2016 CVE Vulnerabilities

10,647 CVEs published in 2016.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2016-8935IBM Kenexa LMS on Cloud 13.1, 13.2, 13.2.2, 13.2.3, 13.2.4 and 14.0.0 are vulnerable to cross-site scripting. This vulne...
CVE-2016-8917IBM Sterling Order Management 9.2 - 9.5 is vulnerable to cross-site request forgery which could allow an attacker to exe...
CVE-2016-6111IBM Curam Social Program Management 6.0 and 7.0 are vulnerable to a denial of service, caused by an XML External Entity ...
CVE-2016-6036IBM Rational Quality Manager (RQM) 4.0, 5.0, and 6.0 are vulnerable to cross-site scripting. This vulnerability allows u...
CVE-2016-6031IBM Rational Quality Manager 4.0, 5.0, and 6.0 are vulnerable to cross-site scripting. This vulnerability allows users t...
CVE-2016-6022IBM Quality Manager (RQM) 4.0, 5.0, and 6.0 are vulnerable to cross-site scripting. This vulnerability allows users to e...
CVE-2016-6209Cross-site scripting (XSS) vulnerability in Nagios.
CVE-2016-9319There is Missing SSL Certificate Validation in the Trend Micro Enterprise Mobile Security Android Application before 9.7...
CVE-2016-7542A read-only administrator on Fortinet devices with FortiOS 5.2.x before 5.2.10 GA and 5.4.x before 5.4.2 GA may have acc...
CVE-2016-7541Long lived sessions in Fortinet FortiGate devices with FortiOS 5.x before 5.4.0 could violate a security policy during I...
CVE-2016-10309In the GUI of Ceragon FibeAir IP-10 (before 7.2.0) devices, a remote attacker can bypass authentication by adding an ALB...
CVE-2016-10308Siklu EtherHaul radios before 3.7.1 and 6.x before 6.9.0 have a built-in, hidden root account, with an unchangeable pass...
CVE-2016-10306Trango Altum AC600 devices have a built-in, hidden root account, with a default password of abcd1234. This account is ac...
CVE-2016-6349The machinectl command in oci-register-machine allows local users to list running containers and possibly obtain sensiti...
CVE-2016-4976Apache Ambari 2.x before 2.4.0 includes KDC administrator passwords on the kadmin command line, which allows local users...
CVE-2016-2379The Mxit protocol uses weak encryption when encrypting user passwords, which might allow attackers to (1) decrypt hashed...
CVE-2016-9924Zimbra Collaboration Suite (ZCS) before 8.7.4 allows remote attackers to conduct XML External Entity (XXE) attacks.
CVE-2016-6846Cross-site scripting (XSS) vulnerability in Open-Xchange (OX) AppSuite backend before 7.6.2-rev59, 7.8.0 before 7.8.0-re...
CVE-2016-6807Custom commands may be executed on Ambari Agent (2.4.x, before 2.4.2) hosts without authorization, leading to unauthoriz...
CVE-2016-8749Apache Camel's Jackson and JacksonXML unmarshalling operation are vulnerable to Remote Code Execution attacks.
CVE-2016-8884The bmp_getdata function in libjasper/bmp/bmp_dec.c in JasPer 1.900.5 allows remote attackers to cause a denial of servi...
CVE-2016-10152The read_config_file function in lib/hesiod.c in Hesiod 3.2.1 falls back to the ".athena.mit.edu" default domain when op...
CVE-2016-9472Revive Adserver before 3.2.5 and 4.0.0 suffers from Reflected XSS. The Revive Adserver web installer scripts were vulner...
CVE-2016-9471Revive Adserver before 3.2.5 and 4.0.0 suffers from Special Element Injection. Usernames weren't properly sanitised when...
CVE-2016-9470Revive Adserver before 3.2.5 and 4.0.0 suffers from Reflected File Download. `www/delivery/asyncspc.php` was vulnerable ...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now