2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-1608 | — | — | 11.3% | Aug 1, 2016 | vaconfig/time in Novell Filr before 1.2 Security Update 3 and 2.0 before Security Update 2 allows remote authenticated u... |
| CVE-2016-1607 | — | — | 3.4% | Aug 1, 2016 | Multiple cross-site request forgery (CSRF) vulnerabilities in the administrative interface in Novell Filr before 2.0 Sec... |
| CVE-2016-1605 | — | — | 3.8% | Aug 1, 2016 | Directory traversal vulnerability in the ReportViewServlet servlet in the server in NetIQ Sentinel 7.4.x before 7.4.2 al... |
| CVE-2016-5005 | — | — | 4.8% | Jul 28, 2016 | Cross-site scripting (XSS) vulnerability in Apache Archiva 1.3.9 and earlier allows remote authenticated administrators ... |
| CVE-2016-4469 | — | — | 7.9% | Jul 28, 2016 | Multiple cross-site request forgery (CSRF) vulnerabilities in Apache Archiva 1.3.9 and earlier allow remote attackers to... |
| CVE-2016-4531 | — | — | 8.2% | Jul 28, 2016 | Rockwell Automation FactoryTalk EnergyMetrix before 2.20.00 does not invalidate credentials upon a logout action, which ... |
| CVE-2016-4522 | — | — | 6.3% | Jul 28, 2016 | SQL injection vulnerability in Rockwell Automation FactoryTalk EnergyMetrix before 2.20.00 allows remote attackers to ex... |
| CVE-2016-1467 | — | — | 0.6% | Jul 28, 2016 | Cisco Videoscape Session Resource Manager (VSRM) allows remote attackers to cause a denial of service (device restart) b... |
| CVE-2016-1465 | — | — | 0.9% | Jul 28, 2016 | Cisco Nexus 1000v Application Virtual Switch (AVS) devices before 5.2(1)SV3(1.5i) allow remote attackers to cause a deni... |
| CVE-2016-1463 | — | — | 2.1% | Jul 28, 2016 | Cisco FireSIGHT System Software 5.3.0, 5.3.1, 5.4.0, 6.0, and 6.0.1 allows remote attackers to bypass Snort rules via cr... |
| CVE-2016-1462 | — | — | 1.0% | Jul 28, 2016 | Cross-site scripting (XSS) vulnerability in the web-based management interface in Cisco Prime Service Catalog (PSC) 11.0... |
| CVE-2016-1460 | — | — | 0.7% | Jul 28, 2016 | Cisco Wireless LAN Controller (WLC) devices 7.4(121.0) and 8.0(0.30220.385) allow remote attackers to cause a denial of ... |
| CVE-2016-1374 | — | — | 2.7% | Jul 28, 2016 | The web framework in Cisco Unified Computing System (UCS) Performance Manager 2.0.0 and earlier allows remote authentica... |
| CVE-2016-3992 | — | — | 0.4% | Jul 26, 2016 | cronic before 3 allows local users to write to arbitrary files via a symlink attack on a (1) cronic.out.$$, (2) cronic.e... |
| CVE-2016-6152 | — | — | 3.4% | Jul 26, 2016 | CA eHealth 6.2.x and 6.3.x before 6.3.2.13 allows remote authenticated users to cause a denial of service or possibly ex... |
| CVE-2016-6151 | — | — | 2.7% | Jul 26, 2016 | CA eHealth 6.2.x allows remote authenticated users to cause a denial of service or possibly execute arbitrary commands v... |
| CVE-2016-6297 | — | — | 5.3% | Jul 25, 2016 | Integer overflow in the php_stream_zip_opener function in ext/zip/zip_stream.c in PHP before 5.5.38, 5.6.x before 5.6.24... |
| CVE-2016-6296 | — | — | 6.3% | Jul 25, 2016 | Integer signedness error in the simplestring_addn function in simplestring.c in xmlrpc-epi through 0.54.2, as used in PH... |
| CVE-2016-6295 | — | — | 5.4% | Jul 25, 2016 | ext/snmp/snmp.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 improperly interacts with the unserializ... |
| CVE-2016-6294 | — | — | 6.0% | Jul 25, 2016 | The locale_accept_from_http function in ext/intl/locale/locale_methods.c in PHP before 5.5.38, 5.6.x before 5.6.24, and ... |
| CVE-2016-6293 | — | — | 5.0% | Jul 25, 2016 | The uloc_acceptLanguageFromHTTP function in common/uloc.cpp in International Components for Unicode (ICU) through 57.1 f... |
| CVE-2016-6292 | — | — | 3.9% | Jul 25, 2016 | The exif_process_user_comment function in ext/exif/exif.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.... |
| CVE-2016-6291 | — | — | 5.6% | Jul 25, 2016 | The exif_process_IFD_in_MAKERNOTE function in ext/exif/exif.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before ... |
| CVE-2016-6290 | — | — | 5.5% | Jul 25, 2016 | ext/session/session.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 does not properly maintain a certa... |
| CVE-2016-6289 | — | — | 3.8% | Jul 25, 2016 | Integer overflow in the virtual_file_ex function in TSRM/tsrm_virtual_cwd.c in PHP before 5.5.38, 5.6.x before 5.6.24, a... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now