2016 CVE Vulnerabilities

10,648 CVEs published in 2016.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2016-5802——An issue was discovered in Delta Electronics WPLSoft, Versions prior to V2.42.11, ISPSoft, Versions prior to 3.02.11, an...
CVE-2016-5801——An issue was discovered in OmniMetrix OmniView, Version 1.2. Insufficient password requirements for the OmniView web app...
CVE-2016-5798——An issue was discovered in Fatek Automation PM Designer V3 Version 2.1.2.2, and Automation FV Designer Version 1.2.8.0. ...
CVE-2016-5796——An issue was discovered in Fatek Automation PM Designer V3 Version 2.1.2.2, and Automation FV Designer Version 1.2.8.0. ...
CVE-2016-5786——An issue was discovered in OmniMetrix OmniView, Version 1.2. The OmniView web application transmits credentials with the...
CVE-2016-5782——An issue was discovered in Locus Energy LGate prior to 1.05H, LGate 50, LGate 100, LGate 101, LGate 120, and LGate 320. ...
CVE-2016-2274——An issue was discovered in Adcon Telemetry A850 Telemetry Gateway Base Station. The Web Interface does not neutralize or...
CVE-2016-8859——Multiple integer overflows in the TRE library and musl libc allow attackers to cause memory corruption via a large numbe...
CVE-2016-8659——Bubblewrap before 0.1.3 sets the PR_SET_DUMPABLE flag, which might allow local users to gain privileges by attaching to ...
CVE-2016-7565——install/index.php in Exponent CMS 2.3.9 allows remote attackers to execute arbitrary commands via shell metacharacters i...
CVE-2016-5100——Froxlor before 0.9.35 uses the PHP rand function for random number generation, which makes it easier for remote attacker...
CVE-2016-4547——Samsung devices with Android KK(4.4), L(5.0/5.1), or M(6.0) allow attackers to cause a denial of service (system crash) ...
CVE-2016-4546——Samsung devices with Android KK(4.4) or L(5.0/5.1) allow local users to cause a denial of service (IAndroidShm service c...
CVE-2016-3995——The timing attack protection in Rijndael::Enc::ProcessAndXorBlock and Rijndael::Dec::ProcessAndXorBlock in Crypto++ (aka...
CVE-2016-3616——The cjpeg utility in libjpeg allows remote attackers to cause a denial of service (NULL pointer dereference and applicat...
CVE-2016-2788——MCollective 2.7.0 and 2.8.x before 2.8.9, as used in Puppet Enterprise, allows remote attackers to execute arbitrary cod...
CVE-2016-2787——The Puppet Communications Protocol in Puppet Enterprise 2015.3.x before 2015.3.3 does not properly validate certificates...
CVE-2016-10026——ikiwiki 3.20161219 does not properly check if a revision changes the access permissions for a page on sites with the git...
CVE-2016-8495——An improper certificate validation vulnerability in Fortinet FortiManager 5.0.6 through 5.2.7 and 5.4.0 through 5.4.1 al...
CVE-2016-10216——An issue was discovered in IT ITems DataBase (ITDB) through 1.23. The vulnerability exists due to insufficient filtratio...
CVE-2016-10215——An issue was discovered in Fastspot BigTree bigtree-form-builder before 1.2. The vulnerability exists due to insufficien...
CVE-2016-9244——A BIG-IP virtual server configured with a Client SSL profile that has the non-default Session Tickets option enabled may...
CVE-2016-8494——Insufficient verification of uploaded files allows attackers with webui administrators privileges to perform arbitrary c...
CVE-2016-6173——NSD before 4.1.11 allows remote DNS master servers to cause a denial of service (/tmp disk consumption and slave server ...
CVE-2016-5727——LogInOut.php in Simple Machines Forum (SMF) 2.1 allows remote attackers to conduct PHP object injection attacks and exec...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now