2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-6857 | — | — | 0.6% | Dec 31, 2016 | Cross-site scripting (XSS) vulnerability in the Create Catalogue feature in Hybris Management Console (HMC) in SAP Hybri... |
| CVE-2016-6856 | — | — | 0.9% | Dec 31, 2016 | Cross-site scripting (XSS) vulnerability in the Inbox Search feature in Hybris Management Console (HMC) in SAP Hybris be... |
| CVE-2016-1004 | — | — | — | Dec 31, 2016 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ... |
| CVE-2016-1003 | — | — | — | Dec 31, 2016 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-10033. Reason: This candidate is a duplicate of... |
| CVE-2016-10074 | — | — | 41.8% | Dec 30, 2016 | The mail transport (aka Swift_Transport_MailTransport) in Swift Mailer before 5.4.5 might allow remote attackers to pass... |
| CVE-2016-10034 | — | — | 38.4% | Dec 30, 2016 | The setFrom function in the Sendmail adapter in the zend-mail component before 2.4.11, 2.5.x, 2.6.x, and 2.7.x before 2.... |
| CVE-2016-10085 | — | — | 1.8% | Dec 30, 2016 | admin/languages.php in Piwigo through 2.8.3 allows remote authenticated administrators to conduct File Inclusion attacks... |
| CVE-2016-10084 | — | — | 1.8% | Dec 30, 2016 | admin/batch_manager.php in Piwigo through 2.8.3 allows remote authenticated administrators to conduct File Inclusion att... |
| CVE-2016-10083 | — | — | 1.2% | Dec 30, 2016 | Cross-site scripting (XSS) vulnerability in admin/plugin.php in Piwigo through 2.8.3 allows remote attackers to inject a... |
| CVE-2016-10082 | — | — | 2.9% | Dec 30, 2016 | include/functions_installer.inc.php in Serendipity through 2.0.5 is vulnerable to File Inclusion and a possible Code Exe... |
| CVE-2016-9891 | — | — | 1.0% | Dec 29, 2016 | Cross-site scripting (XSS) vulnerability in admin/media.php and admin/media_item.php in Dotclear before 2.11 allows remo... |
| CVE-2016-10081 | — | — | 6.6% | Dec 29, 2016 | /usr/bin/shutter in Shutter through 0.93.1 allows user-assisted remote attackers to execute arbitrary commands via a cra... |
| CVE-2016-9878 | — | — | 5.6% | Dec 29, 2016 | An issue was discovered in Pivotal Spring Framework before 3.2.18, 4.2.x before 4.2.9, and 4.3.x before 4.3.5. Paths pro... |
| CVE-2016-9877 | — | — | 1.4% | Dec 29, 2016 | An issue was discovered in Pivotal RabbitMQ 3.x before 3.5.8 and 3.6.x before 3.6.6 and RabbitMQ for PCF 1.5.x before 1.... |
| CVE-2016-7463 | — | — | 1.1% | Dec 29, 2016 | Cross-site scripting (XSS) vulnerability in the Host Client in VMware vSphere Hypervisor (aka ESXi) 5.5 and 6.0 allows r... |
| CVE-2016-7462 | — | — | 2.0% | Dec 29, 2016 | The Suite REST API in VMware vRealize Operations (aka vROps) 6.x before 6.4.0 allows remote authenticated users to write... |
| CVE-2016-7461 | — | — | 0.5% | Dec 29, 2016 | The drag-and-drop (aka DnD) function in VMware Workstation Pro 12.x before 12.5.2 and VMware Workstation Player 12.x bef... |
| CVE-2016-7460 | — | — | 2.1% | Dec 29, 2016 | The Single Sign-On feature in VMware vCenter Server 5.5 before U3e and 6.0 before U2a and vRealize Automation 6.x before... |
| CVE-2016-7459 | — | — | 1.9% | Dec 29, 2016 | VMware vCenter Server 5.5 before U3e and 6.0 before U2a allows remote authenticated users to read arbitrary files via a ... |
| CVE-2016-7458 | — | — | 1.2% | Dec 29, 2016 | VMware vSphere Client 5.5 before U3e and 6.0 before U2a allows remote vCenter Server and ESXi instances to read arbitrar... |
| CVE-2016-7457 | — | — | 3.2% | Dec 29, 2016 | VMware vRealize Operations (aka vROps) 6.x before 6.4.0 allows remote authenticated users to gain privileges, or halt an... |
| CVE-2016-7456 | — | — | 32.8% | Dec 29, 2016 | VMware vSphere Data Protection (VDP) 5.5.x though 6.1.x has an SSH private key with a publicly known password, which mak... |
| CVE-2016-7087 | — | — | 4.4% | Dec 29, 2016 | Directory traversal vulnerability in the Connection Server in VMware Horizon View 5.x before 5.3.7, 6.x before 6.2.3, an... |
| CVE-2016-7086 | — | — | 0.3% | Dec 29, 2016 | The installer in VMware Workstation Pro 12.x before 12.5.0 and VMware Workstation Player 12.x before 12.5.0 on Windows a... |
| CVE-2016-7085 | — | — | 0.4% | Dec 29, 2016 | Untrusted search path vulnerability in the installer in VMware Workstation Pro 12.x before 12.5.0 and VMware Workstation... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now