2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-5951 | — | — | 0.5% | Feb 1, 2017 | IBM Kenexa LCMS Premier on Cloud is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitra... |
| CVE-2016-5950 | — | — | 1.0% | Feb 1, 2017 | IBM Kenexa LCMS Premier on Cloud stores user credentials in plain in clear text which can be read by an authenticated us... |
| CVE-2016-5949 | — | — | 1.3% | Feb 1, 2017 | IBM Kenexa LCMS Premier on Cloud could allow an authenticated user to obtain sensitive user data with a specially crafte... |
| CVE-2016-5948 | — | — | 0.5% | Feb 1, 2017 | IBM Kenexa LCMS Premier on Cloud is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitra... |
| CVE-2016-5939 | — | — | 0.8% | Feb 1, 2017 | IBM Kenexa LMS on Cloud is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, w... |
| CVE-2016-5937 | — | — | 0.6% | Feb 1, 2017 | IBM Kenexa LCMS Premier on Cloud is vulnerable to cross-site request forgery which could allow an attacker to execute ma... |
| CVE-2016-5899 | — | — | 0.5% | Feb 1, 2017 | IBM Jazz Reporting Service (JRS) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitra... |
| CVE-2016-5898 | — | — | 0.9% | Feb 1, 2017 | IBM Jazz Reporting Service (JRS) could allow a remote attacker to obtain sensitive information, caused by not restrictin... |
| CVE-2016-5897 | — | — | 0.6% | Feb 1, 2017 | IBM Jazz Reporting Service (JRS) is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, wh... |
| CVE-2016-5896 | — | — | 1.0% | Feb 1, 2017 | IBM Maximo Asset Management could disclose sensitive information from a stack trace after submitting incorrect login ont... |
| CVE-2016-5884 | — | — | 1.0% | Feb 1, 2017 | IBM iNotes is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in ... |
| CVE-2016-5882 | — | — | 1.0% | Feb 1, 2017 | IBM iNotes is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in ... |
| CVE-2016-5880 | — | — | 0.7% | Feb 1, 2017 | IBM iNotes is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in ... |
| CVE-2016-3053 | — | — | 2.5% | Feb 1, 2017 | IBM AIX contains an unspecified vulnerability that would allow a locally authenticated user to obtain root level privile... |
| CVE-2016-3046 | — | — | 0.9% | Feb 1, 2017 | IBM Security Access Manager for Web is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL s... |
| CVE-2016-3045 | — | — | 0.8% | Feb 1, 2017 | IBM Security Access Manager for Web stores sensitive information in URL parameters. This may lead to information disclos... |
| CVE-2016-3043 | — | — | 1.2% | Feb 1, 2017 | IBM Security Access Manager for Web could allow a remote attacker to obtain sensitive information, caused by the failure... |
| CVE-2016-3035 | — | — | 1.0% | Feb 1, 2017 | IBM AppScan Source could reveal some sensitive information through the browsing of testlinks on the server. |
| CVE-2016-3034 | — | — | 0.2% | Feb 1, 2017 | IBM AppScan Source uses a one-way hash without salt to encrypt highly sensitive information, which could allow a local a... |
| CVE-2016-3029 | — | — | 0.5% | Feb 1, 2017 | IBM Security Access Manager for Web is vulnerable to cross-site request forgery which could allow an attacker to execute... |
| CVE-2016-3027 | — | — | 1.3% | Feb 1, 2017 | IBM Security Access Manager for Web is vulnerable to a denial of service, caused by an XML External Entity Injection (XX... |
| CVE-2016-3024 | — | — | 0.3% | Feb 1, 2017 | IBM Security Access Manager for Web allows web pages to be stored locally which can be read by another user on the syste... |
| CVE-2016-3023 | — | — | 1.1% | Feb 1, 2017 | IBM Security Access Manager for Web could allow an unauthenticated user to gain access to sensitive information by enter... |
| CVE-2016-3021 | — | — | 1.0% | Feb 1, 2017 | IBM Security Access Manager for Web could allow an authenticated attacker to obtain sensitive information from error mes... |
| CVE-2016-3018 | — | — | 0.8% | Feb 1, 2017 | IBM Security Access Manager for Web is vulnerable to cross-site scripting. This vulnerability allows users to embed arbi... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now