2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-3963 | — | — | 8.6% | Apr 8, 2016 | Siemens SCALANCE S613 allows remote attackers to cause a denial of service (web-server outage) via traffic to TCP port 4... |
| CVE-2016-2513 | — | — | 3.3% | Apr 8, 2016 | The password hasher in contrib/auth/hashers.py in Django before 1.8.10 and 1.9.x before 1.9.3 allows remote attackers to... |
| CVE-2016-2512 | — | — | 4.0% | Apr 8, 2016 | The utils.http.is_safe_url function in Django before 1.8.10 and 1.9.x before 1.9.3 allows remote attackers to redirect u... |
| CVE-2016-1375 | — | — | 0.8% | Apr 8, 2016 | Cross-site scripting (XSS) vulnerability in Cisco IP Interoperability and Collaboration System 4.10(1) allows remote att... |
| CVE-2016-3980 | — | — | 7.1% | Apr 8, 2016 | The Java Startup Framework (aka jstart) in SAP JAVA AS 7.2 through 7.4 allows remote attackers to cause a denial of serv... |
| CVE-2016-3979 | — | — | 6.4% | Apr 8, 2016 | Internet Communication Manager (aka ICMAN or ICM) in SAP JAVA AS 7.2 through 7.4 allows remote attackers to cause a deni... |
| CVE-2016-3978 | — | — | 6.3% | Apr 8, 2016 | The Web User Interface (WebUI) in FortiOS 5.0.x before 5.0.13, 5.2.x before 5.2.3, and 5.4.x before 5.4.0 allows remote ... |
| CVE-2016-3188 | — | — | 1.9% | Apr 8, 2016 | The _prepopulate_request_walk function in the Prepopulate module 7.x-2.x before 7.x-2.1 for Drupal allows remote attacke... |
| CVE-2016-3187 | — | — | 1.9% | Apr 8, 2016 | The Prepopulate module 7.x-2.x before 7.x-2.1 for Drupal allows remote attackers to modify the REQUEST superglobal array... |
| CVE-2016-3154 | — | — | 1.8% | Apr 8, 2016 | The encoder_contexte_ajax function in ecrire/inc/filtres.php in SPIP 2.x before 2.1.19, 3.0.x before 3.0.22, and 3.1.x b... |
| CVE-2016-3153 | — | — | 1.8% | Apr 8, 2016 | SPIP 2.x before 2.1.19, 3.0.x before 3.0.22, and 3.1.x before 3.1.1 allows remote attackers to execute arbitrary PHP cod... |
| CVE-2016-2851 | — | — | 25.4% | Apr 7, 2016 | Integer overflow in proto.c in libotr before 4.1.1 on 64-bit platforms allows remote attackers to cause a denial of serv... |
| CVE-2016-2789 | — | — | 0.8% | Apr 7, 2016 | Cross-site scripting (XSS) vulnerability in the Web User Interface in Citrix XenMobile Server 10.0, 10.1 before Rolling ... |
| CVE-2016-2563 | — | — | 34.2% | Apr 7, 2016 | Stack-based buffer overflow in the SCP command-line utility in PuTTY before 0.67 and KiTTY 0.66.6.3 and earlier allows r... |
| CVE-2016-2098 | — | — | 81.4% | Apr 7, 2016 | Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to e... |
| CVE-2016-2097 | — | — | 4.4% | Apr 7, 2016 | Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.2 and 4.x before 4.1.14.2 allows remote ... |
| CVE-2016-1531 | — | — | 5.9% | Apr 7, 2016 | Exim before 4.86.2, when installed setuid root, allows local users to gain privileges via the perl_startup argument. |
| CVE-2016-0792 | — | — | 82.7% | Apr 7, 2016 | Multiple unspecified API endpoints in Jenkins before 1.650 and LTS before 1.642.2 allow remote authenticated users to ex... |
| CVE-2016-0791 | — | — | 2.7% | Apr 7, 2016 | Jenkins before 1.650 and LTS before 1.642.2 do not use a constant-time algorithm to verify CSRF tokens, which makes it e... |
| CVE-2016-0790 | — | — | 2.1% | Apr 7, 2016 | Jenkins before 1.650 and LTS before 1.642.2 do not use a constant-time algorithm to verify API tokens, which makes it ea... |
| CVE-2016-0789 | — | — | 1.8% | Apr 7, 2016 | CRLF injection vulnerability in the CLI command documentation in Jenkins before 1.650 and LTS before 1.642.2 allows remo... |
| CVE-2016-0788 | — | — | 11.8% | Apr 7, 2016 | The remoting module in Jenkins before 1.650 and LTS before 1.642.2 allows remote attackers to execute arbitrary code by ... |
| CVE-2016-2511 | — | — | 1.7% | Apr 7, 2016 | Cross-site scripting (XSS) vulnerability in WebSVN 2.3.3 and earlier allows remote attackers to inject arbitrary web scr... |
| CVE-2016-2216 | — | — | 7.0% | Apr 7, 2016 | The HTTP header parsing code in Node.js 0.10.x before 0.10.42, 0.11.6 through 0.11.16, 0.12.x before 0.12.10, 4.x before... |
| CVE-2016-2086 | — | — | 6.3% | Apr 7, 2016 | Node.js 0.10.x before 0.10.42, 0.12.x before 0.12.10, 4.x before 4.3.0, and 5.x before 5.6.0 allow remote attackers to c... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now