2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-7784 | — | — | 2.6% | Mar 7, 2017 | SQL injection vulnerability in the getSection function in framework/core/subsystems/expRouter.php in Exponent CMS 2.3.9 ... |
| CVE-2016-7783 | — | — | 2.6% | Mar 7, 2017 | SQL injection vulnerability in framework/core/models/expRecord.php in Exponent CMS 2.3.9 and earlier allows remote attac... |
| CVE-2016-7782 | — | — | 2.6% | Mar 7, 2017 | SQL injection vulnerability in framework/core/models/expConfig.php in Exponent CMS 2.3.9 and earlier allows remote attac... |
| CVE-2016-7781 | — | — | 2.6% | Mar 7, 2017 | SQL injection vulnerability in framework/modules/blog/controllers/blogController.php in Exponent CMS 2.3.9 and earlier a... |
| CVE-2016-7780 | — | — | 2.6% | Mar 7, 2017 | SQL injection vulnerability in cron/find_help.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute a... |
| CVE-2016-7140 | — | — | 1.6% | Mar 7, 2017 | Multiple cross-site scripting (XSS) vulnerabilities in the ZMI page in Zope2 in Plone CMS 5.x through 5.0.6, 4.x through... |
| CVE-2016-7139 | — | — | 1.6% | Mar 7, 2017 | Cross-site scripting (XSS) vulnerability in an unspecified page template in Plone CMS 5.x through 5.0.6, 4.x through 4.3... |
| CVE-2016-7138 | — | — | 1.6% | Mar 7, 2017 | Cross-site scripting (XSS) vulnerability in the URL checking infrastructure in Plone CMS 5.x through 5.0.6, 4.x through ... |
| CVE-2016-7137 | — | — | 1.7% | Mar 7, 2017 | Multiple open redirect vulnerabilities in Plone CMS 5.x through 5.0.6, 4.x through 4.3.11, and 3.3.x through 3.3.6 allow... |
| CVE-2016-7136 | — | — | 1.6% | Mar 7, 2017 | z3c.form in Plone CMS 5.x through 5.0.6 and 4.x through 4.3.11 allows remote attackers to conduct cross-site scripting (... |
| CVE-2016-7135 | — | — | 2.6% | Mar 7, 2017 | Directory traversal vulnerability in Plone CMS 5.x through 5.0.6 and 4.2.x through 4.3.11 allows remote administrators t... |
| CVE-2016-6522 | — | — | 0.4% | Mar 7, 2017 | Integer overflow in the uvm_map_isavail function in uvm/uvm_map.c in OpenBSD 5.9 allows local users to cause a denial of... |
| CVE-2016-6350 | — | — | 0.4% | Mar 7, 2017 | OpenBSD 5.8 and 5.9 allows local users to cause a denial of service (NULL pointer dereference and panic) via a sysctl ca... |
| CVE-2016-6255 | — | — | 26.8% | Mar 7, 2017 | Portable UPnP SDK (aka libupnp) before 1.6.21 allows remote attackers to write to arbitrary files in the webroot via a P... |
| CVE-2016-6247 | — | — | 0.4% | Mar 7, 2017 | OpenBSD 5.8 and 5.9 allows certain local users to cause a denial of service (kernel panic) by unmounting a filesystem wi... |
| CVE-2016-6246 | — | — | 0.4% | Mar 7, 2017 | OpenBSD 5.8 and 5.9 allows certain local users with kern.usermount privileges to cause a denial of service (kernel panic... |
| CVE-2016-6245 | — | — | 0.4% | Mar 7, 2017 | OpenBSD 5.8 and 5.9 allows local users to cause a denial of service (kernel panic) via a large size in a getdents system... |
| CVE-2016-6243 | — | — | 0.4% | Mar 7, 2017 | thrsleep in kern/kern_synch.c in OpenBSD 5.8 and 5.9 allows local users to cause a denial of service (kernel panic) via ... |
| CVE-2016-6242 | — | — | 0.4% | Mar 7, 2017 | OpenBSD 5.8 and 5.9 allows local users to cause a denial of service (assertion failure and kernel panic) via a large ide... |
| CVE-2016-6241 | — | — | 0.6% | Mar 7, 2017 | Integer overflow in the amap_alloc1 function in OpenBSD 5.8 and 5.9 allows local users to execute arbitrary code with ke... |
| CVE-2016-6240 | — | — | 0.6% | Mar 7, 2017 | Integer truncation error in the amap_alloc function in OpenBSD 5.8 and 5.9 allows local users to execute arbitrary code ... |
| CVE-2016-6239 | — | — | 0.5% | Mar 7, 2017 | The mmap extension __MAP_NOFAULT in OpenBSD 5.8 and 5.9 allows attackers to cause a denial of service (kernel panic and ... |
| CVE-2016-4950 | — | — | 1.6% | Mar 7, 2017 | Cloudera Manager 5.5 and earlier allows remote attackers to enumerate user sessions via a request to /api/v11/users/sess... |
| CVE-2016-4949 | — | — | 1.6% | Mar 7, 2017 | Cloudera Manager 5.5 and earlier allows remote attackers to obtain sensitive information via a (1) stderr.log or (2) std... |
| CVE-2016-4948 | — | — | 0.5% | Mar 7, 2017 | Multiple cross-site scripting (XSS) vulnerabilities in Cloudera Manager 5.5 and earlier allow remote attackers to inject... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now