2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-5402 | HIGH | 8.8 | 5.9% | Oct 31, 2018 | A code injection flaw was found in the way capacity and utilization imported control files are processed. A remote, auth... |
| CVE-2016-2121 | MEDIUM | 4 | 0.4% | Oct 31, 2018 | A permissions flaw was found in redis, which sets weak permissions on certain files and directories that could potential... |
| CVE-2016-10734 | — | — | 1.5% | Oct 29, 2018 | ProjectSend (formerly cFTP) r582 allows Insecure Direct Object Reference via includes/actions.log.export.php. |
| CVE-2016-10733 | — | — | 2.1% | Oct 29, 2018 | ProjectSend (formerly cFTP) r582 allows directory traversal via file=../ in the process-zip-download.php query string. |
| CVE-2016-10732 | — | — | 1.9% | Oct 29, 2018 | ProjectSend (formerly cFTP) r582 allows authentication bypass via a direct request for users.php, home.php, edit-file.ph... |
| CVE-2016-10731 | — | — | 1.4% | Oct 29, 2018 | ProjectSend (formerly cFTP) r582 allows SQL injection via manage-files.php with the request parameter status, manage-fil... |
| CVE-2016-10730 | — | — | 0.6% | Oct 24, 2018 | An issue was discovered in Amanda 3.3.1. A user with backup privileges can trivially compromise a client installation. A... |
| CVE-2016-10729 | — | — | 1.2% | Oct 24, 2018 | An issue was discovered in Amanda 3.3.1. A user with backup privileges can trivially compromise a client installation. T... |
| CVE-2016-9069 | — | — | 1.3% | Oct 18, 2018 | A use-after-free in nsINode::ReplaceOrInsertBefore during DOM operations resulting in potentially exploitable crashes. T... |
| CVE-2016-7475 | — | — | 1.3% | Oct 8, 2018 | Under some circumstances on BIG-IP 12.0.0-12.1.0, 11.6.0-11.6.1, or 11.4.0-11.5.4 HF1, the Traffic Management Microkerne... |
| CVE-2016-9045 | HIGH | 8.8 | 2.2% | Sep 17, 2018 | A code execution vulnerability exists in ProcessMaker Enterprise Core 3.0.1.7-community. A specially crafted web request... |
| CVE-2016-0715 | — | — | 1.2% | Sep 11, 2018 | Pivotal Cloud Foundry Elastic Runtime version 1.4.0 through 1.4.5, 1.5.0 through 1.5.11 and 1.6.0 through 1.6.11 is vuln... |
| CVE-2016-7066 | — | — | 0.3% | Sep 11, 2018 | It was found that the improper default permissions on /tmp/auth directory in JBoss Enterprise Application Platform befor... |
| CVE-2016-7074 | MEDIUM | 5.3 | 1.2% | Sep 11, 2018 | An issue has been found in PowerDNS before 3.4.11 and 4.0.2, and PowerDNS recursor before 4.0.4, allowing an attacker in... |
| CVE-2016-7073 | MEDIUM | 5.3 | 1.2% | Sep 11, 2018 | An issue has been found in PowerDNS before 3.4.11 and 4.0.2, and PowerDNS recursor before 4.0.4, allowing an attacker in... |
| CVE-2016-7070 | HIGH | 8 | 0.6% | Sep 11, 2018 | A privilege escalation flaw was found in the Ansible Tower. When Tower before 3.0.3 deploys a PostgreSQL database, it in... |
| CVE-2016-7069 | MEDIUM | 5.9 | 4.5% | Sep 11, 2018 | An issue has been found in dnsdist before 1.2.0 in the way EDNS0 OPT records are handled when parsing responses from a b... |
| CVE-2016-7068 | MEDIUM | 5.3 | 7.3% | Sep 11, 2018 | An issue has been found in PowerDNS before 3.4.11 and 4.0.2, and PowerDNS recursor before 3.7.4 and 4.0.4, allowing a re... |
| CVE-2016-7047 | MEDIUM | 4.3 | 1.3% | Sep 11, 2018 | A flaw was found in the CloudForms API before 5.6.3.0, 5.7.3.1 and 5.8.1.2. A user with permissions to use the MiqReport... |
| CVE-2016-0750 | MEDIUM | 4.2 | 2.4% | Sep 11, 2018 | The hotrod java client in infinispan before 9.1.0.Final automatically deserializes bytearray message contents in certain... |
| CVE-2016-7072 | MEDIUM | 5.3 | 6.3% | Sep 10, 2018 | An issue has been found in PowerDNS Authoritative Server before 3.4.11 and 4.0.2 allowing a remote, unauthenticated atta... |
| CVE-2016-9048 | HIGH | 7.4 | 0.8% | Sep 10, 2018 | Multiple exploitable SQL Injection vulnerabilities exists in ProcessMaker Enterprise Core 3.0.1.7-community. Specially c... |
| CVE-2016-7061 | LOW | 3.5 | 1.8% | Sep 10, 2018 | An information disclosure vulnerability was found in JBoss Enterprise Application Platform before 7.0.4. It was discover... |
| CVE-2016-7056 | MEDIUM | 5.5 | 0.6% | Sep 10, 2018 | A timing attack flaw was found in OpenSSL 1.0.1u and before that could allow a malicious user with local access to recov... |
| CVE-2016-7041 | MEDIUM | 6.5 | 4.0% | Sep 10, 2018 | Drools Workbench contains a path traversal vulnerability. The vulnerability allows a remote, authenticated attacker to b... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now