflows in the MDSS driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) And...
CVE-2016-5681CRITICAL9.8Stack-based buffer overflow in dws/api/Login on D-Link DIR-850L B1 2.07 before 2.07WWB05, DIR-817 Ax, DIR-818LW Bx befor...
CVE-2016-5772CRITICAL9.8Double free vulnerability in the php_wddx_process_data function in wddx.c in the WDDX extension in PHP before 5.5.37, 5....
CVE-2016-5771CRITICAL9.8spl_array.c in the SPL extension in PHP before 5.5.37 and 5.6.x before 5.6.23 improperly interacts with the unserialize ...
CVE-2016-5770CRITICAL9.8Integer overflow in the SplFileObject::fread function in spl_directory.c in the SPL extension in PHP before 5.5.37 and 5...
CVE-2016-3078CRITICAL9.8Multiple integer overflows in php_zip.c in the zip extension in PHP before 7.0.6 allow remote attackers to cause a denia...
CVE-2016-4999CRITICAL9.8SQL injection vulnerability in the getStringParameterSQL method in main/java/org/dashbuilder/dataprovider/sql/dialect/De...
CVE-2016-4837CRITICAL9.8SQL injection vulnerability in the Seed Coupon plugin before 1.6 for EC-CUBE allows remote attackers to execute arbitrar...
CVE-2016-4614CRITICAL9.8libxml2 in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows,...
CVE-2016-4610CRITICAL9.8libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows,...
CVE-2016-4609CRITICAL9.8libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows,...
CVE-2016-4608CRITICAL9.8libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows,...
CVE-2016-4607CRITICAL9.8libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows,...
CVE-2016-5804CRITICAL9.8Moxa MGate MB3180 before 1.8, MGate MB3280 before 2.7, MGate MB3480 before 2.6, MGate MB3170 before 2.5, and MGate MB327...
CVE-2016-4503CRITICAL9.8Moxa Device Server Web Console 5232-N allows remote attackers to bypass authentication, and consequently modify settings...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now