2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-10083 | — | — | 1.2% | Dec 30, 2016 | Cross-site scripting (XSS) vulnerability in admin/plugin.php in Piwigo through 2.8.3 allows remote attackers to inject a... |
| CVE-2016-10082 | — | — | 2.9% | Dec 30, 2016 | include/functions_installer.inc.php in Serendipity through 2.0.5 is vulnerable to File Inclusion and a possible Code Exe... |
| CVE-2016-9916 | MEDIUM | 6.5 | 0.4% | Dec 29, 2016 | Memory leak in hw/9pfs/9p-proxy.c in QEMU (aka Quick Emulator) allows local privileged guest OS users to cause a denial ... |
| CVE-2016-9915 | MEDIUM | 6.5 | 0.4% | Dec 29, 2016 | Memory leak in hw/9pfs/9p-handle.c in QEMU (aka Quick Emulator) allows local privileged guest OS users to cause a denial... |
| CVE-2016-9914 | MEDIUM | 6.5 | 0.4% | Dec 29, 2016 | Memory leak in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local privileged guest OS users to cause a denial of ser... |
| CVE-2016-9913 | MEDIUM | 6.5 | 0.4% | Dec 29, 2016 | Memory leak in the v9fs_device_unrealize_common function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local privi... |
| CVE-2016-9846 | MEDIUM | 6.5 | 0.4% | Dec 29, 2016 | QEMU (aka Quick Emulator) built with the Virtio GPU Device emulator support is vulnerable to a memory leakage issue. It ... |
| CVE-2016-9845 | MEDIUM | 6.5 | 0.4% | Dec 29, 2016 | QEMU (aka Quick Emulator) built with the Virtio GPU Device emulator support is vulnerable to an information leakage issu... |
| CVE-2016-9776 | MEDIUM | 5.5 | 0.4% | Dec 29, 2016 | QEMU (aka Quick Emulator) built with the ColdFire Fast Ethernet Controller emulator support is vulnerable to an infinite... |
| CVE-2016-2198 | MEDIUM | 5.5 | 0.4% | Dec 29, 2016 | QEMU (aka Quick Emulator) built with the USB EHCI emulation support is vulnerable to a null pointer dereference flaw. It... |
| CVE-2016-2197 | MEDIUM | 5.5 | 0.4% | Dec 29, 2016 | QEMU (aka Quick Emulator) built with an IDE AHCI emulation support is vulnerable to a null pointer dereference flaw. It ... |
| CVE-2016-1981 | MEDIUM | 5.5 | 0.4% | Dec 29, 2016 | QEMU (aka Quick Emulator) built with the e1000 NIC emulation support is vulnerable to an infinite loop issue. It could o... |
| CVE-2016-1922 | MEDIUM | 5.5 | 0.4% | Dec 29, 2016 | QEMU (aka Quick Emulator) built with the TPR optimization for 32-bit Windows guests support is vulnerable to a null poin... |
| CVE-2016-9891 | — | — | 1.0% | Dec 29, 2016 | Cross-site scripting (XSS) vulnerability in admin/media.php and admin/media_item.php in Dotclear before 2.11 allows remo... |
| CVE-2016-10081 | — | — | 6.6% | Dec 29, 2016 | /usr/bin/shutter in Shutter through 0.93.1 allows user-assisted remote attackers to execute arbitrary commands via a cra... |
| CVE-2016-9878 | — | — | 5.6% | Dec 29, 2016 | An issue was discovered in Pivotal Spring Framework before 3.2.18, 4.2.x before 4.2.9, and 4.3.x before 4.3.5. Paths pro... |
| CVE-2016-9877 | — | — | 1.4% | Dec 29, 2016 | An issue was discovered in Pivotal RabbitMQ 3.x before 3.5.8 and 3.6.x before 3.6.6 and RabbitMQ for PCF 1.5.x before 1.... |
| CVE-2016-7463 | — | — | 1.1% | Dec 29, 2016 | Cross-site scripting (XSS) vulnerability in the Host Client in VMware vSphere Hypervisor (aka ESXi) 5.5 and 6.0 allows r... |
| CVE-2016-7462 | — | — | 2.0% | Dec 29, 2016 | The Suite REST API in VMware vRealize Operations (aka vROps) 6.x before 6.4.0 allows remote authenticated users to write... |
| CVE-2016-7461 | — | — | 0.5% | Dec 29, 2016 | The drag-and-drop (aka DnD) function in VMware Workstation Pro 12.x before 12.5.2 and VMware Workstation Player 12.x bef... |
| CVE-2016-7460 | — | — | 2.1% | Dec 29, 2016 | The Single Sign-On feature in VMware vCenter Server 5.5 before U3e and 6.0 before U2a and vRealize Automation 6.x before... |
| CVE-2016-7459 | — | — | 1.9% | Dec 29, 2016 | VMware vCenter Server 5.5 before U3e and 6.0 before U2a allows remote authenticated users to read arbitrary files via a ... |
| CVE-2016-7458 | — | — | 1.2% | Dec 29, 2016 | VMware vSphere Client 5.5 before U3e and 6.0 before U2a allows remote vCenter Server and ESXi instances to read arbitrar... |
| CVE-2016-7457 | — | — | 3.2% | Dec 29, 2016 | VMware vRealize Operations (aka vROps) 6.x before 6.4.0 allows remote authenticated users to gain privileges, or halt an... |
| CVE-2016-7456 | — | — | 32.8% | Dec 29, 2016 | VMware vSphere Data Protection (VDP) 5.5.x though 6.1.x has an SSH private key with a publicly known password, which mak... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now