2016 CVE Vulnerabilities

10,648 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-0349——IBM Business Process Manager 8.5.6 through 8.5.6.2 and 8.5.7 before 8.5.7.CF201606 allows remote authenticated users to ...
CVE-2016-0322——Cross-site scripting (XSS) vulnerability in IBM Connections 4.0 through CR4, 4.5 through CR5, 5.0 through CR4, and 5.5 b...
CVE-2016-5839——WordPress before 4.5.3 allows remote attackers to bypass the sanitize_file_name protection mechanism via unspecified vec...
CVE-2016-5838——WordPress before 4.5.3 allows remote attackers to bypass intended password-change restrictions by leveraging knowledge o...
CVE-2016-5837——WordPress before 4.5.3 allows remote attackers to bypass intended access restrictions and remove a category attribute fr...
CVE-2016-5836——The oEmbed protocol implementation in WordPress before 4.5.3 allows remote attackers to cause a denial of service via un...
CVE-2016-5835——WordPress before 4.5.3 allows remote attackers to obtain sensitive revision-history information by leveraging the abilit...
CVE-2016-5834——Cross-site scripting (XSS) vulnerability in the wp_get_attachment_link function in wp-includes/post-template.php in Word...
CVE-2016-5833——Cross-site scripting (XSS) vulnerability in the column_title function in wp-admin/includes/class-wp-media-list-table.php...
CVE-2016-5832——The customizer in WordPress before 4.5.3 allows remote attackers to bypass intended redirection restrictions via unspeci...
CVE-2016-5101——Unspecified vulnerability in Opera Mail before 2016-02-16 on Windows allows user-assisted remote attackers to execute ar...
CVE-2016-1237——nfsd in the Linux kernel through 4.6.3 allows local users to bypass intended file-permission restrictions by setting a P...
CVE-2016-0304——The Java Console in IBM Domino 8.5.x before 8.5.3 FP6 IF13 and 9.x before 9.0.1 FP6, when a certain unsupported configur...
CVE-2016-0298——Directory traversal vulnerability in IBM Security Guardium Database Activity Monitor 10 before 10.0p100 allows remote au...
CVE-2016-0267——IBM UrbanCode Deploy 6.0.x before 6.0.1.13, 6.1.x before 6.1.3.3, and 6.2.x before 6.2.1.1 allows remote authenticated u...
CVE-2016-0263——IBM Spectrum Scale 4.1 before 4.1.1.5 and 4.2 before 4.2.0.2 and General Parallel File System 3.5 before 3.5.0.30 allow ...
CVE-2016-0260——Memory leak in queue-manager agents in IBM WebSphere MQ 8.x before 8.0.0.5 allows remote attackers to cause a denial of ...
CVE-2016-0233——SQL injection vulnerability in IBM Marketing Platform 8.5.x, 8.6.x, and 9.x before 9.1.2.2 allows remote authenticated u...
CVE-2016-0229——Cross-site scripting (XSS) vulnerability in IBM Marketing Platform 8.6.x and 9.x before 9.1.2.2 allows remote attackers ...
CVE-2016-0224——SQL injection vulnerability in IBM Marketing Platform 8.5.x, 8.6.x, and 9.x before 9.1.2.2 allows remote attackers to ex...
CVE-2016-5829HIGH7.8Multiple heap-based buffer overflows in the hiddev_ioctl_usage function in drivers/hid/usbhid/hiddev.c in the Linux kern...
CVE-2016-5828HIGH7.8The start_thread function in arch/powerpc/kernel/process.c in the Linux kernel through 4.6.3 on powerpc platforms mishan...
CVE-2016-5728——Race condition in the vop_ioctl function in drivers/misc/mic/vop/vop_vringh.c in the MIC VOP driver in the Linux kernel ...
CVE-2016-5244——The rds_inc_info_copy function in net/rds/recv.c in the Linux kernel through 4.6.3 does not initialize a certain structu...
CVE-2016-5243——The tipc_nl_compat_link_dump function in net/tipc/netlink_compat.c in the Linux kernel through 4.6.3 does not properly c...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now