2016 CVE Vulnerabilities

10,647 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-1566Cross-site scripting (XSS) vulnerability in the file browser in Guacamole 0.9.8 and 0.9.9, when file transfer is enabled...
CVE-2016-9739IBM Security Identity Manager Virtual Appliance stores user credentials in plain in clear text which can be read by a lo...
CVE-2016-9704IBM Security Identity Manager Virtual Appliance is vulnerable to cross-site scripting. This vulnerability allows users t...
CVE-2016-9703IBM Security Identity Manager Virtual Appliance does not invalidate session tokens which could allow an unauthorized use...
CVE-2016-9008IBM UrbanCode Deploy could allow a malicious user to access the Agent Relay ActiveMQ Broker JMX interface and run plugin...
CVE-2016-9000IBM InfoSphere DataStage is vulnerable to cross-frame scripting, caused by insufficient HTML iframe protection. A remote...
CVE-2016-8999IBM InfoSphere Information Server contains a Path-relative stylesheet import vulnerability that allows attackers to rend...
CVE-2016-8982IBM InfoSphere Information Server stores sensitive information in URL parameters. This may lead to information disclosur...
CVE-2016-8977IBM BigFix Inventory v9 could disclose sensitive information to an unauthorized user using HTTP GET requests. This infor...
CVE-2016-8963IBM BigFix Inventory v9 stores potentially sensitive information in log files that could be read by a local user.
CVE-2016-8938IBM UrbanCode Deploy could allow a user to execute code using a specially crafted file upload that would replace code on...
CVE-2016-8933IBM Kenexa LMS on Cloud could allow a remote attacker to traverse directories on the system. An attacker could send a sp...
CVE-2016-8932IBM Kenexa LMS on Cloud could allow a remote attacker to upload arbitrary files, which could allow the attacker to execu...
CVE-2016-8931IBM Kenexa LMS on Cloud could allow a remote attacker to upload arbitrary files, which could allow the attacker to execu...
CVE-2016-8930IBM Kenexa LMS on Cloud is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, w...
CVE-2016-8929IBM Kenexa LMS on Cloud is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, w...
CVE-2016-8928IBM Kenexa LMS on Cloud is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, w...
CVE-2016-8919IBM WebSphere Application Server may be vulnerable to a denial of service, caused by allowing serialized objects from un...
CVE-2016-6115IBM General Parallel File System is vulnerable to a buffer overflow. A remote authenticated attacker could overflow a bu...
CVE-2016-6110IBM Tivoli Storage Manager discloses unencrypted login credentials to Vmware vCenter that could be obtained by a local u...
CVE-2016-6068IBM UrbanCode Deploy could allow an authenticated user with access to the REST endpoints to access API and CLI getResour...
CVE-2016-6001IBM Forms Experience Builder could be susceptible to a server-side request forgery (SSRF) from the application design in...
CVE-2016-5953IBM Sterling Order Management transmits the session identifier within the URL. When a user is unable to view a certain v...
CVE-2016-5942IBM Kenexa LMS on Cloud is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaSc...
CVE-2016-5941IBM Kenexa LMS on Cloud could allow a remote attacker to traverse directories on the system. An attacker could send a sp...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now