2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-0089 | — | — | 3.4% | Apr 12, 2016 | Hyper-V in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, and Windows 10 allows guest OS users to obtain sensit... |
| CVE-2016-0088 | — | — | 7.5% | Apr 12, 2016 | Hyper-V in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, and Windows 10 allows guest OS users to execute arbit... |
| CVE-2016-4004 | — | — | 8.9% | Apr 12, 2016 | Directory traversal vulnerability in Dell OpenManage Server Administrator (OMSA) 8.2 allows remote authenticated adminis... |
| CVE-2016-3657 | — | — | 4.8% | Apr 12, 2016 | Buffer overflow in the GlobalProtect Portal in Palo Alto Networks PAN-OS before 5.0.18, 6.0.x before 6.0.13, 6.1.x befor... |
| CVE-2016-3656 | — | — | 1.8% | Apr 12, 2016 | The GlobalProtect Portal in Palo Alto Networks PAN-OS before 5.0.18, 6.0.x before 6.0.13, 6.1.x before 6.1.10, and 7.0.x... |
| CVE-2016-3655 | — | — | 3.2% | Apr 12, 2016 | The management web interface in Palo Alto Networks PAN-OS before 5.0.18, 6.0.x before 6.0.13, 6.1.x before 6.1.10, and 7... |
| CVE-2016-3654 | — | — | 2.6% | Apr 12, 2016 | The device management command line interface (CLI) in Palo Alto Networks PAN-OS before 5.0.18, 5.1.x before 5.1.11, 6.0.... |
| CVE-2016-2405 | — | — | 1.8% | Apr 12, 2016 | Huawei Policy Center with software before V100R003C10SPC020 allows remote authenticated users to gain privileges and cau... |
| CVE-2016-4003 | — | — | 12.0% | Apr 12, 2016 | Cross-site scripting (XSS) vulnerability in the URLDecoder function in JRE before 1.8, as used in Apache Struts 2.x befo... |
| CVE-2016-3172 | — | — | 2.8% | Apr 12, 2016 | SQL injection vulnerability in tree.php in Cacti 0.8.8g and earlier allows remote authenticated users to execute arbitra... |
| CVE-2016-3157 | — | — | 0.5% | Apr 12, 2016 | The __switch_to function in arch/x86/kernel/process_64.c in the Linux kernel does not properly context-switch IOPL on 64... |
| CVE-2016-2162 | — | — | 9.2% | Apr 12, 2016 | Apache Struts 2.x before 2.3.25 does not sanitize text in the Locale object constructed by I18NInterceptor, which might ... |
| CVE-2016-0785 | — | — | 8.8% | Apr 12, 2016 | Apache Struts 2.x before 2.3.28 allows remote attackers to execute arbitrary code via a "%{}" sequence in a tag attribut... |
| CVE-2016-3171 | — | — | 3.2% | Apr 12, 2016 | Drupal 6.x before 6.38, when used with PHP before 5.4.45, 5.5.x before 5.5.29, or 5.6.x before 5.6.13, might allow remot... |
| CVE-2016-3170 | — | — | 2.1% | Apr 12, 2016 | The "have you forgotten your password" links in the User module in Drupal 7.x before 7.43 and 8.x before 8.0.4 allow rem... |
| CVE-2016-3169 | — | — | 2.2% | Apr 12, 2016 | The User module in Drupal 6.x before 6.38 and 7.x before 7.43 allows remote attackers to gain privileges by leveraging c... |
| CVE-2016-3168 | — | — | 2.5% | Apr 12, 2016 | The System module in Drupal 6.x before 6.38 and 7.x before 7.43 might allow remote attackers to hijack the authenticatio... |
| CVE-2016-3167 | — | — | 1.4% | Apr 12, 2016 | Open redirect vulnerability in the drupal_goto function in Drupal 6.x before 6.38, when used with PHP before 5.4.7, allo... |
| CVE-2016-3166 | — | — | 1.2% | Apr 12, 2016 | CRLF injection vulnerability in the drupal_set_header function in Drupal 6.x before 6.38, when used with PHP before 5.1.... |
| CVE-2016-3165 | — | — | 1.4% | Apr 12, 2016 | The Form API in Drupal 6.x before 6.38 ignores access restrictions on submit buttons, which might allow remote attackers... |
| CVE-2016-3164 | — | — | 1.9% | Apr 12, 2016 | Drupal 6.x before 6.38, 7.x before 7.43, and 8.x before 8.0.4 might allow remote attackers to conduct open redirect atta... |
| CVE-2016-3163 | — | — | 1.4% | Apr 12, 2016 | The XML-RPC system in Drupal 6.x before 6.38 and 7.x before 7.43 might make it easier for remote attackers to conduct br... |
| CVE-2016-3162 | — | — | 1.6% | Apr 12, 2016 | The File module in Drupal 7.x before 7.43 and 8.x before 8.0.4 allows remote authenticated users to bypass access restri... |
| CVE-2016-2166 | — | — | 4.3% | Apr 12, 2016 | The (1) proton.reactor.Connector, (2) proton.reactor.Container, and (3) proton.utils.BlockingConnection classes in Apach... |
| CVE-2016-2140 | — | — | 2.1% | Apr 12, 2016 | The libvirt driver in OpenStack Compute (Nova) before 2015.1.4 (kilo) and 12.0.x before 12.0.3 (liberty), when using raw... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now