2016 CVE Vulnerabilities

10,647 CVEs published in 2016.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2016-7859Adobe Flash Player versions 23.0.0.205 and earlier, 11.2.202.643 and earlier have an exploitable use-after-free vulnerab...
CVE-2016-7858Adobe Flash Player versions 23.0.0.205 and earlier, 11.2.202.643 and earlier have an exploitable use-after-free vulnerab...
CVE-2016-7857Adobe Flash Player versions 23.0.0.205 and earlier, 11.2.202.643 and earlier have an exploitable use-after-free vulnerab...
CVE-2016-7851Adobe Connect version 9.5.6 and earlier does not adequately validate input in the events registration module. This vulne...
CVE-2016-9242Multiple SQL injection vulnerabilities in the update method in framework/modules/core/controllers/expRatingController.ph...
CVE-2016-9111Incorrect access control mechanisms in Citrix Receiver Desktop Lock 4.5 allow an attacker to bypass the authentication r...
CVE-2016-8870The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before...
CVE-2016-8869The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before...
CVE-2016-9190Pillow before 3.3.2 allows context-dependent attackers to execute arbitrary code by using the "crafted image file" appro...
CVE-2016-9189Pillow before 3.3.2 allows context-dependent attackers to obtain sensitive information by using the "crafted image file"...
CVE-2016-9188Cross-site scripting (XSS) vulnerabilities in Moodle CMS on or before 3.1.2 allow remote attackers to inject arbitrary w...
CVE-2016-9187Unrestricted file upload vulnerability in the double extension support in the "image" module in Moodle 3.1.2 allows remo...
CVE-2016-9186Unrestricted file upload vulnerability in the "legacy course files" and "file manager" modules in Moodle 3.1.2 allows re...
CVE-2016-9185In OpenStack Heat, by launching a new Heat stack with a local URL an authenticated user may conduct network discovery re...
CVE-2016-9184In /framework/modules/core/controllers/expHTMLEditorController.php of Exponent CMS 2.4.0, untrusted input is used to con...
CVE-2016-9183In /framework/modules/ecommerce/controllers/orderController.php of Exponent CMS 2.4.0, untrusted input is passed into se...
CVE-2016-9182Exponent CMS 2.4 uses PHP reflection to call a method of a controller class, and then uses the method name to check user...
CVE-2016-9177Directory traversal vulnerability in Spark 2.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the...
CVE-2016-9176Stack buffer overflow in the send.exe and receive.exe components of Micro Focus Rumba 9.4 and earlier could be used by l...
CVE-2016-6455A vulnerability in the Slowpath of StarOS for Cisco ASR 5500 Series routers with Data Processing Card 2 (DPC2) could all...
CVE-2016-6454A cross-site request forgery (CSRF) vulnerability in the web interface of the Cisco Hosted Collaboration Mediation Fulfi...
CVE-2016-6453A vulnerability in the web framework code of Cisco Identity Services Engine (ISE) could allow an authenticated, remote a...
CVE-2016-6452A vulnerability in the web-based graphical user interface (GUI) of Cisco Prime Home could allow an unauthenticated, remo...
CVE-2016-6451Multiple vulnerabilities in the web framework code of the Cisco Prime Collaboration Provisioning could allow an unauthen...
CVE-2016-6448A vulnerability in the Session Description Protocol (SDP) parser of Cisco Meeting Server could allow an unauthenticated,...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now