2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-1566 | — | — | 2.2% | Feb 2, 2017 | Cross-site scripting (XSS) vulnerability in the file browser in Guacamole 0.9.8 and 0.9.9, when file transfer is enabled... |
| CVE-2016-9739 | — | — | 0.4% | Feb 1, 2017 | IBM Security Identity Manager Virtual Appliance stores user credentials in plain in clear text which can be read by a lo... |
| CVE-2016-9704 | — | — | 1.0% | Feb 1, 2017 | IBM Security Identity Manager Virtual Appliance is vulnerable to cross-site scripting. This vulnerability allows users t... |
| CVE-2016-9703 | — | — | 0.3% | Feb 1, 2017 | IBM Security Identity Manager Virtual Appliance does not invalidate session tokens which could allow an unauthorized use... |
| CVE-2016-9008 | — | — | 1.0% | Feb 1, 2017 | IBM UrbanCode Deploy could allow a malicious user to access the Agent Relay ActiveMQ Broker JMX interface and run plugin... |
| CVE-2016-9000 | — | — | 1.1% | Feb 1, 2017 | IBM InfoSphere DataStage is vulnerable to cross-frame scripting, caused by insufficient HTML iframe protection. A remote... |
| CVE-2016-8999 | — | — | 0.7% | Feb 1, 2017 | IBM InfoSphere Information Server contains a Path-relative stylesheet import vulnerability that allows attackers to rend... |
| CVE-2016-8982 | — | — | 1.3% | Feb 1, 2017 | IBM InfoSphere Information Server stores sensitive information in URL parameters. This may lead to information disclosur... |
| CVE-2016-8977 | — | — | 1.1% | Feb 1, 2017 | IBM BigFix Inventory v9 could disclose sensitive information to an unauthorized user using HTTP GET requests. This infor... |
| CVE-2016-8963 | — | — | 0.3% | Feb 1, 2017 | IBM BigFix Inventory v9 stores potentially sensitive information in log files that could be read by a local user. |
| CVE-2016-8938 | — | — | 2.8% | Feb 1, 2017 | IBM UrbanCode Deploy could allow a user to execute code using a specially crafted file upload that would replace code on... |
| CVE-2016-8933 | — | — | 1.8% | Feb 1, 2017 | IBM Kenexa LMS on Cloud could allow a remote attacker to traverse directories on the system. An attacker could send a sp... |
| CVE-2016-8932 | — | — | 1.9% | Feb 1, 2017 | IBM Kenexa LMS on Cloud could allow a remote attacker to upload arbitrary files, which could allow the attacker to execu... |
| CVE-2016-8931 | — | — | 1.9% | Feb 1, 2017 | IBM Kenexa LMS on Cloud could allow a remote attacker to upload arbitrary files, which could allow the attacker to execu... |
| CVE-2016-8930 | — | — | 1.0% | Feb 1, 2017 | IBM Kenexa LMS on Cloud is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, w... |
| CVE-2016-8929 | — | — | 0.9% | Feb 1, 2017 | IBM Kenexa LMS on Cloud is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, w... |
| CVE-2016-8928 | — | — | 1.0% | Feb 1, 2017 | IBM Kenexa LMS on Cloud is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, w... |
| CVE-2016-8919 | — | — | 2.8% | Feb 1, 2017 | IBM WebSphere Application Server may be vulnerable to a denial of service, caused by allowing serialized objects from un... |
| CVE-2016-6115 | — | — | 4.0% | Feb 1, 2017 | IBM General Parallel File System is vulnerable to a buffer overflow. A remote authenticated attacker could overflow a bu... |
| CVE-2016-6110 | — | — | 0.3% | Feb 1, 2017 | IBM Tivoli Storage Manager discloses unencrypted login credentials to Vmware vCenter that could be obtained by a local u... |
| CVE-2016-6068 | — | — | 1.4% | Feb 1, 2017 | IBM UrbanCode Deploy could allow an authenticated user with access to the REST endpoints to access API and CLI getResour... |
| CVE-2016-6001 | — | — | 0.6% | Feb 1, 2017 | IBM Forms Experience Builder could be susceptible to a server-side request forgery (SSRF) from the application design in... |
| CVE-2016-5953 | — | — | 0.8% | Feb 1, 2017 | IBM Sterling Order Management transmits the session identifier within the URL. When a user is unable to view a certain v... |
| CVE-2016-5942 | — | — | 0.6% | Feb 1, 2017 | IBM Kenexa LMS on Cloud is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaSc... |
| CVE-2016-5941 | — | — | 1.6% | Feb 1, 2017 | IBM Kenexa LMS on Cloud could allow a remote attacker to traverse directories on the system. An attacker could send a sp... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now