2016 CVE Vulnerabilities

10,648 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-4854——Cross-site request forgery (CSRF) vulnerability in L-04D firmware version V10a and V10b allows remote attackers to hijac...
CVE-2016-10374MEDIUM5.5perltidy through 20160302, as used by perlcritic, check-all-the-things, and other software, relies on the current workin...
CVE-2016-3403——Multiple cross-site request forgery (CSRF) vulnerabilities in the Admin Console in Zimbra Collaboration before 8.6.0 Pat...
CVE-2016-10372——The Eir D1000 modem does not properly restrict the TR-064 protocol, which allows remote attackers to execute arbitrary c...
CVE-2016-10242——A time-of-check time-of-use race condition could potentially exist in the secure file system in all Android releases fro...
CVE-2016-10239——In TrustZone access control policy may potentially be bypassed in all Android releases from CAF using the Linux kernel d...
CVE-2016-10238——In QSEE in all Android releases from CAF using the Linux kernel access control may potentially be bypassed due to a page...
CVE-2016-10237——If shared content protection memory were passed as the secure camera memory buffer by the HLOS to a trusted application ...
CVE-2016-9750——IBM QRadar 7.2 and 7.3 stores user credentials in plain in clear text which can be read by an authenticated user. IBM X-...
CVE-2016-9735——IBM Jazz Foundation could allow an authenticated user to obtain sensitive information from stack traces. IBM X-Force ID:...
CVE-2016-5979——IBM Distributed Marketing 8.6, 9.0, and 10.0 could allow a privileged authenticated user to create an instance that gets...
CVE-2016-8741HIGH7.5The Apache Qpid Broker for Java can be configured to use different so called AuthenticationProviders to handle user auth...
CVE-2016-10331——Directory traversal vulnerability in download.php in Synology Photo Station before 6.5.3-3226 allows remote attackers to...
CVE-2016-10330——Directory traversal vulnerability in synophoto_dsm_user, a SUID program, as used in Synology Photo Station before 6.5.3-...
CVE-2016-10329——Command injection vulnerability in login.php in Synology Photo Station before 6.5.3-3226 allows remote attackers to exec...
CVE-2016-4887——Cross-site request forgery (CSRF) vulnerability in baserCMS plugin Uploader version 3.0.10 and earlier allows remote att...
CVE-2016-4886——Cross-site request forgery (CSRF) vulnerability in baserCMS plugin Mail version 3.0.10 and earlier allows remote attacke...
CVE-2016-4885——Cross-site request forgery (CSRF) vulnerability in baserCMS plugin Feed version 3.0.10 and earlier allows remote attacke...
CVE-2016-4884——Cross-site request forgery (CSRF) vulnerability in baserCMS plugin Blog version 3.0.10 and earlier allows remote attacke...
CVE-2016-4883——Cross-site scripting vulnerability in baserCMS version 3.0.10 and earlier allows remote attackers to inject arbitrary we...
CVE-2016-4882——Cross-site request forgery (CSRF) vulnerability in baserCMS version 3.0.10 and earlier allows remote attackers to hijack...
CVE-2016-4881——Cross-site request forgery (CSRF) vulnerability in baserCMS plugin Blog version 3.0.10 and earlier allows remote attacke...
CVE-2016-4880——Cross-site scripting vulnerability in baserCMS plugin Blog version 3.0.10 and earlier allows remote authenticated attack...
CVE-2016-4879HIGH8.8Cross-site request forgery (CSRF) vulnerability in baserCMS plugin Mail version 3.0.10 and earlier allows remote attacke...
CVE-2016-4878——Cross-site request forgery (CSRF) vulnerability in baserCMS version 3.0.10 and earlier allows remote attackers to hijack...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now