2016 CVE Vulnerabilities

10,645 CVEs published in 2016.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2016-4247MEDIUM5.3Race condition in Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and b...
CVE-2016-4178MEDIUM4.3Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632...
CVE-2016-4428MEDIUM5.4Cross-site scripting (XSS) vulnerability in OpenStack Dashboard (Horizon) 8.0.1 and earlier and 9.0.0 through 9.0.1 allo...
CVE-2016-1445MEDIUM5.3Cisco Adaptive Security Appliance (ASA) Software 8.2 through 9.4.3.3 allows remote attackers to bypass intended ICMP Ech...
CVE-2016-1444MEDIUM6.5The Mobile and Remote Access (MRA) component in Cisco TelePresence Video Communication Server (VCS) X8.1 through X8.7 an...
CVE-2016-0230MEDIUM6.8IBM Power Hardware Management Console (HMC) 7.3 through 7.3.0 SP7, 7.9 through 7.9.0 SP3, 8.1 through 8.1.0 SP3, 8.2 thr...
CVE-2016-6170MEDIUM6.5ISC BIND through 9.9.9-P1, 9.10.x through 9.10.4-P1, and 9.11.x through 9.11.0b1 allows primary DNS servers to cause a d...
CVE-2016-4508MEDIUM6.1Cross-site scripting (XSS) vulnerability in Rexroth Bosch BLADEcontrol-WebVIS 3.0.2 and earlier allows remote attackers ...
CVE-2016-4507MEDIUM6.4SQL injection vulnerability in Rexroth Bosch BLADEcontrol-WebVIS 3.0.2 and earlier allows remote authenticated users to ...
CVE-2016-4956MEDIUM5.3ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (interleaved-mode transition and tim...
CVE-2016-4955MEDIUM5.9ntpd in NTP 4.x before 4.2.8p8, when autokey is enabled, allows remote attackers to cause a denial of service (peer-vari...
CVE-2016-5848MEDIUM6.7Siemens SICAM PAS before 8.07 does not properly restrict password data in the database, which makes it easier for local ...
CVE-2016-3189MEDIUM6.5Use-after-free vulnerability in bzip2recover in bzip2 1.0.6 allows remote attackers to cause a denial of service (crash)...
CVE-2016-4828MEDIUM6.5The Collne Welcart e-Commerce plugin before 1.8.3 for WordPress mishandles sessions, which allows remote attackers to ob...
CVE-2016-4827MEDIUM6.1Cross-site scripting (XSS) vulnerability in the Collne Welcart e-Commerce plugin before 1.8.3 for WordPress allows remot...
CVE-2016-4826MEDIUM6.1Cross-site scripting (XSS) vulnerability in the Collne Welcart e-Commerce plugin before 1.8.3 for WordPress allows remot...
CVE-2016-4825MEDIUM5.6The Collne Welcart e-Commerce plugin before 1.8.3 for WordPress allows remote attackers to conduct PHP object injection ...
CVE-2016-2178MEDIUM5.5The dsa_sign_setup function in crypto/dsa/dsa_ossl.c in OpenSSL through 1.0.2h does not properly ensure the use of const...
CVE-2016-4530MEDIUM6.5OSIsoft PI SQL Data Access Server (aka OLE DB) 2016 1.5 allows remote authenticated users to cause a denial of service (...
CVE-2016-1224MEDIUM6.1CRLF injection vulnerability in Trend Micro Worry-Free Business Security Service 5.x and Worry-Free Business Security 9....
CVE-2016-1223MEDIUM5.3Directory traversal vulnerability in Trend Micro Office Scan 11.0, Worry-Free Business Security Service 5.x, and Worry-F...
CVE-2016-2391MEDIUM5The ohci_bus_start function in the USB OHCI emulation support (hw/usb/hcd-ohci.c) in QEMU allows local guest OS administ...
CVE-2016-4159MEDIUM6.1Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 10 before Update 20, 11 before Update 9, and 2016 before Up...
CVE-2016-5337MEDIUM5.5The megasas_ctrl_get_info function in hw/scsi/megasas.c in QEMU allows local guest OS administrators to obtain sensitive...
CVE-2016-5238MEDIUM4.4The get_cmd function in hw/scsi/esp.c in QEMU might allow local guest OS administrators to cause a denial of service (ou...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now