2016 CVE Vulnerabilities

10,647 CVEs published in 2016.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2016-6115IBM General Parallel File System is vulnerable to a buffer overflow. A remote authenticated attacker could overflow a bu...
CVE-2016-6110IBM Tivoli Storage Manager discloses unencrypted login credentials to Vmware vCenter that could be obtained by a local u...
CVE-2016-6068IBM UrbanCode Deploy could allow an authenticated user with access to the REST endpoints to access API and CLI getResour...
CVE-2016-6001IBM Forms Experience Builder could be susceptible to a server-side request forgery (SSRF) from the application design in...
CVE-2016-5953IBM Sterling Order Management transmits the session identifier within the URL. When a user is unable to view a certain v...
CVE-2016-5942IBM Kenexa LMS on Cloud is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaSc...
CVE-2016-5941IBM Kenexa LMS on Cloud could allow a remote attacker to traverse directories on the system. An attacker could send a sp...
CVE-2016-5940IBM Kenexa LMS on Cloud is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaSc...
CVE-2016-5938IBM Kenexa LMS on Cloud allows web pages to be stored locally which can be read by another user on the system.
CVE-2016-5881IBM iNotes is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in ...
CVE-2016-2992IBM Infosphere BigInsights is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Jav...
CVE-2016-2942IBM UrbanCode Deploy could allow an authenticated attacker with special permissions to craft a script on the server in a...
CVE-2016-2941IBM UrbanCode Deploy creates temporary files during step execution that could contain sensitive information including pa...
CVE-2016-2924IBM Infosphere BigInsights is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. ...
CVE-2016-0320IBM UrbanCode Deploy could allow an authenticated user to modify Ucd objects due to multiple REST endpoints not properly...
CVE-2016-0218IBM Cognos Business Intelligence and IBM Cognos Analytics are vulnerable to cross-site scripting, caused by improper val...
CVE-2016-0217IBM Cognos Business Intelligence and IBM Cognos Analytics are vulnerable to stored cross-site scripting, caused by impro...
CVE-2016-8967IBM BigFix Inventory v9 9.2 stores user credentials in plain in clear text which can be read by a local user.
CVE-2016-6117IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 can be deployed with active debugging code that can disclose sensitive info...
CVE-2016-6105IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 do not perform an authentication check for a critical resource or functiona...
CVE-2016-9731IBM Business Process Manager is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary J...
CVE-2016-8981IBM BigFix Inventory v9 allows web pages to be stored locally which can be read by another user on the system.
CVE-2016-8980IBM BigFix Inventory v9 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error whe...
CVE-2016-8966IBM BigFix Inventory v9 could allow a remote attacker to obtain sensitive information, caused by the failure to properly...
CVE-2016-8961IBM BigFix Inventory v9 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By per...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now