2016 CVE Vulnerabilities

10,647 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-5053OSRAM SYLVANIA Osram Lightify Home before 2016-07-26 allows remote attackers to execute arbitrary commands via TCP port ...
CVE-2016-5052OSRAM SYLVANIA Osram Lightify Home through 2016-07-26 does not use SSL pinning.
CVE-2016-5051OSRAM SYLVANIA Osram Lightify Home before 2016-07-26 stores a PSK in cleartext under /private/var/mobile/Containers/Data...
CVE-2016-4334MEDIUM6.1Jive before 2016.3.1 has an open redirect from the external-link.jspa page.
CVE-2016-4320Atlassian Bitbucket Server before 4.7.1 allows remote attackers to read the first line of an arbitrary file via a direct...
CVE-2016-4319Atlassian JIRA Server before 7.1.9 has CSRF in auditing/settings.
CVE-2016-4318Atlassian JIRA Server before 7.1.9 has XSS in project/ViewDefaultProjectRoleActors.jspa via a role name.
CVE-2016-4317Atlassian Confluence Server before 5.9.11 has XSS on the viewmyprofile.action page.
CVE-2016-1517OpenCV 3.0.0 allows remote attackers to cause a denial of service (segfault) via vectors involving corrupt chunks.
CVE-2016-1516HIGH8.8OpenCV 3.0.0 has a double free issue that allows attackers to execute arbitrary code.
CVE-2016-7786Sophos Cyberoam UTM CR25iNG 10.6.3 MR-5 allows remote authenticated users to bypass intended access restrictions via dir...
CVE-2016-6805Apache Ignite before 1.9 allows man-in-the-middle attackers to read arbitrary files via XXE in modified update-notifier ...
CVE-2016-9197A vulnerability in the CLI command parser of the Cisco Mobility Express 2800 and 3800 Series Wireless LAN Controllers co...
CVE-2016-9196A vulnerability in login authentication management in Cisco Aironet 1800, 2800, and 3800 Series Access Point platforms c...
CVE-2016-9195A vulnerability in RADIUS Change of Authorization (CoA) request processing in the Cisco Wireless LAN Controller (WLC) co...
CVE-2016-1000307Multiple Cross Site Scripting (XSS) Vulnerabilities in ClipBucket v2.8.1 and probably prior allow Remote Attackers to in...
CVE-2016-1000306Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-1000307. Reason: This candidate is a reservatio...
CVE-2016-8735CRITICAL9.8Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8...
CVE-2016-6809CRITICAL9.8Apache Tika before 1.14 allows Java code execution for serialized objects embedded in MATLAB files. The issue exists bec...
CVE-2016-5349The high level operating systems (HLOS) was not providing sufficient memory address information to ensure that secure ap...
CVE-2016-9219A vulnerability with IPv6 UDP ingress packet processing in Cisco Wireless LAN Controller (WLC) Software could allow an u...
CVE-2016-9194A vulnerability in 802.11 Wireless Multimedia Extensions (WME) action frame processing in Cisco Wireless LAN Controller ...
CVE-2016-10320textract before 1.5.0 allows OS Command Injection attacks via a filename in a call to the process function. This may be ...
CVE-2016-10319In ARM Trusted Firmware 1.2 and 1.3, a malformed firmware update SMC can result in copying unexpectedly large data into ...
CVE-2016-6100IBM Disposal and Governance Management for IT and IBM Global Retention Policy and Schedule Management, components of IBM...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now