2016 CVE Vulnerabilities

10,647 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-6111IBM Curam Social Program Management 6.0 and 7.0 are vulnerable to a denial of service, caused by an XML External Entity ...
CVE-2016-6036IBM Rational Quality Manager (RQM) 4.0, 5.0, and 6.0 are vulnerable to cross-site scripting. This vulnerability allows u...
CVE-2016-6031IBM Rational Quality Manager 4.0, 5.0, and 6.0 are vulnerable to cross-site scripting. This vulnerability allows users t...
CVE-2016-6022IBM Quality Manager (RQM) 4.0, 5.0, and 6.0 are vulnerable to cross-site scripting. This vulnerability allows users to e...
CVE-2016-6209Cross-site scripting (XSS) vulnerability in Nagios.
CVE-2016-9319There is Missing SSL Certificate Validation in the Trend Micro Enterprise Mobile Security Android Application before 9.7...
CVE-2016-7542A read-only administrator on Fortinet devices with FortiOS 5.2.x before 5.2.10 GA and 5.4.x before 5.4.2 GA may have acc...
CVE-2016-7541Long lived sessions in Fortinet FortiGate devices with FortiOS 5.x before 5.4.0 could violate a security policy during I...
CVE-2016-10309In the GUI of Ceragon FibeAir IP-10 (before 7.2.0) devices, a remote attacker can bypass authentication by adding an ALB...
CVE-2016-10308Siklu EtherHaul radios before 3.7.1 and 6.x before 6.9.0 have a built-in, hidden root account, with an unchangeable pass...
CVE-2016-10307CRITICAL9.8Trango ApexLynx 2.0, ApexOrion 2.0, GigaLynx 2.0, GigaOrion 2.0, and StrataLink 3.0 devices have a built-in, hidden root...
CVE-2016-10306Trango Altum AC600 devices have a built-in, hidden root account, with a default password of abcd1234. This account is ac...
CVE-2016-10305CRITICAL9.8Trango Apex <= 2.1.1, ApexLynx < 2.0, ApexOrion < 2.0, ApexPlus <= 3.2.0, Giga <= 2.6.1, GigaLynx < 2.0, GigaOrion < 2.0...
CVE-2016-6349The machinectl command in oci-register-machine allows local users to list running containers and possibly obtain sensiti...
CVE-2016-4976Apache Ambari 2.x before 2.4.0 includes KDC administrator passwords on the kadmin command line, which allows local users...
CVE-2016-2379The Mxit protocol uses weak encryption when encrypting user passwords, which might allow attackers to (1) decrypt hashed...
CVE-2016-9924Zimbra Collaboration Suite (ZCS) before 8.7.4 allows remote attackers to conduct XML External Entity (XXE) attacks.
CVE-2016-6846Cross-site scripting (XSS) vulnerability in Open-Xchange (OX) AppSuite backend before 7.6.2-rev59, 7.8.0 before 7.8.0-re...
CVE-2016-6807Custom commands may be executed on Ambari Agent (2.4.x, before 2.4.2) hosts without authorization, leading to unauthoriz...
CVE-2016-8749Apache Camel's Jackson and JacksonXML unmarshalling operation are vulnerable to Remote Code Execution attacks.
CVE-2016-8031HIGH7.3Software Integrity Attacks vulnerability in Intel Security Anti-Virus Engine (AVE) 5200 through 5800 allows local users ...
CVE-2016-8884The bmp_getdata function in libjasper/bmp/bmp_dec.c in JasPer 1.900.5 allows remote attackers to cause a denial of servi...
CVE-2016-10152The read_config_file function in lib/hesiod.c in Hesiod 3.2.1 falls back to the ".athena.mit.edu" default domain when op...
CVE-2016-9473MEDIUM4.7Brave Browser iOS before 1.2.18 and Brave Browser Android 1.9.56 and earlier suffer from Full Address Bar Spoofing, allo...
CVE-2016-9472Revive Adserver before 3.2.5 and 4.0.0 suffers from Reflected XSS. The Revive Adserver web installer scripts were vulner...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now