2016 CVE Vulnerabilities

10,648 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-8917——IBM Sterling Order Management 9.2 - 9.5 is vulnerable to cross-site request forgery which could allow an attacker to exe...
CVE-2016-6111——IBM Curam Social Program Management 6.0 and 7.0 are vulnerable to a denial of service, caused by an XML External Entity ...
CVE-2016-6036——IBM Rational Quality Manager (RQM) 4.0, 5.0, and 6.0 are vulnerable to cross-site scripting. This vulnerability allows u...
CVE-2016-6031——IBM Rational Quality Manager 4.0, 5.0, and 6.0 are vulnerable to cross-site scripting. This vulnerability allows users t...
CVE-2016-6022——IBM Quality Manager (RQM) 4.0, 5.0, and 6.0 are vulnerable to cross-site scripting. This vulnerability allows users to e...
CVE-2016-6209——Cross-site scripting (XSS) vulnerability in Nagios.
CVE-2016-9319——There is Missing SSL Certificate Validation in the Trend Micro Enterprise Mobile Security Android Application before 9.7...
CVE-2016-7542——A read-only administrator on Fortinet devices with FortiOS 5.2.x before 5.2.10 GA and 5.4.x before 5.4.2 GA may have acc...
CVE-2016-7541——Long lived sessions in Fortinet FortiGate devices with FortiOS 5.x before 5.4.0 could violate a security policy during I...
CVE-2016-10309——In the GUI of Ceragon FibeAir IP-10 (before 7.2.0) devices, a remote attacker can bypass authentication by adding an ALB...
CVE-2016-10308——Siklu EtherHaul radios before 3.7.1 and 6.x before 6.9.0 have a built-in, hidden root account, with an unchangeable pass...
CVE-2016-10307CRITICAL9.8Trango ApexLynx 2.0, ApexOrion 2.0, GigaLynx 2.0, GigaOrion 2.0, and StrataLink 3.0 devices have a built-in, hidden root...
CVE-2016-10306——Trango Altum AC600 devices have a built-in, hidden root account, with a default password of abcd1234. This account is ac...
CVE-2016-10305CRITICAL9.8Trango Apex <= 2.1.1, ApexLynx < 2.0, ApexOrion < 2.0, ApexPlus <= 3.2.0, Giga <= 2.6.1, GigaLynx < 2.0, GigaOrion < 2.0...
CVE-2016-6349——The machinectl command in oci-register-machine allows local users to list running containers and possibly obtain sensiti...
CVE-2016-4976——Apache Ambari 2.x before 2.4.0 includes KDC administrator passwords on the kadmin command line, which allows local users...
CVE-2016-2379——The Mxit protocol uses weak encryption when encrypting user passwords, which might allow attackers to (1) decrypt hashed...
CVE-2016-9924——Zimbra Collaboration Suite (ZCS) before 8.7.4 allows remote attackers to conduct XML External Entity (XXE) attacks.
CVE-2016-6846——Cross-site scripting (XSS) vulnerability in Open-Xchange (OX) AppSuite backend before 7.6.2-rev59, 7.8.0 before 7.8.0-re...
CVE-2016-6807——Custom commands may be executed on Ambari Agent (2.4.x, before 2.4.2) hosts without authorization, leading to unauthoriz...
CVE-2016-8749——Apache Camel's Jackson and JacksonXML unmarshalling operation are vulnerable to Remote Code Execution attacks.
CVE-2016-8031HIGH7.3Software Integrity Attacks vulnerability in Intel Security Anti-Virus Engine (AVE) 5200 through 5800 allows local users ...
CVE-2016-8884——The bmp_getdata function in libjasper/bmp/bmp_dec.c in JasPer 1.900.5 allows remote attackers to cause a denial of servi...
CVE-2016-10152——The read_config_file function in lib/hesiod.c in Hesiod 3.2.1 falls back to the ".athena.mit.edu" default domain when op...
CVE-2016-9473MEDIUM4.7Brave Browser iOS before 1.2.18 and Brave Browser Android 1.9.56 and earlier suffer from Full Address Bar Spoofing, allo...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now