2016 CVE Vulnerabilities

10,648 CVEs published in 2016.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2016-3109——The backend/Login/load/ script in Shopware before 5.1.5 allows remote attackers to execute arbitrary code.
CVE-2016-3067——Cygwin before 2.5.0 does not properly handle updating permissions when changing users, which allows attackers to gain pr...
CVE-2016-2433——The Broadcom Wi-Fi driver for Android, as used by BlackBerry smartphones before Build AAE570, allows remote attackers to...
CVE-2016-2347——Integer underflow in the decode_level3_header function in lib/lha_file_header.c in Lhasa before 0.3.1 allows remote atta...
CVE-2016-1561——ExaGrid appliances with firmware before 4.8 P26 have a default SSH public key in the authorized_keys file for root, whic...
CVE-2016-1560——ExaGrid appliances with firmware before 4.8 P26 have a default password of (1) inflection for the root shell account and...
CVE-2016-1520——The Grandstream Wave app 1.0.1.26 and earlier for Android does not use HTTPS when retrieving update information, which m...
CVE-2016-1519——The com.softphone.common package in the Grandstream Wave app 1.0.1.26 and earlier for Android does not properly validate...
CVE-2016-1518——The auto-provisioning mechanism in the Grandstream Wave app 1.0.1.26 and earlier for Android and Grandstream Video IP ph...
CVE-2016-1221——Jetstar App for iOS before 3.0.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle att...
CVE-2016-1210——The 105 BANK app 1.0 and 1.1 for Android and 1.0 for iOS does not verify X.509 certificates from SSL servers, which allo...
CVE-2016-1198——Photopt for Android before 2.0.1 does not verify SSL certificates.
CVE-2016-1187——Cybozu KUNAI for iPhone 2.0.3 through 3.1.5 and for Android 2.1.2 through 3.0.4 does not verify SSL certificates.
CVE-2016-1186——Kintone mobile for Android 1.0.0 through 1.0.5 does not verify SSL server certificates.
CVE-2016-6519——Cross-site scripting (XSS) vulnerability in the "Shares" overview in Openstack Manila before 2.5.1 allows remote authent...
CVE-2016-1559——D-Link DAP-1353 H/W vers. B1 3.15 and earlier, D-Link DAP-2553 H/W ver. A1 1.31 and earlier, and D-Link DAP-3520 H/W ver...
CVE-2016-1558——Buffer overflow in D-Link DAP-2310 2.06 and earlier, DAP-2330 1.06 and earlier, DAP-2360 2.06 and earlier, DAP-2553 H/W ...
CVE-2016-1557——Netgear WNAP320, WNDAP350, and WNDAP360 before 3.5.5.0 reveal wireless passwords and administrative usernames and passwo...
CVE-2016-1556——Information disclosure in Netgear WN604 before 3.3.3; WNAP210, WNAP320, WNDAP350, and WNDAP360 before 3.5.5.0; and WND93...
CVE-2016-10091——Multiple stack-based buffer overflows in unrtf 0.21.9 allow remote attackers to cause a denial-of-service by writing a n...
CVE-2016-0721——Session fixation vulnerability in pcsd in pcs before 0.9.157.
CVE-2016-0720——Cross-site request forgery (CSRF) vulnerability in pcsd web UI in pcs before 0.9.149.
CVE-2016-4846——Untrusted search path vulnerability in the installer of PhishWall Client Internet Explorer before 3.7.8.2.
CVE-2016-4841——Cybozu Mailwise before 5.4.0 allows remote attackers to inject arbitrary email headers.
CVE-2016-4832——WAON "Service Application" for Android 1.4.1 and earlier does not verify SSL certificates.

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now