2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-10952 | MEDIUM | 6.1 | 1.4% | Sep 13, 2019 | The quotes-collection plugin before 2.0.6 for WordPress has XSS via the wp-admin/admin.php?page=quotes-collection page p... |
| CVE-2016-10941 | MEDIUM | 6.1 | 1.2% | Sep 13, 2019 | The podlove-podcasting-plugin-for-wordpress plugin before 2.3.16 for WordPress has XSS exploitable via CSRF. |
| CVE-2016-10938 | MEDIUM | 6.5 | 0.9% | Sep 13, 2019 | The copy-me plugin 1.0.0 for WordPress has CSRF for copying non-public posts to a public location. |
| CVE-2016-10893 | MEDIUM | 6.1 | 1.3% | Aug 20, 2019 | The crayon-syntax-highlighter plugin before 2.8.4 for WordPress has multiple XSS issues via AJAX requests. |
| CVE-2016-10894 | MEDIUM | 4.6 | 0.4% | Aug 16, 2019 | xtrlock through 2.10 does not block multitouch events. Consequently, an attacker at a locked screen can send input to (a... |
| CVE-2016-10867 | MEDIUM | 6.1 | 0.9% | Aug 13, 2019 | The all-in-one-wp-security-and-firewall plugin before 4.0.6 for WordPress has XSS in settings pages. |
| CVE-2016-10872 | MEDIUM | 6.1 | 1.0% | Aug 12, 2019 | The ultimate-member plugin before 1.3.40 for WordPress has XSS on the login form. |
| CVE-2016-10878 | MEDIUM | 6.1 | 1.0% | Aug 12, 2019 | The wp-google-map-plugin plugin before 3.1.2 for WordPress has XSS. |
| CVE-2016-10875 | MEDIUM | 6.1 | 0.9% | Aug 12, 2019 | The wp-database-backup plugin before 4.3.1 for WordPress has XSS. |
| CVE-2016-10873 | MEDIUM | 6.1 | 0.9% | Aug 12, 2019 | The wp-database-backup plugin before 4.3.3 for WordPress has XSS. |
| CVE-2016-10765 | MEDIUM | 5.3 | 0.8% | Jul 29, 2019 | edx-platform before 2016-06-10 allows account activation with a spoofed e-mail address. |
| CVE-2016-7043 | MEDIUM | 5.9 | 1.5% | May 15, 2019 | It has been reported that KIE server and Busitess Central before version 7.21.0.Final contain username and password as p... |
| CVE-2016-1579 | MEDIUM | 6.7 | 0.8% | Apr 22, 2019 | UDM provides support for running commands after a download is completed, this is currently made use of for click package... |
| CVE-2016-9749 | MEDIUM | 4 | 0.3% | Nov 9, 2018 | IBM Campaign 9.1.0, 9.1.2, 10.0, and 10.1 could allow an authenticated user with access to the local network to bypass s... |
| CVE-2016-2125 | MEDIUM | 6.5 | 9.3% | Oct 31, 2018 | It was found that Samba before versions 4.5.3, 4.4.8, 4.3.13 always requested forwardable tickets when using Kerberos au... |
| CVE-2016-6343 | MEDIUM | 6.1 | 1.7% | Oct 31, 2018 | JBoss BPM Suite 6 is vulnerable to a reflected XSS via dashbuilder. Remote attackers can entice authenticated users that... |
| CVE-2016-2121 | MEDIUM | 4 | 0.4% | Oct 31, 2018 | A permissions flaw was found in redis, which sets weak permissions on certain files and directories that could potential... |
| CVE-2016-7074 | MEDIUM | 5.3 | 1.2% | Sep 11, 2018 | An issue has been found in PowerDNS before 3.4.11 and 4.0.2, and PowerDNS recursor before 4.0.4, allowing an attacker in... |
| CVE-2016-7073 | MEDIUM | 5.3 | 1.2% | Sep 11, 2018 | An issue has been found in PowerDNS before 3.4.11 and 4.0.2, and PowerDNS recursor before 4.0.4, allowing an attacker in... |
| CVE-2016-7069 | MEDIUM | 5.9 | 4.5% | Sep 11, 2018 | An issue has been found in dnsdist before 1.2.0 in the way EDNS0 OPT records are handled when parsing responses from a b... |
| CVE-2016-7068 | MEDIUM | 5.3 | 7.3% | Sep 11, 2018 | An issue has been found in PowerDNS before 3.4.11 and 4.0.2, and PowerDNS recursor before 3.7.4 and 4.0.4, allowing a re... |
| CVE-2016-7047 | MEDIUM | 4.3 | 1.3% | Sep 11, 2018 | A flaw was found in the CloudForms API before 5.6.3.0, 5.7.3.1 and 5.8.1.2. A user with permissions to use the MiqReport... |
| CVE-2016-0750 | MEDIUM | 4.2 | 2.4% | Sep 11, 2018 | The hotrod java client in infinispan before 9.1.0.Final automatically deserializes bytearray message contents in certain... |
| CVE-2016-7072 | MEDIUM | 5.3 | 6.3% | Sep 10, 2018 | An issue has been found in PowerDNS Authoritative Server before 3.4.11 and 4.0.2 allowing a remote, unauthenticated atta... |
| CVE-2016-7056 | MEDIUM | 5.5 | 0.6% | Sep 10, 2018 | A timing attack flaw was found in OpenSSL 1.0.1u and before that could allow a malicious user with local access to recov... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now