2016 CVE Vulnerabilities

10,647 CVEs published in 2016.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2016-3109The backend/Login/load/ script in Shopware before 5.1.5 allows remote attackers to execute arbitrary code.
CVE-2016-3067Cygwin before 2.5.0 does not properly handle updating permissions when changing users, which allows attackers to gain pr...
CVE-2016-2433The Broadcom Wi-Fi driver for Android, as used by BlackBerry smartphones before Build AAE570, allows remote attackers to...
CVE-2016-2347Integer underflow in the decode_level3_header function in lib/lha_file_header.c in Lhasa before 0.3.1 allows remote atta...
CVE-2016-1561ExaGrid appliances with firmware before 4.8 P26 have a default SSH public key in the authorized_keys file for root, whic...
CVE-2016-1560ExaGrid appliances with firmware before 4.8 P26 have a default password of (1) inflection for the root shell account and...
CVE-2016-1520The Grandstream Wave app 1.0.1.26 and earlier for Android does not use HTTPS when retrieving update information, which m...
CVE-2016-1519The com.softphone.common package in the Grandstream Wave app 1.0.1.26 and earlier for Android does not properly validate...
CVE-2016-1518The auto-provisioning mechanism in the Grandstream Wave app 1.0.1.26 and earlier for Android and Grandstream Video IP ph...
CVE-2016-1221Jetstar App for iOS before 3.0.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle att...
CVE-2016-1210The 105 BANK app 1.0 and 1.1 for Android and 1.0 for iOS does not verify X.509 certificates from SSL servers, which allo...
CVE-2016-1198Photopt for Android before 2.0.1 does not verify SSL certificates.
CVE-2016-1187Cybozu KUNAI for iPhone 2.0.3 through 3.1.5 and for Android 2.1.2 through 3.0.4 does not verify SSL certificates.
CVE-2016-1186Kintone mobile for Android 1.0.0 through 1.0.5 does not verify SSL server certificates.
CVE-2016-6519Cross-site scripting (XSS) vulnerability in the "Shares" overview in Openstack Manila before 2.5.1 allows remote authent...
CVE-2016-1559D-Link DAP-1353 H/W vers. B1 3.15 and earlier, D-Link DAP-2553 H/W ver. A1 1.31 and earlier, and D-Link DAP-3520 H/W ver...
CVE-2016-1558Buffer overflow in D-Link DAP-2310 2.06 and earlier, DAP-2330 1.06 and earlier, DAP-2360 2.06 and earlier, DAP-2553 H/W ...
CVE-2016-1557Netgear WNAP320, WNDAP350, and WNDAP360 before 3.5.5.0 reveal wireless passwords and administrative usernames and passwo...
CVE-2016-1556Information disclosure in Netgear WN604 before 3.3.3; WNAP210, WNAP320, WNDAP350, and WNDAP360 before 3.5.5.0; and WND93...
CVE-2016-10091Multiple stack-based buffer overflows in unrtf 0.21.9 allow remote attackers to cause a denial-of-service by writing a n...
CVE-2016-0721Session fixation vulnerability in pcsd in pcs before 0.9.157.
CVE-2016-0720Cross-site request forgery (CSRF) vulnerability in pcsd web UI in pcs before 0.9.149.
CVE-2016-4846Untrusted search path vulnerability in the installer of PhishWall Client Internet Explorer before 3.7.8.2.
CVE-2016-4841Cybozu Mailwise before 5.4.0 allows remote attackers to inject arbitrary email headers.
CVE-2016-4832WAON "Service Application" for Android 1.4.1 and earlier does not verify SSL certificates.

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now