2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-7859 | — | — | 7.0% | Nov 8, 2016 | Adobe Flash Player versions 23.0.0.205 and earlier, 11.2.202.643 and earlier have an exploitable use-after-free vulnerab... |
| CVE-2016-7858 | — | — | 7.0% | Nov 8, 2016 | Adobe Flash Player versions 23.0.0.205 and earlier, 11.2.202.643 and earlier have an exploitable use-after-free vulnerab... |
| CVE-2016-7857 | — | — | 7.0% | Nov 8, 2016 | Adobe Flash Player versions 23.0.0.205 and earlier, 11.2.202.643 and earlier have an exploitable use-after-free vulnerab... |
| CVE-2016-7851 | — | — | 7.0% | Nov 8, 2016 | Adobe Connect version 9.5.6 and earlier does not adequately validate input in the events registration module. This vulne... |
| CVE-2016-9242 | — | — | 1.4% | Nov 7, 2016 | Multiple SQL injection vulnerabilities in the update method in framework/modules/core/controllers/expRatingController.ph... |
| CVE-2016-9111 | — | — | 1.8% | Nov 7, 2016 | Incorrect access control mechanisms in Citrix Receiver Desktop Lock 4.5 allow an attacker to bypass the authentication r... |
| CVE-2016-8870 | — | — | 82.1% | Nov 4, 2016 | The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before... |
| CVE-2016-8869 | — | — | 97.4% | Nov 4, 2016 | The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before... |
| CVE-2016-9190 | — | — | 2.0% | Nov 4, 2016 | Pillow before 3.3.2 allows context-dependent attackers to execute arbitrary code by using the "crafted image file" appro... |
| CVE-2016-9189 | — | — | 1.9% | Nov 4, 2016 | Pillow before 3.3.2 allows context-dependent attackers to obtain sensitive information by using the "crafted image file"... |
| CVE-2016-9188 | — | — | 1.5% | Nov 4, 2016 | Cross-site scripting (XSS) vulnerabilities in Moodle CMS on or before 3.1.2 allow remote attackers to inject arbitrary w... |
| CVE-2016-9187 | — | — | 4.0% | Nov 4, 2016 | Unrestricted file upload vulnerability in the double extension support in the "image" module in Moodle 3.1.2 allows remo... |
| CVE-2016-9186 | — | — | 3.8% | Nov 4, 2016 | Unrestricted file upload vulnerability in the "legacy course files" and "file manager" modules in Moodle 3.1.2 allows re... |
| CVE-2016-9185 | — | — | 1.5% | Nov 4, 2016 | In OpenStack Heat, by launching a new Heat stack with a local URL an authenticated user may conduct network discovery re... |
| CVE-2016-9184 | — | — | 1.8% | Nov 4, 2016 | In /framework/modules/core/controllers/expHTMLEditorController.php of Exponent CMS 2.4.0, untrusted input is used to con... |
| CVE-2016-9183 | — | — | 1.8% | Nov 4, 2016 | In /framework/modules/ecommerce/controllers/orderController.php of Exponent CMS 2.4.0, untrusted input is passed into se... |
| CVE-2016-9182 | — | — | 1.4% | Nov 4, 2016 | Exponent CMS 2.4 uses PHP reflection to call a method of a controller class, and then uses the method name to check user... |
| CVE-2016-9177 | — | — | 5.1% | Nov 4, 2016 | Directory traversal vulnerability in Spark 2.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the... |
| CVE-2016-9176 | — | — | 2.8% | Nov 4, 2016 | Stack buffer overflow in the send.exe and receive.exe components of Micro Focus Rumba 9.4 and earlier could be used by l... |
| CVE-2016-6455 | — | — | 1.7% | Nov 3, 2016 | A vulnerability in the Slowpath of StarOS for Cisco ASR 5500 Series routers with Data Processing Card 2 (DPC2) could all... |
| CVE-2016-6454 | — | — | 0.5% | Nov 3, 2016 | A cross-site request forgery (CSRF) vulnerability in the web interface of the Cisco Hosted Collaboration Mediation Fulfi... |
| CVE-2016-6453 | — | — | 1.1% | Nov 3, 2016 | A vulnerability in the web framework code of Cisco Identity Services Engine (ISE) could allow an authenticated, remote a... |
| CVE-2016-6452 | — | — | 2.7% | Nov 3, 2016 | A vulnerability in the web-based graphical user interface (GUI) of Cisco Prime Home could allow an unauthenticated, remo... |
| CVE-2016-6451 | — | — | 1.1% | Nov 3, 2016 | Multiple vulnerabilities in the web framework code of the Cisco Prime Collaboration Provisioning could allow an unauthen... |
| CVE-2016-6448 | — | — | 4.0% | Nov 3, 2016 | A vulnerability in the Session Description Protocol (SDP) parser of Cisco Meeting Server could allow an unauthenticated,... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now