2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-0147 | — | — | 15.7% | Apr 12, 2016 | Microsoft XML Core Services 3.0 allows remote attackers to execute arbitrary code via a crafted web site, aka "MSXML 3.0... |
| CVE-2016-0145 | — | — | 43.3% | Apr 12, 2016 | The font library in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows... |
| CVE-2016-0143 | — | — | 3.6% | Apr 12, 2016 | The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, W... |
| CVE-2016-0139 | — | — | 16.3% | Apr 12, 2016 | Microsoft Excel 2010 SP2, Word for Mac 2011, and Excel Viewer allow remote attackers to execute arbitrary code via a cra... |
| CVE-2016-0136 | — | — | 20.7% | Apr 12, 2016 | Microsoft Excel 2007 SP3, Excel 2010 SP2, Office Compatibility Pack SP3, Excel Services on SharePoint Server 2007 SP3, a... |
| CVE-2016-0135 | — | — | 1.6% | Apr 12, 2016 | The Secondary Logon Service in Microsoft Windows 10 Gold and 1511 allows local users to gain privileges via a crafted ap... |
| CVE-2016-0128 | MEDIUM | 6.8 | 20.9% | Apr 12, 2016 | The SAM and LSAD protocol implementations in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 ... |
| CVE-2016-0127 | — | — | 21.1% | Apr 12, 2016 | Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Office Compatibility Pack SP3,... |
| CVE-2016-0122 | — | — | 41.1% | Apr 12, 2016 | Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Word 2016 for Mac, Office Compa... |
| CVE-2016-0090 | — | — | 3.0% | Apr 12, 2016 | Hyper-V in Microsoft Windows 8.1, Windows Server 2012 R2, and Windows 10 allows guest OS users to obtain sensitive infor... |
| CVE-2016-0089 | — | — | 3.4% | Apr 12, 2016 | Hyper-V in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, and Windows 10 allows guest OS users to obtain sensit... |
| CVE-2016-0088 | — | — | 7.5% | Apr 12, 2016 | Hyper-V in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, and Windows 10 allows guest OS users to execute arbit... |
| CVE-2016-4004 | — | — | 8.9% | Apr 12, 2016 | Directory traversal vulnerability in Dell OpenManage Server Administrator (OMSA) 8.2 allows remote authenticated adminis... |
| CVE-2016-3657 | — | — | 4.8% | Apr 12, 2016 | Buffer overflow in the GlobalProtect Portal in Palo Alto Networks PAN-OS before 5.0.18, 6.0.x before 6.0.13, 6.1.x befor... |
| CVE-2016-3656 | — | — | 1.8% | Apr 12, 2016 | The GlobalProtect Portal in Palo Alto Networks PAN-OS before 5.0.18, 6.0.x before 6.0.13, 6.1.x before 6.1.10, and 7.0.x... |
| CVE-2016-3655 | — | — | 3.2% | Apr 12, 2016 | The management web interface in Palo Alto Networks PAN-OS before 5.0.18, 6.0.x before 6.0.13, 6.1.x before 6.1.10, and 7... |
| CVE-2016-3654 | — | — | 2.6% | Apr 12, 2016 | The device management command line interface (CLI) in Palo Alto Networks PAN-OS before 5.0.18, 5.1.x before 5.1.11, 6.0.... |
| CVE-2016-2405 | — | — | 1.8% | Apr 12, 2016 | Huawei Policy Center with software before V100R003C10SPC020 allows remote authenticated users to gain privileges and cau... |
| CVE-2016-4003 | — | — | 12.0% | Apr 12, 2016 | Cross-site scripting (XSS) vulnerability in the URLDecoder function in JRE before 1.8, as used in Apache Struts 2.x befo... |
| CVE-2016-3172 | — | — | 2.8% | Apr 12, 2016 | SQL injection vulnerability in tree.php in Cacti 0.8.8g and earlier allows remote authenticated users to execute arbitra... |
| CVE-2016-3157 | — | — | 0.5% | Apr 12, 2016 | The __switch_to function in arch/x86/kernel/process_64.c in the Linux kernel does not properly context-switch IOPL on 64... |
| CVE-2016-2162 | — | — | 9.2% | Apr 12, 2016 | Apache Struts 2.x before 2.3.25 does not sanitize text in the Locale object constructed by I18NInterceptor, which might ... |
| CVE-2016-0785 | — | — | 8.8% | Apr 12, 2016 | Apache Struts 2.x before 2.3.28 allows remote attackers to execute arbitrary code via a "%{}" sequence in a tag attribut... |
| CVE-2016-3171 | — | — | 3.2% | Apr 12, 2016 | Drupal 6.x before 6.38, when used with PHP before 5.4.45, 5.5.x before 5.5.29, or 5.6.x before 5.6.13, might allow remot... |
| CVE-2016-3170 | — | — | 2.1% | Apr 12, 2016 | The "have you forgotten your password" links in the User module in Drupal 7.x before 7.43 and 8.x before 8.0.4 allow rem... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now