2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-4803 | — | — | 2.2% | Jun 30, 2016 | CRLF injection vulnerability in the send email functionality in dotCMS before 3.3.2 allows remote attackers to inject ar... |
| CVE-2016-5840 | — | — | 7.8% | Jun 30, 2016 | hotfix_upload.cgi in Trend Micro Deep Discovery Inspector (DDI) 3.7, 3.8 SP1 (3.81), and 3.8 SP2 (3.82) allows remote ad... |
| CVE-2016-5368 | — | — | 1.4% | Jun 30, 2016 | Memory leak in Huawei AR3200 before V200R007C00SPC900 allows remote attackers to cause a denial of service (memory consu... |
| CVE-2016-5249 | — | — | 0.6% | Jun 30, 2016 | Lenovo Solution Center (LSC) before 3.3.003 allows local users to execute arbitrary code with LocalSystem privileges via... |
| CVE-2016-5248 | — | — | 0.3% | Jun 30, 2016 | The StopProxy command in LSC.Services.SystemService in Lenovo Solution Center before 3.3.003 allows local users to termi... |
| CVE-2016-5232 | — | — | 0.5% | Jun 30, 2016 | Buffer overflow in Huawei Mate8 NXT-AL before NXT-AL10C00B182, NXT-CL before NXT-CL00C92B182, NXT-DL before NXT-DL00C17B... |
| CVE-2016-5231 | — | — | 0.6% | Jun 30, 2016 | Huawei Mate8 NXT-AL before NXT-AL10C00B182, NXT-CL before NXT-CL00C92B182, NXT-DL before NXT-DL00C17B182, and NXT-TL bef... |
| CVE-2016-5230 | — | — | 0.7% | Jun 30, 2016 | Huawei Mate8 NXT-AL before NXT-AL10C00B182, NXT-CL before NXT-CL00C92B182, NXT-DL before NXT-DL00C17B182, and NXT-TL bef... |
| CVE-2016-4474 | — | — | 0.8% | Jun 30, 2016 | The image build process for the overcloud images in Red Hat OpenStack Platform 8.0 (Liberty) director and Red Hat Enterp... |
| CVE-2016-4086 | — | — | 0.3% | Jun 30, 2016 | Huawei HiSuite (In China) before 4.0.4.301 and (Out of China) before 4.0.4.204_ove allows remote attackers to install ar... |
| CVE-2016-4057 | — | — | 1.0% | Jun 30, 2016 | Huawei FusionCompute before V100R005C10SPC700 allows remote authenticated users to cause a denial of service (resource c... |
| CVE-2016-0349 | — | — | 1.5% | Jun 30, 2016 | IBM Business Process Manager 8.5.6 through 8.5.6.2 and 8.5.7 before 8.5.7.CF201606 allows remote authenticated users to ... |
| CVE-2016-0322 | — | — | 0.6% | Jun 30, 2016 | Cross-site scripting (XSS) vulnerability in IBM Connections 4.0 through CR4, 4.5 through CR5, 5.0 through CR4, and 5.5 b... |
| CVE-2016-5839 | — | — | 2.5% | Jun 29, 2016 | WordPress before 4.5.3 allows remote attackers to bypass the sanitize_file_name protection mechanism via unspecified vec... |
| CVE-2016-5838 | — | — | 2.7% | Jun 29, 2016 | WordPress before 4.5.3 allows remote attackers to bypass intended password-change restrictions by leveraging knowledge o... |
| CVE-2016-5837 | — | — | 3.5% | Jun 29, 2016 | WordPress before 4.5.3 allows remote attackers to bypass intended access restrictions and remove a category attribute fr... |
| CVE-2016-5836 | — | — | 4.1% | Jun 29, 2016 | The oEmbed protocol implementation in WordPress before 4.5.3 allows remote attackers to cause a denial of service via un... |
| CVE-2016-5835 | — | — | 3.6% | Jun 29, 2016 | WordPress before 4.5.3 allows remote attackers to obtain sensitive revision-history information by leveraging the abilit... |
| CVE-2016-5834 | — | — | 2.1% | Jun 29, 2016 | Cross-site scripting (XSS) vulnerability in the wp_get_attachment_link function in wp-includes/post-template.php in Word... |
| CVE-2016-5833 | — | — | 2.1% | Jun 29, 2016 | Cross-site scripting (XSS) vulnerability in the column_title function in wp-admin/includes/class-wp-media-list-table.php... |
| CVE-2016-5832 | — | — | 2.7% | Jun 29, 2016 | The customizer in WordPress before 4.5.3 allows remote attackers to bypass intended redirection restrictions via unspeci... |
| CVE-2016-5101 | — | — | 2.9% | Jun 29, 2016 | Unspecified vulnerability in Opera Mail before 2016-02-16 on Windows allows user-assisted remote attackers to execute ar... |
| CVE-2016-1237 | — | — | 0.4% | Jun 29, 2016 | nfsd in the Linux kernel through 4.6.3 allows local users to bypass intended file-permission restrictions by setting a P... |
| CVE-2016-0304 | — | — | 2.5% | Jun 29, 2016 | The Java Console in IBM Domino 8.5.x before 8.5.3 FP6 IF13 and 9.x before 9.0.1 FP6, when a certain unsupported configur... |
| CVE-2016-0298 | — | — | 1.3% | Jun 29, 2016 | Directory traversal vulnerability in IBM Security Guardium Database Activity Monitor 10 before 10.0p100 allows remote au... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now