2016 CVE Vulnerabilities

10,647 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-11078MEDIUM6.5An issue was discovered in Mattermost Server before 3.0.0. It potentially allows attackers to obtain sensitive informati...
CVE-2016-11077LOW2.7An issue was discovered in Mattermost Server before 3.0.0. It has a superfluous API in which the System Admin can change...
CVE-2016-11076MEDIUM5.3An issue was discovered in Mattermost Server before 3.0.0. It does not ensure that a cookie is used over SSL.
CVE-2016-11075MEDIUM5.3An issue was discovered in Mattermost Server before 3.0.0. It allows attackers to obtain sensitive information about tea...
CVE-2016-11074CRITICAL9.8An issue was discovered in Mattermost Server before 3.0.0. A password-reset link could be reused.
CVE-2016-11073MEDIUM6.1An issue was discovered in Mattermost Server before 3.0.0. It allows XSS via a Legal or Support setting.
CVE-2016-11072MEDIUM6.5An issue was discovered in Mattermost Server before 3.0.2. The purposes of a session ID and a Session Token were mishand...
CVE-2016-11071MEDIUM6.1An issue was discovered in Mattermost Server before 3.1.0. It allows XSS because the noreferrer and noopener protection ...
CVE-2016-11070MEDIUM5.4An issue was discovered in Mattermost Server before 3.1.0. It allows XSS via theme color-code values.
CVE-2016-11069HIGH7.5An issue was discovered in Mattermost Server before 3.2.0. It mishandles brute-force attempts at password change.
CVE-2016-11068MEDIUM5.3An issue was discovered in Mattermost Server before 3.2.0. Attackers could read LDAP fields via injection.
CVE-2016-11067MEDIUM5.3An issue was discovered in Mattermost Server before 3.2.0. It allowed crafted posts that could cause a web browser to ha...
CVE-2016-11066HIGH7.5An issue was discovered in Mattermost Server before 3.2.0. The initial_load API disclosed unnecessary personal informati...
CVE-2016-11065MEDIUM4.3An issue was discovered in Mattermost Server before 3.3.0. An attacker could use the WebSocket feature to send pop-up me...
CVE-2016-11064CRITICAL9.8An issue was discovered in Mattermost Desktop App before 3.4.0. Strings could be executed as code via injection.
CVE-2016-11063MEDIUM6.1An issue was discovered in Mattermost Server before 3.5.1. XSS can occur via file preview.
CVE-2016-11062MEDIUM5.3An issue was discovered in Mattermost Server before 3.5.1. E-mail address verification can be bypassed.
CVE-2016-11061CRITICAL9.8Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, and 7970i devices b...
CVE-2016-11060HIGH7.5Certain NETGEAR devices are affected by insecure renegotiation. This affects SRX5308 before 2017-02-10, FVS336Gv3 before...
CVE-2016-11059HIGH7.5Certain NETGEAR devices are affected by password exposure. This affects AC1450 before 2017-01-06, C6300 before 2017-01-0...
CVE-2016-11058HIGH7.5The NETGEAR genie application before 2.4.34 for Android is affected by mishandling of hard-coded API keys and session ID...
CVE-2016-11057HIGH7.5Certain NETGEAR devices are affected by mishandling of repeated URL calls. This affects JNR1010v2 before 2017-01-06, WNR...
CVE-2016-11056HIGH8.8Certain NETGEAR devices are affected by anonymous root access. This affects ReadyNAS Surveillance 1.1.1-3-armel and earl...
CVE-2016-11055MEDIUM4.3Certain NETGEAR devices are affected by CSRF. This affects CM400 before 2017-01-11, CM600 before 2017-01-11, D1500 befor...
CVE-2016-11054HIGH7.2NETGEAR DGN2200v4 devices before 2017-01-06 are affected by command execution and an FTP insecure root directory.

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now