2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-10709 | — | — | 34.3% | Jan 22, 2018 | pfSense before 2.3 allows remote authenticated users to execute arbitrary OS commands via a '|' character in the status_... |
| CVE-2016-6814 | — | — | 17.5% | Jan 18, 2018 | When an application with unsupported Codehaus versions of Groovy from 1.7.0 to 2.4.3, Apache Groovy 2.4.4 to 2.4.7 on cl... |
| CVE-2016-0219 | — | — | 1.3% | Jan 16, 2018 | XML external entity (XXE) vulnerability in IBM Rational Team Concert 3.0 before 3.0.1.6 iFix7 Interim Fix 1, 4.0 before ... |
| CVE-2016-0215 | — | — | 1.6% | Jan 16, 2018 | IBM DB2 9.7, 10.1 before FP6, and 10.5 before FP8 on AIX, Linux, HP, Solaris and Windows allow remote authenticated user... |
| CVE-2016-0207 | — | — | 0.7% | Jan 16, 2018 | IBM Algorithmics One-Algo Risk Application (ARA) 4.9.1 through 5.1.0 allows remote authenticated users to conduct clickj... |
| CVE-2016-10706 | — | — | 1.0% | Jan 12, 2018 | The Jetpack plugin before 4.0.3 for WordPress has XSS via a crafted Vimeo link. |
| CVE-2016-10705 | — | — | 1.0% | Jan 12, 2018 | The Jetpack plugin before 4.0.4 for WordPress has XSS via the Likes module. |
| CVE-2016-0336 | — | — | 0.6% | Jan 12, 2018 | Cross-site scripting (XSS) vulnerability in IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1... |
| CVE-2016-0335 | — | — | 0.8% | Jan 12, 2018 | Cross-site request forgery (CSRF) vulnerability in IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 throug... |
| CVE-2016-0332 | — | — | 2.3% | Jan 12, 2018 | IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.0 before 7.0.1-ISS-SIM-FP0001 do not proper... |
| CVE-2016-0327 | — | — | 0.3% | Jan 12, 2018 | IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.0 before 7.0.1-ISS-SIM-FP0001 allows local ... |
| CVE-2016-0324 | — | — | 3.7% | Jan 12, 2018 | IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.0 before 7.0.1-ISS-SIM-FP0001 allows remote... |
| CVE-2016-9722 | — | — | 12.0% | Jan 10, 2018 | IBM QRadar 7.2 and 7.3 specifies permissions for a security-critical resource in a way that allows that resource to be r... |
| CVE-2016-6810 | — | — | 6.1% | Jan 10, 2018 | In Apache ActiveMQ 5.x before 5.14.2, an instance of a cross-site scripting vulnerability was identified to be present i... |
| CVE-2016-10257 | — | — | 1.5% | Jan 10, 2018 | The Symantec Advanced Secure Gateway (ASG) 6.6, ASG 6.7 (prior to 6.7.2.1), ProxySG 6.5 (prior to 6.5.10.6), ProxySG 6.6... |
| CVE-2016-10256 | — | — | 1.5% | Jan 10, 2018 | The Symantec ProxySG 6.5 (prior to 6.5.10.6), 6.6, and 6.7 (prior to 6.7.2.1) management console is susceptible to a ref... |
| CVE-2016-3695 | — | — | 0.5% | Dec 29, 2017 | The einj_error_inject function in drivers/acpi/apei/einj.c in the Linux kernel allows local users to simulate hardware e... |
| CVE-2016-6904 | — | — | 1.2% | Dec 11, 2017 | Versions of VASA Provider for Clustered Data ONTAP prior to 7.0P1 contain a web server that accepts plain text authentic... |
| CVE-2016-5713 | — | — | 2.0% | Dec 6, 2017 | Versions of Puppet Agent prior to 1.6.0 included a version of the Puppet Execution Protocol (PXP) agent that passed envi... |
| CVE-2016-1255 | — | — | 0.4% | Dec 5, 2017 | The pg_ctlcluster script in postgresql-common package in Debian wheezy before 134wheezy5, in Debian jessie before 165+de... |
| CVE-2016-1254 | — | — | 3.0% | Dec 5, 2017 | Tor before 0.2.8.12 might allow remote attackers to cause a denial of service (client crash) via a crafted hidden servic... |
| CVE-2016-1253 | — | — | 4.8% | Dec 5, 2017 | The most package in Debian wheezy before 5.0.0a-2.2, in Debian jessie before 5.0.0a-2.3+deb8u1, and in Debian unstable b... |
| CVE-2016-10702 | — | — | 0.7% | Nov 28, 2017 | Pebble Smartwatch devices through 4.3 mishandle UUID storage, which allows attackers to read an arbitrary application's ... |
| CVE-2016-10701 | — | — | 0.8% | Nov 28, 2017 | In Hitachi Vantara Pentaho BA Platform through 8.0, a CSRF issue exists in the Business Analytics application. |
| CVE-2016-6024 | — | — | 0.7% | Nov 27, 2017 | IBM Jazz technology based products might divulge information that might be useful in helping attackers through error mes... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now