2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-0322 | — | — | 0.6% | Jun 30, 2016 | Cross-site scripting (XSS) vulnerability in IBM Connections 4.0 through CR4, 4.5 through CR5, 5.0 through CR4, and 5.5 b... |
| CVE-2016-5839 | — | — | 2.5% | Jun 29, 2016 | WordPress before 4.5.3 allows remote attackers to bypass the sanitize_file_name protection mechanism via unspecified vec... |
| CVE-2016-5838 | — | — | 2.7% | Jun 29, 2016 | WordPress before 4.5.3 allows remote attackers to bypass intended password-change restrictions by leveraging knowledge o... |
| CVE-2016-5837 | — | — | 3.5% | Jun 29, 2016 | WordPress before 4.5.3 allows remote attackers to bypass intended access restrictions and remove a category attribute fr... |
| CVE-2016-5836 | — | — | 4.1% | Jun 29, 2016 | The oEmbed protocol implementation in WordPress before 4.5.3 allows remote attackers to cause a denial of service via un... |
| CVE-2016-5835 | — | — | 3.6% | Jun 29, 2016 | WordPress before 4.5.3 allows remote attackers to obtain sensitive revision-history information by leveraging the abilit... |
| CVE-2016-5834 | — | — | 2.1% | Jun 29, 2016 | Cross-site scripting (XSS) vulnerability in the wp_get_attachment_link function in wp-includes/post-template.php in Word... |
| CVE-2016-5833 | — | — | 2.1% | Jun 29, 2016 | Cross-site scripting (XSS) vulnerability in the column_title function in wp-admin/includes/class-wp-media-list-table.php... |
| CVE-2016-5832 | — | — | 2.7% | Jun 29, 2016 | The customizer in WordPress before 4.5.3 allows remote attackers to bypass intended redirection restrictions via unspeci... |
| CVE-2016-5101 | — | — | 2.9% | Jun 29, 2016 | Unspecified vulnerability in Opera Mail before 2016-02-16 on Windows allows user-assisted remote attackers to execute ar... |
| CVE-2016-1237 | — | — | 0.4% | Jun 29, 2016 | nfsd in the Linux kernel through 4.6.3 allows local users to bypass intended file-permission restrictions by setting a P... |
| CVE-2016-0304 | — | — | 2.5% | Jun 29, 2016 | The Java Console in IBM Domino 8.5.x before 8.5.3 FP6 IF13 and 9.x before 9.0.1 FP6, when a certain unsupported configur... |
| CVE-2016-0298 | — | — | 1.3% | Jun 29, 2016 | Directory traversal vulnerability in IBM Security Guardium Database Activity Monitor 10 before 10.0p100 allows remote au... |
| CVE-2016-0267 | — | — | 1.0% | Jun 29, 2016 | IBM UrbanCode Deploy 6.0.x before 6.0.1.13, 6.1.x before 6.1.3.3, and 6.2.x before 6.2.1.1 allows remote authenticated u... |
| CVE-2016-0263 | — | — | 0.3% | Jun 29, 2016 | IBM Spectrum Scale 4.1 before 4.1.1.5 and 4.2 before 4.2.0.2 and General Parallel File System 3.5 before 3.5.0.30 allow ... |
| CVE-2016-0260 | — | — | 1.3% | Jun 29, 2016 | Memory leak in queue-manager agents in IBM WebSphere MQ 8.x before 8.0.0.5 allows remote attackers to cause a denial of ... |
| CVE-2016-0233 | — | — | 1.1% | Jun 28, 2016 | SQL injection vulnerability in IBM Marketing Platform 8.5.x, 8.6.x, and 9.x before 9.1.2.2 allows remote authenticated u... |
| CVE-2016-0229 | — | — | 0.8% | Jun 28, 2016 | Cross-site scripting (XSS) vulnerability in IBM Marketing Platform 8.6.x and 9.x before 9.1.2.2 allows remote attackers ... |
| CVE-2016-0224 | — | — | 1.3% | Jun 28, 2016 | SQL injection vulnerability in IBM Marketing Platform 8.5.x, 8.6.x, and 9.x before 9.1.2.2 allows remote attackers to ex... |
| CVE-2016-5829 | HIGH | 7.8 | 0.5% | Jun 27, 2016 | Multiple heap-based buffer overflows in the hiddev_ioctl_usage function in drivers/hid/usbhid/hiddev.c in the Linux kern... |
| CVE-2016-5828 | HIGH | 7.8 | 0.4% | Jun 27, 2016 | The start_thread function in arch/powerpc/kernel/process.c in the Linux kernel through 4.6.3 on powerpc platforms mishan... |
| CVE-2016-5728 | — | — | 0.4% | Jun 27, 2016 | Race condition in the vop_ioctl function in drivers/misc/mic/vop/vop_vringh.c in the MIC VOP driver in the Linux kernel ... |
| CVE-2016-5244 | — | — | 5.6% | Jun 27, 2016 | The rds_inc_info_copy function in net/rds/recv.c in the Linux kernel through 4.6.3 does not initialize a certain structu... |
| CVE-2016-5243 | — | — | 0.5% | Jun 27, 2016 | The tipc_nl_compat_link_dump function in net/tipc/netlink_compat.c in the Linux kernel through 4.6.3 does not properly c... |
| CVE-2016-4470 | — | — | 0.6% | Jun 27, 2016 | The key_reject_and_link function in security/keys/key.c in the Linux kernel through 4.6.3 does not ensure that a certain... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now