2016 CVE Vulnerabilities

10,647 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-10374MEDIUM5.5perltidy through 20160302, as used by perlcritic, check-all-the-things, and other software, relies on the current workin...
CVE-2016-3403Multiple cross-site request forgery (CSRF) vulnerabilities in the Admin Console in Zimbra Collaboration before 8.6.0 Pat...
CVE-2016-10372The Eir D1000 modem does not properly restrict the TR-064 protocol, which allows remote attackers to execute arbitrary c...
CVE-2016-10242A time-of-check time-of-use race condition could potentially exist in the secure file system in all Android releases fro...
CVE-2016-10239In TrustZone access control policy may potentially be bypassed in all Android releases from CAF using the Linux kernel d...
CVE-2016-10238In QSEE in all Android releases from CAF using the Linux kernel access control may potentially be bypassed due to a page...
CVE-2016-10237If shared content protection memory were passed as the secure camera memory buffer by the HLOS to a trusted application ...
CVE-2016-9750IBM QRadar 7.2 and 7.3 stores user credentials in plain in clear text which can be read by an authenticated user. IBM X-...
CVE-2016-9735IBM Jazz Foundation could allow an authenticated user to obtain sensitive information from stack traces. IBM X-Force ID:...
CVE-2016-5979IBM Distributed Marketing 8.6, 9.0, and 10.0 could allow a privileged authenticated user to create an instance that gets...
CVE-2016-8741HIGH7.5The Apache Qpid Broker for Java can be configured to use different so called AuthenticationProviders to handle user auth...
CVE-2016-10331Directory traversal vulnerability in download.php in Synology Photo Station before 6.5.3-3226 allows remote attackers to...
CVE-2016-10330Directory traversal vulnerability in synophoto_dsm_user, a SUID program, as used in Synology Photo Station before 6.5.3-...
CVE-2016-10329Command injection vulnerability in login.php in Synology Photo Station before 6.5.3-3226 allows remote attackers to exec...
CVE-2016-4887Cross-site request forgery (CSRF) vulnerability in baserCMS plugin Uploader version 3.0.10 and earlier allows remote att...
CVE-2016-4886Cross-site request forgery (CSRF) vulnerability in baserCMS plugin Mail version 3.0.10 and earlier allows remote attacke...
CVE-2016-4885Cross-site request forgery (CSRF) vulnerability in baserCMS plugin Feed version 3.0.10 and earlier allows remote attacke...
CVE-2016-4884Cross-site request forgery (CSRF) vulnerability in baserCMS plugin Blog version 3.0.10 and earlier allows remote attacke...
CVE-2016-4883Cross-site scripting vulnerability in baserCMS version 3.0.10 and earlier allows remote attackers to inject arbitrary we...
CVE-2016-4882Cross-site request forgery (CSRF) vulnerability in baserCMS version 3.0.10 and earlier allows remote attackers to hijack...
CVE-2016-4881Cross-site request forgery (CSRF) vulnerability in baserCMS plugin Blog version 3.0.10 and earlier allows remote attacke...
CVE-2016-4880Cross-site scripting vulnerability in baserCMS plugin Blog version 3.0.10 and earlier allows remote authenticated attack...
CVE-2016-4879HIGH8.8Cross-site request forgery (CSRF) vulnerability in baserCMS plugin Mail version 3.0.10 and earlier allows remote attacke...
CVE-2016-4878Cross-site request forgery (CSRF) vulnerability in baserCMS version 3.0.10 and earlier allows remote attackers to hijack...
CVE-2016-4877MEDIUM5.4Cross-site scripting vulnerability in baserCMS plugin Mail version 3.0.10 and earlier allows remote authenticated attack...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now