2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-4387 | — | — | 8.5% | Oct 5, 2016 | The Filter SDK in HPE KeyView 10.18 through 10.24 allows remote attackers to execute arbitrary code via unspecified vect... |
| CVE-2016-2308 | — | — | 1.4% | Oct 5, 2016 | American Auto-Matrix Aspect-Nexus Building Automation Front-End Solutions application before 3.0.0 and Aspect-Matrix Bui... |
| CVE-2016-2307 | — | — | 1.5% | Oct 5, 2016 | American Auto-Matrix Aspect-Nexus Building Automation Front-End Solutions application before 3.0.0 and Aspect-Matrix Bui... |
| CVE-2016-6646 | — | — | 4.9% | Oct 5, 2016 | The vApp Managers web application in EMC Unisphere for VMAX Virtual Appliance 8.x before 8.3.0 and Solutions Enabler Vir... |
| CVE-2016-6645 | — | — | 3.6% | Oct 5, 2016 | The vApp Managers web application in EMC Unisphere for VMAX Virtual Appliance 8.x before 8.3.0 and Solutions Enabler Vir... |
| CVE-2016-6550 | — | — | 0.3% | Oct 5, 2016 | The U by BB&T app 1.5.4 and earlier for iOS does not properly verify X.509 certificates from SSL servers, which allows m... |
| CVE-2016-0913 | — | — | 2.6% | Oct 5, 2016 | The client in EMC Replication Manager (RM) before 5.5.3.0_01-PatchHotfix, EMC Network Module for Microsoft 3.x, and EMC ... |
| CVE-2016-4990 | — | — | — | Oct 4, 2016 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. ... |
| CVE-2016-8280 | — | — | 1.6% | Oct 3, 2016 | Directory traversal vulnerability in Huawei eSight before V300R003C20SPC005 allows remote authenticated users to read ar... |
| CVE-2016-8278 | — | — | 1.2% | Oct 3, 2016 | Huawei USG9520, USG9560, and USG9580 unified security gateways with software before V300R001C01SPCa00 allow remote attac... |
| CVE-2016-8277 | — | — | 1.0% | Oct 3, 2016 | Huawei USG9520, USG9560, and USG9580 unified security gateways with software before V300R001C01SPCa00 allow remote authe... |
| CVE-2016-8276 | — | — | 5.6% | Oct 3, 2016 | Buffer overflow in the Point-to-Point Protocol over Ethernet (PPPoE) module in Huawei USG2100, USG2200, USG5100, and USG... |
| CVE-2016-7141 | — | — | 8.4% | Oct 3, 2016 | curl and libcurl before 7.50.2, when built with NSS and the libnsspem.so library is available at runtime, allow remote a... |
| CVE-2016-7046 | — | — | 2.5% | Oct 3, 2016 | Red Hat JBoss Enterprise Application Platform (EAP) 7, when operating as a reverse-proxy with default buffer sizes, allo... |
| CVE-2016-6905 | — | — | 2.6% | Oct 3, 2016 | The read_image_tga function in gd_tga.c in the GD Graphics Library (aka libgd) before 2.2.3 allows remote attackers to c... |
| CVE-2016-7572 | — | — | 1.7% | Oct 3, 2016 | The system.temporary route in Drupal 8.x before 8.1.10 does not properly check for "Export configuration" permission, wh... |
| CVE-2016-7571 | — | — | 1.5% | Oct 3, 2016 | Cross-site scripting (XSS) vulnerability in Drupal 8.x before 8.1.10 allows remote attackers to inject arbitrary web scr... |
| CVE-2016-7570 | — | — | 1.7% | Oct 3, 2016 | Drupal 8.x before 8.1.10 does not properly check for "Administer comments" permission, which allows remote authenticated... |
| CVE-2016-7405 | — | — | 3.0% | Oct 3, 2016 | The qstr method in the PDO driver in the ADOdb Library for PHP before 5.x before 5.20.7 might allow remote attackers to ... |
| CVE-2016-7401 | — | — | 6.1% | Oct 3, 2016 | The cookie parsing code in Django before 1.8.15 and 1.9.x before 1.9.10, when used on a site with Google Analytics, allo... |
| CVE-2016-7031 | — | — | 1.8% | Oct 3, 2016 | The RGW code in Ceph before 10.0.1, when authenticated-read ACL is applied to a bucket, allows remote attackers to list ... |
| CVE-2016-6494 | — | — | 0.4% | Oct 3, 2016 | The client in MongoDB uses world-readable permissions on .dbshell history files, which might allow local users to obtain... |
| CVE-2016-6352 | — | — | 3.9% | Oct 3, 2016 | The OneLine32 function in io-ico.c in gdk-pixbuf before 2.35.3 allows remote attackers to cause a denial of service (out... |
| CVE-2016-5432 | — | — | 0.3% | Oct 3, 2016 | The ovirt-engine-provisiondb utility in Red Hat Enterprise Virtualization (RHEV) Engine 4.0 allows local users to obtain... |
| CVE-2016-5398 | — | — | 0.8% | Oct 3, 2016 | Cross-site scripting (XSS) vulnerability in Business Process Editor in Red Hat JBoss BPM Suite before 6.3.3 allows remot... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now