2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-5388 | — | — | 50.9% | Jul 19, 2016 | Apache Tomcat 7.x through 7.0.70 and 8.x through 8.5.4, when the CGI Servlet is enabled, follows RFC 3875 section 4.1.18... |
| CVE-2016-3039 | — | — | 2.1% | Jul 17, 2016 | IBM Traveler 8.x and 9.x before 9.0.1.12 allows remote authenticated users to read arbitrary files or cause a denial of ... |
| CVE-2016-1459 | — | — | 1.4% | Jul 17, 2016 | Cisco IOS 12.4 and 15.0 through 15.5 and IOS XE 3.13 through 3.17 allow remote authenticated users to cause a denial of ... |
| CVE-2016-1448 | — | — | 0.9% | Jul 17, 2016 | Cross-site request forgery (CSRF) vulnerability in Cisco WebEx Meetings Server 2.7 allows remote attackers to hijack the... |
| CVE-2016-0393 | — | — | 1.0% | Jul 17, 2016 | IBM Maximo Asset Management 7.5 before 7.5.0.10-TIV-MBS-IFIX002 and 7.6 before 7.6.0.5-TIV-MAMMT-FP001 allows remote att... |
| CVE-2016-0321 | — | — | 0.4% | Jul 17, 2016 | IBM Personal Communications (aka PCOMM) 6.x before 6.0.17 and 12.x before 12.0.0.1 does not properly restrict credential... |
| CVE-2016-5661 | — | — | 2.6% | Jul 15, 2016 | Accela Civic Platform Citizen Access portal relies on the client to restrict file types for uploads, which allows remote... |
| CVE-2016-5637 | — | — | 2.9% | Jul 15, 2016 | The restore_tqb_pixels function in libbpg 0.9.5 through 0.9.7 mishandles the transquant_bypass_enable_flag value, which ... |
| CVE-2016-2865 | — | — | 1.1% | Jul 15, 2016 | The GIT Integration component in IBM Rational Team Concert (RTC) 5.x before 5.0.2 iFix14 and 6.x before 6.0.1 iFix5 and ... |
| CVE-2016-0357 | — | — | 1.3% | Jul 15, 2016 | IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.1 before 7.0.1-ISS-SIM-FP0003 allows remote... |
| CVE-2016-0340 | — | — | 0.5% | Jul 15, 2016 | IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.1 before 7.0.1-ISS-SIM-FP0003 mishandles se... |
| CVE-2016-0339 | — | — | 1.3% | Jul 15, 2016 | IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.1 before 7.0.1-ISS-SIM-FP0003 mishandles se... |
| CVE-2016-0338 | — | — | 0.4% | Jul 15, 2016 | IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.1 before 7.0.1-ISS-SIM-FP0003 allows local ... |
| CVE-2016-0330 | — | — | 1.2% | Jul 15, 2016 | IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.1 before 7.0.1-ISS-SIM-FP0003 mishandles pa... |
| CVE-2016-0269 | — | — | 0.6% | Jul 15, 2016 | Cross-site scripting (XSS) vulnerability in IBM BigFix Platform 9.x before 9.1.8 and 9.2.x before 9.2.7 allows remote au... |
| CVE-2016-5807 | — | — | 1.2% | Jul 15, 2016 | Tollgrade LightHouse SMS before 5.1 patch 3 allows remote authenticated users to bypass an intended administrative-authe... |
| CVE-2016-5797 | — | — | 1.3% | Jul 15, 2016 | Tollgrade LightHouse SMS before 5.1 patch 3 provides different error messages for failed authentication attempts dependi... |
| CVE-2016-4520 | — | — | 5.8% | Jul 15, 2016 | Schneider Electric Pelco Digital Sentry Video Management System with firmware before 7.14 has hardcoded credentials, whi... |
| CVE-2016-4372 | — | — | 19.4% | Jul 15, 2016 | HPE iMC PLAT before 7.2 E0403P04, iMC EAD before 7.2 E0405P05, iMC APM before 7.2 E0401P04, iMC NTA before 7.2 E0401P01,... |
| CVE-2016-1456 | — | — | 0.3% | Jul 15, 2016 | The CLI in Cisco IOS XR 6.x through 6.0.1 allows local users to execute arbitrary OS commands in a privileged context by... |
| CVE-2016-1452 | — | — | 1.1% | Jul 15, 2016 | Cisco ASR 5000 devices with software 18.3 through 20.0.0 allow remote attackers to make configuration changes over SNMP ... |
| CVE-2016-1451 | — | — | 0.8% | Jul 15, 2016 | Cross-site scripting (XSS) vulnerability in the web-based management interface in Cisco Meeting Server (formerly Acano C... |
| CVE-2016-1450 | — | — | 1.3% | Jul 15, 2016 | Cisco WebEx Meetings Server 2.6 allows remote authenticated users to conduct command-injection attacks via vectors relat... |
| CVE-2016-1449 | — | — | 1.0% | Jul 15, 2016 | Cross-site scripting (XSS) vulnerability in Cisco WebEx Meetings Server 2.6 allows remote attackers to inject arbitrary ... |
| CVE-2016-1447 | — | — | 1.4% | Jul 15, 2016 | Cross-site scripting (XSS) vulnerability in the administrator interface in Cisco WebEx Meetings Server 2.6 allows remote... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now