2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-6059 | — | — | 1.5% | Feb 1, 2017 | IBM InfoSphere Information Server is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE)... |
| CVE-2016-6054 | — | — | 0.5% | Feb 1, 2017 | IBM Jazz Foundation is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript... |
| CVE-2016-6047 | — | — | 0.5% | Feb 1, 2017 | IBM Jazz Reporting Service (JRS) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitra... |
| CVE-2016-6046 | — | — | 0.5% | Feb 1, 2017 | IBM Tivoli Storage Manager Operations Center is vulnerable to cross-site scripting. This vulnerability allows users to e... |
| CVE-2016-6045 | — | — | 0.6% | Feb 1, 2017 | IBM Tivoli Storage Manager Operations Center is vulnerable to cross-site request forgery which could allow an attacker t... |
| CVE-2016-6044 | — | — | 0.6% | Feb 1, 2017 | IBM Tivoli Storage Manager Operations Center could allow an authenticated attacker to enable or disable the application'... |
| CVE-2016-6043 | — | — | 0.2% | Feb 1, 2017 | Tivoli Storage Manager Operations Center could allow a local user to take over a previously logged in user due to sessio... |
| CVE-2016-6042 | — | — | 2.6% | Feb 1, 2017 | IBM AppScan Enterprise Edition could allow a remote attacker to execute arbitrary code on the system, caused by improper... |
| CVE-2016-6040 | — | — | 0.5% | Feb 1, 2017 | IBM Jazz Foundation could allow an authenticated user to take over a previously logged in user due to session expiration... |
| CVE-2016-6039 | — | — | 0.5% | Feb 1, 2017 | IBM Jazz Reporting Service (JRS) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitra... |
| CVE-2016-6034 | — | — | 1.0% | Feb 1, 2017 | IBM Tivoli Storage Manager for Virtual Environments (VMware) could disclose the Windows domain credentials to a user wit... |
| CVE-2016-6030 | — | — | 0.5% | Feb 1, 2017 | IBM Jazz Foundation is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript... |
| CVE-2016-6028 | — | — | 0.8% | Feb 1, 2017 | IBM Jazz technology based products might allow an attacker to view work item titles that they do not have privilege to v... |
| CVE-2016-6020 | — | — | 0.8% | Feb 1, 2017 | IBM Sterling B2B Integrator Standard Edition could allow a remote attacker to conduct phishing attacks, using an open re... |
| CVE-2016-6000 | — | — | 0.7% | Feb 1, 2017 | IBM TRIRIGA Application Platform is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitra... |
| CVE-2016-5994 | — | — | 1.2% | Feb 1, 2017 | IBM InfoSphere Information Server contains a vulnerability that would allow an authenticated user to browse any file on ... |
| CVE-2016-5990 | — | — | 0.6% | Feb 1, 2017 | IBM Security Privileged Identity Manager Virtual Appliance allows an authenticated user to upload malicious files that w... |
| CVE-2016-5988 | — | — | 1.0% | Feb 1, 2017 | IBM Security Privileged Identity Manager Virtual Appliance could disclose sensitive information in generated error messa... |
| CVE-2016-5985 | — | — | 0.4% | Feb 1, 2017 | The IBM Tivoli Storage Manager (IBM Spectrum Protect) AIX client is vulnerable to a buffer overflow when Journal-Based B... |
| CVE-2016-5984 | — | — | 0.9% | Feb 1, 2017 | IBM InfoSphere Information Server is vulnerable to cross-frame scripting, caused by insufficient HTML iframe protection.... |
| CVE-2016-5980 | — | — | 0.5% | Feb 1, 2017 | IBM TRIRIGA Application Platform is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitra... |
| CVE-2016-5966 | — | — | 1.2% | Feb 1, 2017 | IBM Security Privileged Identity Manager Virtual Appliance could allow a remote attacker to obtain sensitive information... |
| CVE-2016-5964 | — | — | 1.6% | Feb 1, 2017 | IBM Security Privileged Identity Manager Virtual Appliance version 2.0.2 uses an inadequate account lockout setting that... |
| CVE-2016-5958 | — | — | 1.7% | Feb 1, 2017 | IBM Security Privileged Identity Manager could allow a remote attacker to obtain sensitive information, caused by the fa... |
| CVE-2016-5952 | — | — | 1.4% | Feb 1, 2017 | IBM Kenexa LCMS Premier on Cloud is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL stat... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now