2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-8935 | — | — | 0.5% | Mar 31, 2017 | IBM Kenexa LMS on Cloud 13.1, 13.2, 13.2.2, 13.2.3, 13.2.4 and 14.0.0 are vulnerable to cross-site scripting. This vulne... |
| CVE-2016-8917 | — | — | 0.6% | Mar 31, 2017 | IBM Sterling Order Management 9.2 - 9.5 is vulnerable to cross-site request forgery which could allow an attacker to exe... |
| CVE-2016-6111 | — | — | 2.1% | Mar 31, 2017 | IBM Curam Social Program Management 6.0 and 7.0 are vulnerable to a denial of service, caused by an XML External Entity ... |
| CVE-2016-6036 | — | — | 0.5% | Mar 31, 2017 | IBM Rational Quality Manager (RQM) 4.0, 5.0, and 6.0 are vulnerable to cross-site scripting. This vulnerability allows u... |
| CVE-2016-6031 | — | — | 0.5% | Mar 31, 2017 | IBM Rational Quality Manager 4.0, 5.0, and 6.0 are vulnerable to cross-site scripting. This vulnerability allows users t... |
| CVE-2016-6022 | — | — | 0.5% | Mar 31, 2017 | IBM Quality Manager (RQM) 4.0, 5.0, and 6.0 are vulnerable to cross-site scripting. This vulnerability allows users to e... |
| CVE-2016-6209 | — | — | 1.8% | Mar 31, 2017 | Cross-site scripting (XSS) vulnerability in Nagios. |
| CVE-2016-9319 | — | — | 0.8% | Mar 31, 2017 | There is Missing SSL Certificate Validation in the Trend Micro Enterprise Mobile Security Android Application before 9.7... |
| CVE-2016-7542 | — | — | 1.5% | Mar 30, 2017 | A read-only administrator on Fortinet devices with FortiOS 5.2.x before 5.2.10 GA and 5.4.x before 5.4.2 GA may have acc... |
| CVE-2016-7541 | — | — | 1.0% | Mar 30, 2017 | Long lived sessions in Fortinet FortiGate devices with FortiOS 5.x before 5.4.0 could violate a security policy during I... |
| CVE-2016-10309 | — | — | 1.7% | Mar 30, 2017 | In the GUI of Ceragon FibeAir IP-10 (before 7.2.0) devices, a remote attacker can bypass authentication by adding an ALB... |
| CVE-2016-10308 | — | — | 2.9% | Mar 30, 2017 | Siklu EtherHaul radios before 3.7.1 and 6.x before 6.9.0 have a built-in, hidden root account, with an unchangeable pass... |
| CVE-2016-10306 | — | — | 2.7% | Mar 30, 2017 | Trango Altum AC600 devices have a built-in, hidden root account, with a default password of abcd1234. This account is ac... |
| CVE-2016-6349 | — | — | 0.4% | Mar 29, 2017 | The machinectl command in oci-register-machine allows local users to list running containers and possibly obtain sensiti... |
| CVE-2016-4976 | — | — | 0.5% | Mar 29, 2017 | Apache Ambari 2.x before 2.4.0 includes KDC administrator passwords on the kadmin command line, which allows local users... |
| CVE-2016-2379 | — | — | 0.4% | Mar 29, 2017 | The Mxit protocol uses weak encryption when encrypting user passwords, which might allow attackers to (1) decrypt hashed... |
| CVE-2016-9924 | — | — | 2.8% | Mar 29, 2017 | Zimbra Collaboration Suite (ZCS) before 8.7.4 allows remote attackers to conduct XML External Entity (XXE) attacks. |
| CVE-2016-6846 | — | — | 1.2% | Mar 29, 2017 | Cross-site scripting (XSS) vulnerability in Open-Xchange (OX) AppSuite backend before 7.6.2-rev59, 7.8.0 before 7.8.0-re... |
| CVE-2016-6807 | — | — | 2.4% | Mar 28, 2017 | Custom commands may be executed on Ambari Agent (2.4.x, before 2.4.2) hosts without authorization, leading to unauthoriz... |
| CVE-2016-8749 | — | — | 10.6% | Mar 28, 2017 | Apache Camel's Jackson and JacksonXML unmarshalling operation are vulnerable to Remote Code Execution attacks. |
| CVE-2016-8884 | — | — | 2.3% | Mar 28, 2017 | The bmp_getdata function in libjasper/bmp/bmp_dec.c in JasPer 1.900.5 allows remote attackers to cause a denial of servi... |
| CVE-2016-10152 | — | — | 6.8% | Mar 28, 2017 | The read_config_file function in lib/hesiod.c in Hesiod 3.2.1 falls back to the ".athena.mit.edu" default domain when op... |
| CVE-2016-9472 | — | — | 1.6% | Mar 28, 2017 | Revive Adserver before 3.2.5 and 4.0.0 suffers from Reflected XSS. The Revive Adserver web installer scripts were vulner... |
| CVE-2016-9471 | — | — | 1.4% | Mar 28, 2017 | Revive Adserver before 3.2.5 and 4.0.0 suffers from Special Element Injection. Usernames weren't properly sanitised when... |
| CVE-2016-9470 | — | — | 2.1% | Mar 28, 2017 | Revive Adserver before 3.2.5 and 4.0.0 suffers from Reflected File Download. `www/delivery/asyncspc.php` was vulnerable ... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now