2016 CVE Vulnerabilities

10,645 CVEs published in 2016.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2016-20084MEDIUM5.1WordPress appointment-booking-calendar 1.1.24 contains multiple privilege escalation vulnerabilities that allow unauthen...
CVE-2016-20083MEDIUM6.9WordPress More Fields Plugin 2.1 contains a cross-site request forgery vulnerability that allows attackers to perform un...
CVE-2016-20082MEDIUM6.9WordPress Plugin Abtest contains a local file inclusion vulnerability that allows unauthenticated attackers to include a...
CVE-2016-20080MEDIUM6.9WordPress Brandfolder plugin version 3.0 and earlier contains a local file inclusion vulnerability in callback.php that ...
CVE-2016-20079MEDIUM6.9WordPress Dharma Booking 2.28.3 and earlier contains a local file inclusion vulnerability that allows unauthenticated at...
CVE-2016-20078MEDIUM6.9WordPress IMDb Profile Widget 1.0.8 contains a local file inclusion vulnerability that allows unauthenticated attackers ...
CVE-2016-20077MEDIUM6.9WordPress Plugin Photocart Link 1.6 contains a local file inclusion vulnerability that allows unauthenticated attackers ...
CVE-2016-20074MEDIUM5.3WordPress Lazy Content Slider Plugin 3.4 contains a cross-site request forgery vulnerability that allows attackers to pe...
CVE-2016-20070MEDIUM5.1WordPress Booking Calendar Contact Form 1.0.23 contains privilege escalation and stored cross-site scripting vulnerabili...
CVE-2016-20067MEDIUM5.3WordPress CP Polls 1.0.8 contains a cross-site request forgery vulnerability that allows attackers to perform unauthoriz...
CVE-2016-20066MEDIUM5.1WordPress CP Polls 1.0.8 contains a persistent cross-site scripting vulnerability that allows attackers to inject malici...
CVE-2016-20064MEDIUM6.9WP Vault 0.8.6.6 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary f...
CVE-2016-20054MEDIUM5.3Nodcms contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized administrative ...
CVE-2016-20053MEDIUM6.9Redaxo CMS 5.2 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to create admin...
CVE-2016-20051MEDIUM6.9Snews CMS 1.7 contains a cross-site request forgery vulnerability that allows attackers to change administrator credenti...
CVE-2016-20050MEDIUM6.9NetSchedScan 1.0 contains a buffer overflow vulnerability in the scan Hostname/IP field that allows local attackers to c...
CVE-2016-20036MEDIUM5.1Wowza Streaming Engine 4.5.0 contains multiple reflected cross-site scripting vulnerabilities in the enginemanager inter...
CVE-2016-20035MEDIUM6.9Wowza Streaming Engine 4.5.0 contains a cross-site request forgery vulnerability that allows attackers to perform admini...
CVE-2016-20032MEDIUM5.1ZKTeco ZKAccess Security System 5.3.1 contains a stored cross-site scripting vulnerability that allows attackers to exec...
CVE-2016-20031MEDIUM6.8ZKTeco ZKBioSecurity 3.0 contains a local authorization bypass vulnerability in visLogin.jsp that allows attackers to au...
CVE-2016-20029MEDIUM6.9ZKTeco ZKBioSecurity 3.0 contains a file path manipulation vulnerability that allows attackers to access arbitrary files...
CVE-2016-20028MEDIUM5.3ZKTeco ZKBioSecurity 3.0 contains a cross-site request forgery vulnerability that allows attackers to perform administra...
CVE-2016-20027MEDIUM5.1ZKTeco ZKBioSecurity 3.0 contains multiple reflected cross-site scripting vulnerabilities that allow attackers to execut...
CVE-2016-20023MEDIUM6.5In CKSource CKFinder before 2.5.0.1 for ASP.NET, authenticated users could download any file from the server if the corr...
CVE-2016-15053MEDIUM5.1Nagios XI versions prior to 5.2.4 are vulnerable to cross-site scripting (XSS) via the “My Reports” listing of the web i...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now