2016 CVE Vulnerabilities

10,647 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-6348JacksonJsonpInterceptor in RESTEasy might allow remote attackers to conduct a cross-site script inclusion (XSSI) attack.
CVE-2016-5856Drivers/soc/qcom/spcom.c in the Qualcomm SPCom driver in the Android kernel 2017-03-05 allows local users to gain privil...
CVE-2016-5313Symantec Web Gateway (SWG) before 5.2.5 allows remote authenticated users to execute arbitrary OS commands.
CVE-2016-4897Multiple cross-site scripting (XSS) vulnerabilities in (1) filter/save_forward.cgi, (2) filter/save.cgi, (3) /man/search...
CVE-2016-4896SetsucoCMS all versions does not properly manage sessions, which allows remote attackers to disclose or alter unauthoriz...
CVE-2016-4895SetsucoCMS all versions allows remote authenticated attackers to conduct code injection attacks via unspecified vectors.
CVE-2016-4894SetsucoCMS all versions allows remote attackers to cause a denial of service via unspecified vectors.
CVE-2016-4893SQL injection vulnerability in the SetsucoCMS all versions allows remote authenticated attackers to execute arbitrary SQ...
CVE-2016-4892Cross-site scripting vulnerability in SetsucoCMS all versions allows remote attackers to inject arbitrary web script or ...
CVE-2016-4891Cross-site request forgery (CSRF) vulnerability in SetsucoCMS all versions allows remote attackers to hijack the authent...
CVE-2016-4337SQL injection vulnerability in the mgr.login.php file in Ktools.net Photostore before 4.7.5 allows remote attackers to e...
CVE-2016-2803Cross-site scripting (XSS) vulnerability in the dependency graphs in Bugzilla 2.16rc1 through 4.4.11, and 4.5.1 through ...
CVE-2016-1179Cross-site scripting (XSS) vulnerability in the standard template of the comment functionality in appleple a-blog cms 2....
CVE-2016-1178The session management of the comment functionality in appleple a-blog cms 2.6.0.1 and earlier allows remote attackers t...
CVE-2016-9959game-music-emu before 0.6.1 allows remote attackers to generate out of bounds 8-bit values.
CVE-2016-9958game-music-emu before 0.6.1 allows remote attackers to write to arbitrary memory locations.
CVE-2016-9957Stack-based buffer overflow in game-music-emu before 0.6.1.
CVE-2016-6808Buffer overflow in Apache Tomcat Connectors (mod_jk) before 1.2.42.
CVE-2016-4459Stack-based buffer overflow in native/mod_manager/node.c in mod_cluster 1.2.9.
CVE-2016-8719MEDIUM6.1An exploitable reflected Cross-Site Scripting vulnerability exists in the Web Application functionality of Moxa AWK-3131...
CVE-2016-8718HIGH8.8An exploitable Cross-Site Request Forgery vulnerability exists in the Web Application functionality of Moxa AWK-3131A Wi...
CVE-2016-8716HIGH7.5An exploitable Cleartext Transmission of Password vulnerability exists in the Web Application functionality of Moxa AWK-...
CVE-2016-7958In Wireshark 2.2.0, the NCP dissector could crash, triggered by packet injection or a malformed capture file. This was a...
CVE-2016-7957In Wireshark 2.2.0, the Bluetooth L2CAP dissector could crash, triggered by packet injection or a malformed capture file...
CVE-2016-7552On the Trend Micro Threat Discovery Appliance 2.6.1062r1, directory traversal when processing a session_id cookie allows...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now