2016 CVE Vulnerabilities

10,648 CVEs published in 2016.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2016-4803——CRLF injection vulnerability in the send email functionality in dotCMS before 3.3.2 allows remote attackers to inject ar...
CVE-2016-5840——hotfix_upload.cgi in Trend Micro Deep Discovery Inspector (DDI) 3.7, 3.8 SP1 (3.81), and 3.8 SP2 (3.82) allows remote ad...
CVE-2016-5368——Memory leak in Huawei AR3200 before V200R007C00SPC900 allows remote attackers to cause a denial of service (memory consu...
CVE-2016-5249——Lenovo Solution Center (LSC) before 3.3.003 allows local users to execute arbitrary code with LocalSystem privileges via...
CVE-2016-5248——The StopProxy command in LSC.Services.SystemService in Lenovo Solution Center before 3.3.003 allows local users to termi...
CVE-2016-5232——Buffer overflow in Huawei Mate8 NXT-AL before NXT-AL10C00B182, NXT-CL before NXT-CL00C92B182, NXT-DL before NXT-DL00C17B...
CVE-2016-5231——Huawei Mate8 NXT-AL before NXT-AL10C00B182, NXT-CL before NXT-CL00C92B182, NXT-DL before NXT-DL00C17B182, and NXT-TL bef...
CVE-2016-5230——Huawei Mate8 NXT-AL before NXT-AL10C00B182, NXT-CL before NXT-CL00C92B182, NXT-DL before NXT-DL00C17B182, and NXT-TL bef...
CVE-2016-4474——The image build process for the overcloud images in Red Hat OpenStack Platform 8.0 (Liberty) director and Red Hat Enterp...
CVE-2016-4086——Huawei HiSuite (In China) before 4.0.4.301 and (Out of China) before 4.0.4.204_ove allows remote attackers to install ar...
CVE-2016-4057——Huawei FusionCompute before V100R005C10SPC700 allows remote authenticated users to cause a denial of service (resource c...
CVE-2016-0349——IBM Business Process Manager 8.5.6 through 8.5.6.2 and 8.5.7 before 8.5.7.CF201606 allows remote authenticated users to ...
CVE-2016-0322——Cross-site scripting (XSS) vulnerability in IBM Connections 4.0 through CR4, 4.5 through CR5, 5.0 through CR4, and 5.5 b...
CVE-2016-5839——WordPress before 4.5.3 allows remote attackers to bypass the sanitize_file_name protection mechanism via unspecified vec...
CVE-2016-5838——WordPress before 4.5.3 allows remote attackers to bypass intended password-change restrictions by leveraging knowledge o...
CVE-2016-5837——WordPress before 4.5.3 allows remote attackers to bypass intended access restrictions and remove a category attribute fr...
CVE-2016-5836——The oEmbed protocol implementation in WordPress before 4.5.3 allows remote attackers to cause a denial of service via un...
CVE-2016-5835——WordPress before 4.5.3 allows remote attackers to obtain sensitive revision-history information by leveraging the abilit...
CVE-2016-5834——Cross-site scripting (XSS) vulnerability in the wp_get_attachment_link function in wp-includes/post-template.php in Word...
CVE-2016-5833——Cross-site scripting (XSS) vulnerability in the column_title function in wp-admin/includes/class-wp-media-list-table.php...
CVE-2016-5832——The customizer in WordPress before 4.5.3 allows remote attackers to bypass intended redirection restrictions via unspeci...
CVE-2016-5101——Unspecified vulnerability in Opera Mail before 2016-02-16 on Windows allows user-assisted remote attackers to execute ar...
CVE-2016-1237——nfsd in the Linux kernel through 4.6.3 allows local users to bypass intended file-permission restrictions by setting a P...
CVE-2016-0304——The Java Console in IBM Domino 8.5.x before 8.5.3 FP6 IF13 and 9.x before 9.0.1 FP6, when a certain unsupported configur...
CVE-2016-0298——Directory traversal vulnerability in IBM Security Guardium Database Activity Monitor 10 before 10.0p100 allows remote au...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now