2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-4567 | — | — | 6.4% | May 22, 2016 | Cross-site scripting (XSS) vulnerability in flash/FlashMediaElement.as in MediaElement.js before 2.21.0, as used in Word... |
| CVE-2016-4566 | — | — | 5.4% | May 22, 2016 | Cross-site scripting (XSS) vulnerability in plupload.flash.swf in Plupload before 2.1.9, as used in WordPress before 4.5... |
| CVE-2016-4543 | — | — | 12.2% | May 22, 2016 | The exif_process_IFD_in_JPEG function in ext/exif/exif.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6... |
| CVE-2016-4542 | — | — | 6.1% | May 22, 2016 | The exif_process_IFD_TAG function in ext/exif/exif.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 doe... |
| CVE-2016-4541 | — | — | 6.2% | May 22, 2016 | The grapheme_strpos function in ext/intl/grapheme/grapheme_string.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x b... |
| CVE-2016-4540 | — | — | 6.2% | May 22, 2016 | The grapheme_stripos function in ext/intl/grapheme/grapheme_string.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x ... |
| CVE-2016-4539 | — | — | 6.2% | May 22, 2016 | The xml_parse_into_struct function in ext/xml/xml.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 allo... |
| CVE-2016-4538 | — | — | 6.2% | May 22, 2016 | The bcpowmod function in ext/bcmath/bcmath.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 modifies ce... |
| CVE-2016-4537 | — | — | 5.9% | May 22, 2016 | The bcpowmod function in ext/bcmath/bcmath.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 accepts a n... |
| CVE-2016-4342 | — | — | 5.3% | May 22, 2016 | ext/phar/phar_object.c in PHP before 5.5.32, 5.6.x before 5.6.18, and 7.x before 7.0.3 mishandles zero-length uncompress... |
| CVE-2016-2222 | — | — | 9.3% | May 22, 2016 | The wp_http_validate_url function in wp-includes/http.php in WordPress before 4.4.2 allows remote attackers to conduct s... |
| CVE-2016-2221 | — | — | 4.7% | May 22, 2016 | Open redirect vulnerability in the wp_validate_redirect function in wp-includes/pluggable.php in WordPress before 4.4.2 ... |
| CVE-2016-1564 | — | — | 2.7% | May 22, 2016 | Multiple cross-site scripting (XSS) vulnerabilities in wp-includes/class-wp-theme.php in WordPress before 4.4.1 allow re... |
| CVE-2016-1402 | — | — | 2.0% | May 21, 2016 | The Active Directory (AD) integration component in Cisco Identity Service Engine (ISE) before 1.2.0.899 patch 7, when AD... |
| CVE-2016-1401 | — | — | 1.0% | May 21, 2016 | Cross-site scripting (XSS) vulnerability in the management interface in Cisco Unified Computing System (UCS) Central Sof... |
| CVE-2016-4348 | — | — | 2.4% | May 20, 2016 | The _rsvg_css_normalize_font_size function in librsvg 2.40.2 allows context-dependent attackers to cause a denial of ser... |
| CVE-2016-3739 | — | — | 6.4% | May 20, 2016 | The (1) mbed_connect_step1 function in lib/vtls/mbedtls.c and (2) polarssl_connect_step1 function in lib/vtls/polarssl.c... |
| CVE-2016-3728 | — | — | 2.8% | May 20, 2016 | Eval injection vulnerability in tftp_api.rb in the TFTP module in the Smart-Proxy in Foreman before 1.10.4 and 1.11.x be... |
| CVE-2016-3693 | — | — | 2.1% | May 20, 2016 | The Safemode gem before 1.2.4 for Ruby, when initialized with a delegate object that is a Rails controller, allows conte... |
| CVE-2016-2100 | — | — | 1.2% | May 20, 2016 | Foreman before 1.10.3 and 1.11.0 before 1.11.0-RC2 allow remote authenticated users to read, modify, or delete private b... |
| CVE-2016-4073 | — | — | 7.3% | May 20, 2016 | Multiple integer overflows in the mbfl_strcut function in ext/mbstring/libmbfl/mbfl/mbfilter.c in PHP before 5.5.34, 5.6... |
| CVE-2016-4072 | — | — | 5.9% | May 20, 2016 | The Phar extension in PHP before 5.5.34, 5.6.x before 5.6.20, and 7.x before 7.0.5 allows remote attackers to execute ar... |
| CVE-2016-4071 | — | — | 19.5% | May 20, 2016 | Format string vulnerability in the php_snmp_error function in ext/snmp/snmp.c in PHP before 5.5.34, 5.6.x before 5.6.20,... |
| CVE-2016-4070 | — | — | 5.7% | May 20, 2016 | Integer overflow in the php_raw_url_encode function in ext/standard/url.c in PHP before 5.5.34, 5.6.x before 5.6.20, and... |
| CVE-2016-1859 | — | — | 2.6% | May 20, 2016 | The WebKit Canvas implementation in Apple iOS before 9.3.2, Safari before 9.1.1, and tvOS before 9.2.1 allows remote att... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now