2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-0275 | — | — | 0.3% | Mar 9, 2018 | IBM Financial Transaction Manager (FTM) for ACH Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, Financial... |
| CVE-2016-0274 | — | — | 0.6% | Mar 9, 2018 | IBM Financial Transaction Manager (FTM) for ACH Services for Multi-Platform 2.1.1.2 and 3.0.0.x before fp0013, Financial... |
| CVE-2016-0272 | — | — | 0.7% | Mar 9, 2018 | Cross-site request forgery (CSRF) vulnerability in IBM Financial Transaction Manager (FTM) for ACH Services for Multi-Pl... |
| CVE-2016-0268 | — | — | 0.8% | Mar 9, 2018 | XML external entity (XXE) vulnerability in IBM Financial Transaction Manager (FTM) for ACH Services for Multi-Platform 2... |
| CVE-2016-0253 | — | — | 0.7% | Mar 9, 2018 | Cross-site scripting (XSS) vulnerability in IBM Financial Transaction Manager (FTM) for ACH Services for Multi-Platform ... |
| CVE-2016-9585 | — | — | 1.2% | Mar 9, 2018 | Red Hat JBoss EAP version 5 is vulnerable to a deserialization of untrusted data in the JMX endpoint when deserializes t... |
| CVE-2016-7443 | — | — | 2.2% | Mar 7, 2018 | Exponent CMS 2.3.0 through 2.3.9 allows remote attackers to have unspecified impact via vectors related to "uploading fi... |
| CVE-2016-5179 | — | — | 2.4% | Mar 7, 2018 | Chrome OS before 53.0.2785.144 allows remote attackers to execute arbitrary commands at boot. |
| CVE-2016-0299 | — | — | 1.7% | Feb 28, 2018 | IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.3, and 3.5 before 3.5.0.1 allows remote attackers ... |
| CVE-2016-0295 | — | — | 1.0% | Feb 28, 2018 | Cross-site request forgery (CSRF) vulnerability in the IBM BigFix Platform 9.0, 9.1, 9.2, and 9.5 before 9.5.2 allows re... |
| CVE-2016-0291 | — | — | 3.9% | Feb 28, 2018 | IBM BigFix Platform 9.0, 9.1 before 9.1.8, and 9.2 before 9.2.8 allow remote authenticated users to execute arbitrary co... |
| CVE-2016-10714 | — | — | 2.2% | Feb 27, 2018 | In zsh before 5.3, an off-by-one error resulted in undersized buffers that were intended to support PATH_MAX characters. |
| CVE-2016-0369 | — | — | 1.0% | Feb 21, 2018 | XML external entity (XXE) vulnerability in IBM Forms Experience Builder 8.5, 8.5.1, and 8.6 allows remote authenticated ... |
| CVE-2016-0367 | — | — | 1.0% | Feb 21, 2018 | IBM Security Identity Manager Virtual Appliance 7.0.x before 7.0.1.3-ISS-SIM-IF0001 allows remote authenticated users to... |
| CVE-2016-0366 | — | — | 0.7% | Feb 21, 2018 | IBM Security Identity Manager Virtual Appliance 7.0.x before 7.0.1.3-ISS-SIM-IF0001 might allow remote attackers to obta... |
| CVE-2016-0351 | — | — | 1.1% | Feb 21, 2018 | IBM Security Identity Manager Virtual Appliance 7.0.x before 7.0.1.3-ISS-SIM-IF0001 does not set the secure flag for the... |
| CVE-2016-0348 | — | — | 0.7% | Feb 21, 2018 | Cross-site request forgery (CSRF) vulnerability in IBM TRIRIGA Application Platform 3.3, 3.3.1, 3.3.2, and 3.4 allows re... |
| CVE-2016-0345 | — | — | 1.0% | Feb 21, 2018 | IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.3, and 3.5 before 3.5.0.1 allows remote authentica... |
| CVE-2016-0344 | — | — | 0.7% | Feb 21, 2018 | Cross-site scripting (XSS) vulnerability in the My Reports component in IBM TRIRIGA Application Platform 3.3 before 3.3.... |
| CVE-2016-0343 | — | — | 1.0% | Feb 21, 2018 | IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.3, and 3.5 before 3.5.0.1 allows remote authentica... |
| CVE-2016-6272 | — | — | 21.7% | Feb 20, 2018 | XPath injection vulnerability in Epic MyChart allows remote attackers to access contents of an XML document containing s... |
| CVE-2016-10008 | — | — | 1.3% | Feb 19, 2018 | SQL injection vulnerability in the "Content Types > Content Types" screen in dotCMS before 3.7.2 and 4.x before 4.1.1 al... |
| CVE-2016-10007 | — | — | 1.3% | Feb 19, 2018 | SQL injection vulnerability in the "Marketing > Forms" screen in dotCMS before 3.7.2 and 4.x before 4.1.1 allows remote ... |
| CVE-2016-9568 | — | — | 1.8% | Feb 19, 2018 | A security design issue can allow an unprivileged user to interact with the Carbon Black Sensor and perform unauthorized... |
| CVE-2016-8750 | — | — | 5.5% | Feb 19, 2018 | Apache Karaf prior to 4.0.8 used the LDAPLoginModule to authenticate users to a directory via LDAP. However, it did not ... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now