2016 CVE Vulnerabilities

10,647 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-0322Cross-site scripting (XSS) vulnerability in IBM Connections 4.0 through CR4, 4.5 through CR5, 5.0 through CR4, and 5.5 b...
CVE-2016-5839WordPress before 4.5.3 allows remote attackers to bypass the sanitize_file_name protection mechanism via unspecified vec...
CVE-2016-5838WordPress before 4.5.3 allows remote attackers to bypass intended password-change restrictions by leveraging knowledge o...
CVE-2016-5837WordPress before 4.5.3 allows remote attackers to bypass intended access restrictions and remove a category attribute fr...
CVE-2016-5836The oEmbed protocol implementation in WordPress before 4.5.3 allows remote attackers to cause a denial of service via un...
CVE-2016-5835WordPress before 4.5.3 allows remote attackers to obtain sensitive revision-history information by leveraging the abilit...
CVE-2016-5834Cross-site scripting (XSS) vulnerability in the wp_get_attachment_link function in wp-includes/post-template.php in Word...
CVE-2016-5833Cross-site scripting (XSS) vulnerability in the column_title function in wp-admin/includes/class-wp-media-list-table.php...
CVE-2016-5832The customizer in WordPress before 4.5.3 allows remote attackers to bypass intended redirection restrictions via unspeci...
CVE-2016-5101Unspecified vulnerability in Opera Mail before 2016-02-16 on Windows allows user-assisted remote attackers to execute ar...
CVE-2016-1237nfsd in the Linux kernel through 4.6.3 allows local users to bypass intended file-permission restrictions by setting a P...
CVE-2016-0304The Java Console in IBM Domino 8.5.x before 8.5.3 FP6 IF13 and 9.x before 9.0.1 FP6, when a certain unsupported configur...
CVE-2016-0298Directory traversal vulnerability in IBM Security Guardium Database Activity Monitor 10 before 10.0p100 allows remote au...
CVE-2016-0267IBM UrbanCode Deploy 6.0.x before 6.0.1.13, 6.1.x before 6.1.3.3, and 6.2.x before 6.2.1.1 allows remote authenticated u...
CVE-2016-0263IBM Spectrum Scale 4.1 before 4.1.1.5 and 4.2 before 4.2.0.2 and General Parallel File System 3.5 before 3.5.0.30 allow ...
CVE-2016-0260Memory leak in queue-manager agents in IBM WebSphere MQ 8.x before 8.0.0.5 allows remote attackers to cause a denial of ...
CVE-2016-0233SQL injection vulnerability in IBM Marketing Platform 8.5.x, 8.6.x, and 9.x before 9.1.2.2 allows remote authenticated u...
CVE-2016-0229Cross-site scripting (XSS) vulnerability in IBM Marketing Platform 8.6.x and 9.x before 9.1.2.2 allows remote attackers ...
CVE-2016-0224SQL injection vulnerability in IBM Marketing Platform 8.5.x, 8.6.x, and 9.x before 9.1.2.2 allows remote attackers to ex...
CVE-2016-5829HIGH7.8Multiple heap-based buffer overflows in the hiddev_ioctl_usage function in drivers/hid/usbhid/hiddev.c in the Linux kern...
CVE-2016-5828HIGH7.8The start_thread function in arch/powerpc/kernel/process.c in the Linux kernel through 4.6.3 on powerpc platforms mishan...
CVE-2016-5728Race condition in the vop_ioctl function in drivers/misc/mic/vop/vop_vringh.c in the MIC VOP driver in the Linux kernel ...
CVE-2016-5244The rds_inc_info_copy function in net/rds/recv.c in the Linux kernel through 4.6.3 does not initialize a certain structu...
CVE-2016-5243The tipc_nl_compat_link_dump function in net/tipc/netlink_compat.c in the Linux kernel through 4.6.3 does not properly c...
CVE-2016-4470The key_reject_and_link function in security/keys/key.c in the Linux kernel through 4.6.3 does not ensure that a certain...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now