2016 CVE Vulnerabilities

10,647 CVEs published in 2016.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2016-4803CRLF injection vulnerability in the send email functionality in dotCMS before 3.3.2 allows remote attackers to inject ar...
CVE-2016-5840hotfix_upload.cgi in Trend Micro Deep Discovery Inspector (DDI) 3.7, 3.8 SP1 (3.81), and 3.8 SP2 (3.82) allows remote ad...
CVE-2016-5368Memory leak in Huawei AR3200 before V200R007C00SPC900 allows remote attackers to cause a denial of service (memory consu...
CVE-2016-5249Lenovo Solution Center (LSC) before 3.3.003 allows local users to execute arbitrary code with LocalSystem privileges via...
CVE-2016-5248The StopProxy command in LSC.Services.SystemService in Lenovo Solution Center before 3.3.003 allows local users to termi...
CVE-2016-5232Buffer overflow in Huawei Mate8 NXT-AL before NXT-AL10C00B182, NXT-CL before NXT-CL00C92B182, NXT-DL before NXT-DL00C17B...
CVE-2016-5231Huawei Mate8 NXT-AL before NXT-AL10C00B182, NXT-CL before NXT-CL00C92B182, NXT-DL before NXT-DL00C17B182, and NXT-TL bef...
CVE-2016-5230Huawei Mate8 NXT-AL before NXT-AL10C00B182, NXT-CL before NXT-CL00C92B182, NXT-DL before NXT-DL00C17B182, and NXT-TL bef...
CVE-2016-4474The image build process for the overcloud images in Red Hat OpenStack Platform 8.0 (Liberty) director and Red Hat Enterp...
CVE-2016-4086Huawei HiSuite (In China) before 4.0.4.301 and (Out of China) before 4.0.4.204_ove allows remote attackers to install ar...
CVE-2016-4057Huawei FusionCompute before V100R005C10SPC700 allows remote authenticated users to cause a denial of service (resource c...
CVE-2016-0349IBM Business Process Manager 8.5.6 through 8.5.6.2 and 8.5.7 before 8.5.7.CF201606 allows remote authenticated users to ...
CVE-2016-0322Cross-site scripting (XSS) vulnerability in IBM Connections 4.0 through CR4, 4.5 through CR5, 5.0 through CR4, and 5.5 b...
CVE-2016-5839WordPress before 4.5.3 allows remote attackers to bypass the sanitize_file_name protection mechanism via unspecified vec...
CVE-2016-5838WordPress before 4.5.3 allows remote attackers to bypass intended password-change restrictions by leveraging knowledge o...
CVE-2016-5837WordPress before 4.5.3 allows remote attackers to bypass intended access restrictions and remove a category attribute fr...
CVE-2016-5836The oEmbed protocol implementation in WordPress before 4.5.3 allows remote attackers to cause a denial of service via un...
CVE-2016-5835WordPress before 4.5.3 allows remote attackers to obtain sensitive revision-history information by leveraging the abilit...
CVE-2016-5834Cross-site scripting (XSS) vulnerability in the wp_get_attachment_link function in wp-includes/post-template.php in Word...
CVE-2016-5833Cross-site scripting (XSS) vulnerability in the column_title function in wp-admin/includes/class-wp-media-list-table.php...
CVE-2016-5832The customizer in WordPress before 4.5.3 allows remote attackers to bypass intended redirection restrictions via unspeci...
CVE-2016-5101Unspecified vulnerability in Opera Mail before 2016-02-16 on Windows allows user-assisted remote attackers to execute ar...
CVE-2016-1237nfsd in the Linux kernel through 4.6.3 allows local users to bypass intended file-permission restrictions by setting a P...
CVE-2016-0304The Java Console in IBM Domino 8.5.x before 8.5.3 FP6 IF13 and 9.x before 9.0.1 FP6, when a certain unsupported configur...
CVE-2016-0298Directory traversal vulnerability in IBM Security Guardium Database Activity Monitor 10 before 10.0p100 allows remote au...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now