2016 CVE Vulnerabilities

10,645 CVEs published in 2016.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2016-2139MEDIUM6.4In kippo-graph before version 1.5.1, there is a cross-site scripting vulnerability in $file_link in class/KippoInput.cla...
CVE-2016-2138MEDIUM6.4In kippo-graph before version 1.5.1, there is a cross-site scripting vulnerability in xss_clean() in class/KippoInput.cl...
CVE-2016-2124MEDIUM5.9A flaw was found in the way samba implemented SMB1 authentication. An attacker could use this flaw to retrieve the plain...
CVE-2016-6556MEDIUM6.1OpenNMS version 18.0.1 and prior are vulnerable to a stored XSS issue due to insufficient filtering of SNMP agent suppli...
CVE-2016-6555MEDIUM6.1OpenNMS version 18.0.1 and prior are vulnerable to a stored XSS issue due to insufficient filtering of SNMP trap supplie...
CVE-2016-20012MEDIUM5.3OpenSSH through 8.7 allows remote attackers, who have a suspicion that a certain combination of username and public key ...
CVE-2016-11085MEDIUM6.5php/qmn_options_questions_tab.php in the quiz-master-next plugin before 4.7.9 for WordPress allows CSRF, with resultant ...
CVE-2016-11084MEDIUM6.1An issue was discovered in Mattermost Server before 2.1.0. It allows XSS via CSRF.
CVE-2016-11083MEDIUM6.1An issue was discovered in Mattermost Server before 2.2.0. It allows XSS because it configures files to be opened in a b...
CVE-2016-11082MEDIUM6.1An issue was discovered in Mattermost Server before 2.2.0. It allows XSS via a crafted link.
CVE-2016-11081MEDIUM4.3An issue was discovered in Mattermost Server before 2.2.0. It allows unintended access to information stored by a web br...
CVE-2016-11080MEDIUM4.3An issue was discovered in Mattermost Server before 3.0.0. It offers superfluous APIs for a Team Administrator to view a...
CVE-2016-11079MEDIUM6.1An issue was discovered in Mattermost Server before 3.0.0. It allows XSS via a redirect URL.
CVE-2016-11078MEDIUM6.5An issue was discovered in Mattermost Server before 3.0.0. It potentially allows attackers to obtain sensitive informati...
CVE-2016-11076MEDIUM5.3An issue was discovered in Mattermost Server before 3.0.0. It does not ensure that a cookie is used over SSL.
CVE-2016-11075MEDIUM5.3An issue was discovered in Mattermost Server before 3.0.0. It allows attackers to obtain sensitive information about tea...
CVE-2016-11073MEDIUM6.1An issue was discovered in Mattermost Server before 3.0.0. It allows XSS via a Legal or Support setting.
CVE-2016-11072MEDIUM6.5An issue was discovered in Mattermost Server before 3.0.2. The purposes of a session ID and a Session Token were mishand...
CVE-2016-11071MEDIUM6.1An issue was discovered in Mattermost Server before 3.1.0. It allows XSS because the noreferrer and noopener protection ...
CVE-2016-11070MEDIUM5.4An issue was discovered in Mattermost Server before 3.1.0. It allows XSS via theme color-code values.
CVE-2016-11068MEDIUM5.3An issue was discovered in Mattermost Server before 3.2.0. Attackers could read LDAP fields via injection.
CVE-2016-11067MEDIUM5.3An issue was discovered in Mattermost Server before 3.2.0. It allowed crafted posts that could cause a web browser to ha...
CVE-2016-11065MEDIUM4.3An issue was discovered in Mattermost Server before 3.3.0. An attacker could use the WebSocket feature to send pop-up me...
CVE-2016-11063MEDIUM6.1An issue was discovered in Mattermost Server before 3.5.1. XSS can occur via file preview.
CVE-2016-11062MEDIUM5.3An issue was discovered in Mattermost Server before 3.5.1. E-mail address verification can be bypassed.

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now