2016 CVE Vulnerabilities

10,647 CVEs published in 2016.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2016-10952MEDIUM6.1The quotes-collection plugin before 2.0.6 for WordPress has XSS via the wp-admin/admin.php?page=quotes-collection page p...
CVE-2016-10941MEDIUM6.1The podlove-podcasting-plugin-for-wordpress plugin before 2.3.16 for WordPress has XSS exploitable via CSRF.
CVE-2016-10938MEDIUM6.5The copy-me plugin 1.0.0 for WordPress has CSRF for copying non-public posts to a public location.
CVE-2016-10893MEDIUM6.1The crayon-syntax-highlighter plugin before 2.8.4 for WordPress has multiple XSS issues via AJAX requests.
CVE-2016-10894MEDIUM4.6xtrlock through 2.10 does not block multitouch events. Consequently, an attacker at a locked screen can send input to (a...
CVE-2016-10867MEDIUM6.1The all-in-one-wp-security-and-firewall plugin before 4.0.6 for WordPress has XSS in settings pages.
CVE-2016-10872MEDIUM6.1The ultimate-member plugin before 1.3.40 for WordPress has XSS on the login form.
CVE-2016-10878MEDIUM6.1The wp-google-map-plugin plugin before 3.1.2 for WordPress has XSS.
CVE-2016-10875MEDIUM6.1The wp-database-backup plugin before 4.3.1 for WordPress has XSS.
CVE-2016-10873MEDIUM6.1The wp-database-backup plugin before 4.3.3 for WordPress has XSS.
CVE-2016-10765MEDIUM5.3edx-platform before 2016-06-10 allows account activation with a spoofed e-mail address.
CVE-2016-7043MEDIUM5.9It has been reported that KIE server and Busitess Central before version 7.21.0.Final contain username and password as p...
CVE-2016-1579MEDIUM6.7UDM provides support for running commands after a download is completed, this is currently made use of for click package...
CVE-2016-9749MEDIUM4IBM Campaign 9.1.0, 9.1.2, 10.0, and 10.1 could allow an authenticated user with access to the local network to bypass s...
CVE-2016-2125MEDIUM6.5It was found that Samba before versions 4.5.3, 4.4.8, 4.3.13 always requested forwardable tickets when using Kerberos au...
CVE-2016-6343MEDIUM6.1JBoss BPM Suite 6 is vulnerable to a reflected XSS via dashbuilder. Remote attackers can entice authenticated users that...
CVE-2016-2121MEDIUM4A permissions flaw was found in redis, which sets weak permissions on certain files and directories that could potential...
CVE-2016-7074MEDIUM5.3An issue has been found in PowerDNS before 3.4.11 and 4.0.2, and PowerDNS recursor before 4.0.4, allowing an attacker in...
CVE-2016-7073MEDIUM5.3An issue has been found in PowerDNS before 3.4.11 and 4.0.2, and PowerDNS recursor before 4.0.4, allowing an attacker in...
CVE-2016-7069MEDIUM5.9An issue has been found in dnsdist before 1.2.0 in the way EDNS0 OPT records are handled when parsing responses from a b...
CVE-2016-7068MEDIUM5.3An issue has been found in PowerDNS before 3.4.11 and 4.0.2, and PowerDNS recursor before 3.7.4 and 4.0.4, allowing a re...
CVE-2016-7047MEDIUM4.3A flaw was found in the CloudForms API before 5.6.3.0, 5.7.3.1 and 5.8.1.2. A user with permissions to use the MiqReport...
CVE-2016-0750MEDIUM4.2The hotrod java client in infinispan before 9.1.0.Final automatically deserializes bytearray message contents in certain...
CVE-2016-7072MEDIUM5.3An issue has been found in PowerDNS Authoritative Server before 3.4.11 and 4.0.2 allowing a remote, unauthenticated atta...
CVE-2016-7056MEDIUM5.5A timing attack flaw was found in OpenSSL 1.0.1u and before that could allow a malicious user with local access to recov...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now