2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-1149 | — | — | 1.1% | Feb 17, 2016 | Cross-site scripting (XSS) vulnerability in Cybozu Office 9.0.0 through 10.3.0 allows remote attackers to inject arbitra... |
| CVE-2016-2389 | — | — | 41.4% | Feb 16, 2016 | Directory traversal vulnerability in the GetFileList function in the SAP Manufacturing Integration and Intelligence (xMI... |
| CVE-2016-2387 | — | — | 1.5% | Feb 16, 2016 | Multiple cross-site scripting (XSS) vulnerabilities in the Java Proxy Runtime ProxyServer servlet in SAP NetWeaver 7.4 a... |
| CVE-2016-0751 | — | — | 9.7% | Feb 16, 2016 | actionpack/lib/action_dispatch/http/mime_type.rb in Action Pack in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before... |
| CVE-2016-1331 | — | — | 1.0% | Feb 15, 2016 | Multiple cross-site scripting (XSS) vulnerabilities in Cisco Emergency Responder 11.5(0.99833.5) allow remote attackers ... |
| CVE-2016-1330 | — | — | 0.7% | Feb 15, 2016 | Cisco IOS 15.2(4)E on Industrial Ethernet 2000 devices allows remote attackers to cause a denial of service (device relo... |
| CVE-2016-1321 | — | — | 0.9% | Feb 15, 2016 | Cisco Universal Small Cell devices with firmware R2.12 through R3.5 contain an image-decryption key in flash memory, whi... |
| CVE-2016-0232 | — | — | 1.1% | Feb 15, 2016 | IBM Financial Transaction Manager (FTM) for ACH Services, Check Services and Corporate Payment Services (CPS) 3.0.0 befo... |
| CVE-2016-0231 | — | — | 1.1% | Feb 15, 2016 | IBM Financial Transaction Manager (FTM) for ACH Services, Check Services and Corporate Payment Services (CPS) 3.0.0 befo... |
| CVE-2016-2314 | — | — | 0.9% | Feb 15, 2016 | GlobespanVirata ftpd 1.0, as used on Huawei SmartAX MT882 devices V200R002B022 Arg, allows remote authenticated users to... |
| CVE-2016-2231 | — | — | 1.2% | Feb 15, 2016 | The Windows-based Host Interface Program (WHIP) service on Huawei SmartAX MT882 devices V200R002B022 Arg relies on the c... |
| CVE-2016-0701 | — | — | 83.6% | Feb 15, 2016 | The DH_check_pub_key function in crypto/dh/dh_check.c in OpenSSL 1.0.2 before 1.0.2f does not ensure that prime numbers ... |
| CVE-2016-1627 | — | — | 1.3% | Feb 14, 2016 | The Developer Tools (aka DevTools) subsystem in Google Chrome before 48.0.2564.109 does not validate URL schemes and ens... |
| CVE-2016-1626 | — | — | 1.3% | Feb 14, 2016 | The opj_pi_update_decode_poc function in pi.c in OpenJPEG, as used in PDFium in Google Chrome before 48.0.2564.109, misc... |
| CVE-2016-1625 | — | — | 1.2% | Feb 14, 2016 | The Chrome Instant feature in Google Chrome before 48.0.2564.109 does not ensure that a New Tab Page (NTP) navigation ta... |
| CVE-2016-1624 | — | — | 1.4% | Feb 14, 2016 | Integer underflow in the ProcessCommandsInternal function in dec/decode.c in Brotli, as used in Google Chrome before 48.... |
| CVE-2016-1623 | — | — | 1.2% | Feb 14, 2016 | The DOM implementation in Google Chrome before 48.0.2564.109 does not properly restrict frame-attach operations from occ... |
| CVE-2016-1622 | — | — | 1.3% | Feb 14, 2016 | The Extensions subsystem in Google Chrome before 48.0.2564.109 does not prevent use of the Object.defineProperty method ... |
| CVE-2016-1949 | — | — | 1.5% | Feb 13, 2016 | Mozilla Firefox before 44.0.2 does not properly restrict the interaction between Service Workers and plugins, which allo... |
| CVE-2016-1526 | — | — | 2.3% | Feb 13, 2016 | The TtfUtil:LocaLookup function in TtfUtil.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.... |
| CVE-2016-1525 | — | — | 75.0% | Feb 13, 2016 | Directory traversal vulnerability in data/config/image.do in NETGEAR Management System NMS300 1.5.0.11 and earlier allow... |
| CVE-2016-1524 | — | — | 94.1% | Feb 13, 2016 | Multiple unrestricted file upload vulnerabilities in NETGEAR Management System NMS300 1.5.0.11 and earlier allow remote ... |
| CVE-2016-1523 | — | — | 2.3% | Feb 13, 2016 | The SillMap::readFace function in FeatureMap.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 4... |
| CVE-2016-1522 | — | — | 8.3% | Feb 13, 2016 | Code.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, ... |
| CVE-2016-1521 | — | — | 4.1% | Feb 13, 2016 | The directrun function in directmachine.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 a... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now