2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-2945 | — | — | 1.8% | Jul 8, 2016 | The API Discovery implementation in IBM WebSphere Application Server (WAS) 8.5.5.8 through 8.5.5.9 Liberty before Libert... |
| CVE-2016-2889 | — | — | 0.5% | Jul 8, 2016 | Cross-site request forgery (CSRF) vulnerability in the Report Builder and Data Collection Component (DCC) in IBM Jazz Re... |
| CVE-2016-2888 | — | — | 0.7% | Jul 8, 2016 | Cross-site scripting (XSS) vulnerability in the Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting... |
| CVE-2016-0350 | — | — | 0.6% | Jul 8, 2016 | Cross-site scripting (XSS) vulnerability in the Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting... |
| CVE-2016-0315 | — | — | 1.0% | Jul 8, 2016 | The Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2 ifix016 and ... |
| CVE-2016-0314 | — | — | 0.9% | Jul 8, 2016 | The Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2 ifix016 and ... |
| CVE-2016-0313 | — | — | 0.6% | Jul 8, 2016 | Cross-site scripting (XSS) vulnerability in the Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting... |
| CVE-2016-0287 | — | — | 0.4% | Jul 8, 2016 | IBM i Access 7.1 on Windows allows local users to discover registry passwords via unspecified vectors. |
| CVE-2016-0271 | — | — | 0.3% | Jul 8, 2016 | The agents in IBM UrbanCode Deploy 6.x before 6.0.1.14, 6.1.x before 6.1.3.3, and 6.2.x before 6.2.1.1 do not verify a s... |
| CVE-2016-0252 | — | — | 0.3% | Jul 8, 2016 | IBM Control Center 6.x before 6.0.0.1 iFix06 and Sterling Control Center 5.4.x before 5.4.2.1 iFix09 allow local users t... |
| CVE-2016-2119 | HIGH | 7.5 | 3.1% | Jul 7, 2016 | libcli/smb/smbXcli_base.c in Samba 4.x before 4.2.14, 4.3.x before 4.3.11, and 4.4.x before 4.4.5 allows man-in-the-midd... |
| CVE-2016-2923 | — | — | 2.3% | Jul 7, 2016 | IBM WebSphere Application Server (WAS) 8.5 through 8.5.5.9 Liberty before Liberty Fix Pack 16.0.0.2 does not include the... |
| CVE-2016-1444 | MEDIUM | 6.5 | 1.2% | Jul 7, 2016 | The Mobile and Remote Access (MRA) component in Cisco TelePresence Video Communication Server (VCS) X8.1 through X8.7 an... |
| CVE-2016-1443 | HIGH | 8.1 | 1.1% | Jul 7, 2016 | The virtual network stack on Cisco AMP Threat Grid Appliance devices before 2.1.1 allows remote attackers to bypass a sa... |
| CVE-2016-1442 | — | — | 3.2% | Jul 7, 2016 | The administrative web interface in Cisco Prime Infrastructure (PI) before 3.1.1 allows remote authenticated users to ex... |
| CVE-2016-0389 | — | — | 1.9% | Jul 7, 2016 | Admin Center in IBM WebSphere Application Server (WAS) 8.5.5.2 through 8.5.5.9 Liberty before Liberty Fix Pack 16.0.0.2 ... |
| CVE-2016-0230 | MEDIUM | 6.8 | 0.4% | Jul 7, 2016 | IBM Power Hardware Management Console (HMC) 7.3 through 7.3.0 SP7, 7.9 through 7.9.0 SP3, 8.1 through 8.1.0 SP3, 8.2 thr... |
| CVE-2016-6170 | MEDIUM | 6.5 | 40.5% | Jul 6, 2016 | ISC BIND through 9.9.9-P1, 9.10.x through 9.10.4-P1, and 9.11.x through 9.11.0b1 allows primary DNS servers to cause a d... |
| CVE-2016-4979 | — | — | 18.8% | Jul 6, 2016 | The Apache HTTP Server 2.4.18 through 2.4.20, when mod_http2 and mod_ssl are enabled, does not properly recognize the "S... |
| CVE-2016-4508 | MEDIUM | 6.1 | 0.9% | Jul 6, 2016 | Cross-site scripting (XSS) vulnerability in Rexroth Bosch BLADEcontrol-WebVIS 3.0.2 and earlier allows remote attackers ... |
| CVE-2016-4507 | MEDIUM | 6.4 | 0.9% | Jul 6, 2016 | SQL injection vulnerability in Rexroth Bosch BLADEcontrol-WebVIS 3.0.2 and earlier allows remote authenticated users to ... |
| CVE-2016-1546 | — | — | 15.3% | Jul 6, 2016 | The Apache HTTP Server 2.4.17 and 2.4.18, when mod_http2 is enabled, does not limit the number of simultaneous stream wo... |
| CVE-2016-0906 | — | — | 1.6% | Jul 6, 2016 | The web-restore interface in Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar through 7.1.2 and 7.... |
| CVE-2016-5099 | — | — | 1.1% | Jul 5, 2016 | Cross-site scripting (XSS) vulnerability in phpMyAdmin 4.4.x before 4.4.15.6 and 4.6.x before 4.6.2 allows remote attack... |
| CVE-2016-5098 | — | — | 2.0% | Jul 5, 2016 | Directory traversal vulnerability in libraries/error_report.lib.php in phpMyAdmin before 4.6.2-prerelease allows remote ... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now