2016 CVE Vulnerabilities

10,647 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-3675HIGH8.1SQL injection vulnerability in Huawei Policy Center with software before V100R003C10SPC020 allows remote authenticated u...
CVE-2016-3659SQL injection vulnerability in graph_view.php in Cacti 0.8.8.g allows remote authenticated users to execute arbitrary SQ...
CVE-2016-3065The (1) brin_page_type and (2) brin_metapage_info functions in the pageinspect extension in PostgreSQL before 9.5.x befo...
CVE-2016-2385Heap-based buffer overflow in the encode_msg function in encode_msg.c in the SEAS module in Kamailio (formerly OpenSER a...
CVE-2016-2193PostgreSQL before 9.5.x before 9.5.2 does not properly maintain row-security status in cached plans, which might allow a...
CVE-2016-1235The oarsh script in OAR before 2.5.7 allows remote authenticated users of a cluster to obtain sensitive information and ...
CVE-2016-2393Lenovo Fingerprint Manager before 8.01.57 and Touch Fingerprint before 1.00.08 use weak ACLs for unspecified (1) service...
CVE-2016-2171The User Manager service in Apache Jetspeed before 2.3.1 does not properly restrict access using Jetspeed Security, whic...
CVE-2016-2164The (1) FileService.importFileByInternalUserId and (2) FileService.importFile SOAP API methods in Apache OpenMeetings be...
CVE-2016-2163Cross-site scripting (XSS) vulnerability in Apache OpenMeetings before 3.1.1 allows remote attackers to inject arbitrary...
CVE-2016-0784Directory traversal vulnerability in the Import/Export System Backups functionality in Apache OpenMeetings before 3.1.1 ...
CVE-2016-0783The sendHashByUser function in Apache OpenMeetings before 3.1.1 generates predictable password reset tokens, which makes...
CVE-2016-0712Cross-site scripting (XSS) vulnerability in Apache Jetspeed before 2.3.1 allows remote attackers to inject arbitrary web...
CVE-2016-0711Multiple cross-site scripting (XSS) vulnerabilities in Apache Jetspeed before 2.3.1 allow remote attackers to inject arb...
CVE-2016-0710Multiple SQL injection vulnerabilities in the User Manager service in Apache Jetspeed before 2.3.1 allow remote attacker...
CVE-2016-0709Directory traversal vulnerability in the Import/Export function in the Portal Site Manager in Apache Jetspeed before 2.3...
CVE-2016-1033HIGH8.8Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616...
CVE-2016-1032HIGH8.8Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616...
CVE-2016-1031HIGH8.8Use-after-free vulnerability in Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows ...
CVE-2016-1030HIGH8.1Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616...
CVE-2016-1029HIGH8.8Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616...
CVE-2016-1028HIGH8.8Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616...
CVE-2016-1027HIGH8.8Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616...
CVE-2016-1026HIGH8.8Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616...
CVE-2016-1025HIGH8.8Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now