2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-5878 | — | — | 0.8% | Aug 8, 2016 | Open redirect vulnerability in IBM FileNet Workplace 4.0.2 before 4.0.2.14 allows remote authenticated users to redirect... |
| CVE-2016-5331 | — | — | 1.9% | Aug 8, 2016 | CRLF injection vulnerability in VMware vCenter Server 6.0 before U2 and ESXi 6.0 allows remote attackers to inject arbit... |
| CVE-2016-5330 | HIGH | 7.8 | 18.0% | Aug 8, 2016 | Untrusted search path vulnerability in the HGFS (aka Shared Folders) feature in VMware Tools 10.0.5 in VMware ESXi 5.0 t... |
| CVE-2016-3059 | — | — | 0.4% | Aug 8, 2016 | IBM Tivoli Storage Manager for Databases: Data Protection for Microsoft SQL Server (aka IBM Spectrum Protect for Databas... |
| CVE-2016-3054 | — | — | 0.6% | Aug 8, 2016 | Cross-site scripting (XSS) vulnerability in IBM FileNet Workplace 4.0.2 allows remote authenticated users to inject arbi... |
| CVE-2016-2989 | — | — | 1.8% | Aug 8, 2016 | Open redirect vulnerability in the Connections Portlets component 5.x before 5.0.2 for IBM WebSphere Portal allows remot... |
| CVE-2016-2960 | — | — | 39.6% | Aug 8, 2016 | IBM WebSphere Application Server (WAS) 7.x before 7.0.0.43, 8.0.0.x before 8.0.0.13, 8.5.0.x before 8.5.5.10, 8.5.0.x an... |
| CVE-2016-2925 | — | — | 1.2% | Aug 8, 2016 | Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 C... |
| CVE-2016-2914 | — | — | 1.3% | Aug 8, 2016 | Unrestricted file upload vulnerability in the Document Builder in IBM Rational Publishing Engine (aka RPENG) 2.0.1 befor... |
| CVE-2016-2912 | — | — | 0.6% | Aug 8, 2016 | Cross-site scripting (XSS) vulnerability in the Document Builder in IBM Rational Publishing Engine (aka RPENG) 2.0.1 bef... |
| CVE-2016-2875 | — | — | 2.0% | Aug 8, 2016 | IBM Security QRadar SIEM 7.1.x and 7.2.x before 7.2.7 allows remote authenticated users to execute arbitrary OS commands... |
| CVE-2016-0380 | LOW | 3.3 | 0.3% | Aug 8, 2016 | IBM Sterling Connect:Direct for Unix 4.1.0 before 4.1.0.4 iFix073 and 4.2.0 before 4.2.0.4 iFix003 uses default file per... |
| CVE-2016-0361 | — | — | 1.8% | Aug 8, 2016 | IBM General Parallel File System (GPFS) 3.5 before 3.5.0.29 efix 6 and 4.1.1 before 4.1.1.4 efix 9, when the Spectrum Sc... |
| CVE-2016-0281 | — | — | 8.4% | Aug 8, 2016 | The mustendd driver in IBM AIX 5.3, 6.1, 7.1, and 7.2 and VIOS 2.2.x, when the jumbo_frames feature is not enabled, allo... |
| CVE-2016-0280 | — | — | 0.9% | Aug 8, 2016 | Cross-site scripting (XSS) vulnerability in IBM Information Server Framework 8.5, Information Server Framework and InfoS... |
| CVE-2016-0266 | — | — | 1.4% | Aug 8, 2016 | IBM AIX 5.3, 6.1, 7.1, and 7.2 and VIOS 2.2.x do not default to the latest TLS version, which makes it easier for man-in... |
| CVE-2016-6486 | — | — | 0.5% | Aug 8, 2016 | Siemens SINEMA Server uses weak permissions for the application folder, which allows local users to gain privileges via ... |
| CVE-2016-5792 | — | — | 3.0% | Aug 8, 2016 | SQL injection vulnerability in Moxa SoftCMS before 1.5 allows remote attackers to execute arbitrary SQL commands via uns... |
| CVE-2016-4374 | — | — | 1.8% | Aug 8, 2016 | HPE Release Control (RC) 9.13, 9.20, and 9.21 before 9.21.0005 p4 allows remote authenticated users to conduct server-si... |
| CVE-2016-1478 | — | — | 1.9% | Aug 8, 2016 | Cisco IOS 15.5(3)S3, 15.6(1)S2, 15.6(2)S1, and 15.6(2)T1 does not properly dequeue invalid NTP packets, which allows rem... |
| CVE-2016-1474 | — | — | 1.3% | Aug 8, 2016 | Cisco Prime Infrastructure 2.2(2) does not properly restrict use of IFRAME elements, which makes it easier for remote at... |
| CVE-2016-1468 | — | — | 2.9% | Aug 8, 2016 | The administrative web interface in Cisco TelePresence Video Communication Server Expressway X8.5.2 allows remote authen... |
| CVE-2016-1466 | — | — | 2.9% | Aug 8, 2016 | Cisco Unified Communications Manager IM and Presence Service 9.1(1) SU6, 9.1(1) SU6a, 9.1(1) SU7, 10.5(2) SU2, 10.5(2) S... |
| CVE-2016-1430 | — | — | 3.7% | Aug 8, 2016 | Cisco RV180 and RV180W devices allow remote authenticated users to execute arbitrary commands as root via a crafted HTTP... |
| CVE-2016-1429 | — | — | 7.4% | Aug 8, 2016 | Directory traversal vulnerability in the web interface on Cisco RV180 and RV180W devices allows remote attackers to read... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now