2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-3188 | — | — | 1.9% | Apr 8, 2016 | The _prepopulate_request_walk function in the Prepopulate module 7.x-2.x before 7.x-2.1 for Drupal allows remote attacke... |
| CVE-2016-3187 | — | — | 1.9% | Apr 8, 2016 | The Prepopulate module 7.x-2.x before 7.x-2.1 for Drupal allows remote attackers to modify the REQUEST superglobal array... |
| CVE-2016-3154 | — | — | 1.8% | Apr 8, 2016 | The encoder_contexte_ajax function in ecrire/inc/filtres.php in SPIP 2.x before 2.1.19, 3.0.x before 3.0.22, and 3.1.x b... |
| CVE-2016-3153 | — | — | 1.8% | Apr 8, 2016 | SPIP 2.x before 2.1.19, 3.0.x before 3.0.22, and 3.1.x before 3.1.1 allows remote attackers to execute arbitrary PHP cod... |
| CVE-2016-2324 | CRITICAL | 9.8 | 18.8% | Apr 8, 2016 | Integer overflow in Git before 2.7.4 allows remote attackers to execute arbitrary code via a (1) long filename or (2) ma... |
| CVE-2016-2315 | CRITICAL | 9.8 | 18.0% | Apr 8, 2016 | revision.c in git before 2.7.4 uses an incorrect integer data type, which allows remote attackers to execute arbitrary c... |
| CVE-2016-3976 | HIGH | 7.5 | 46.6% | Apr 7, 2016 | Directory traversal vulnerability in SAP NetWeaver AS Java 7.1 through 7.5 allows remote attackers to read arbitrary fil... |
| CVE-2016-2851 | — | — | 25.4% | Apr 7, 2016 | Integer overflow in proto.c in libotr before 4.1.1 on 64-bit platforms allows remote attackers to cause a denial of serv... |
| CVE-2016-2789 | — | — | 0.8% | Apr 7, 2016 | Cross-site scripting (XSS) vulnerability in the Web User Interface in Citrix XenMobile Server 10.0, 10.1 before Rolling ... |
| CVE-2016-2563 | — | — | 34.2% | Apr 7, 2016 | Stack-based buffer overflow in the SCP command-line utility in PuTTY before 0.67 and KiTTY 0.66.6.3 and earlier allows r... |
| CVE-2016-2098 | — | — | 81.4% | Apr 7, 2016 | Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to e... |
| CVE-2016-2097 | — | — | 4.4% | Apr 7, 2016 | Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.2 and 4.x before 4.1.14.2 allows remote ... |
| CVE-2016-1531 | — | — | 5.9% | Apr 7, 2016 | Exim before 4.86.2, when installed setuid root, allows local users to gain privileges via the perl_startup argument. |
| CVE-2016-0792 | — | — | 82.7% | Apr 7, 2016 | Multiple unspecified API endpoints in Jenkins before 1.650 and LTS before 1.642.2 allow remote authenticated users to ex... |
| CVE-2016-0791 | — | — | 2.7% | Apr 7, 2016 | Jenkins before 1.650 and LTS before 1.642.2 do not use a constant-time algorithm to verify CSRF tokens, which makes it e... |
| CVE-2016-0790 | — | — | 2.1% | Apr 7, 2016 | Jenkins before 1.650 and LTS before 1.642.2 do not use a constant-time algorithm to verify API tokens, which makes it ea... |
| CVE-2016-0789 | — | — | 1.8% | Apr 7, 2016 | CRLF injection vulnerability in the CLI command documentation in Jenkins before 1.650 and LTS before 1.642.2 allows remo... |
| CVE-2016-0788 | — | — | 11.8% | Apr 7, 2016 | The remoting module in Jenkins before 1.650 and LTS before 1.642.2 allows remote attackers to execute arbitrary code by ... |
| CVE-2016-2511 | — | — | 1.7% | Apr 7, 2016 | Cross-site scripting (XSS) vulnerability in WebSVN 2.3.3 and earlier allows remote attackers to inject arbitrary web scr... |
| CVE-2016-2216 | — | — | 7.0% | Apr 7, 2016 | The HTTP header parsing code in Node.js 0.10.x before 0.10.42, 0.11.6 through 0.11.16, 0.12.x before 0.12.10, 4.x before... |
| CVE-2016-2086 | — | — | 6.3% | Apr 7, 2016 | Node.js 0.10.x before 0.10.42, 0.12.x before 0.12.10, 4.x before 4.3.0, and 5.x before 5.6.0 allow remote attackers to c... |
| CVE-2016-0729 | — | — | 8.9% | Apr 7, 2016 | Multiple buffer overflows in (1) internal/XMLReader.cpp, (2) util/XMLURL.cpp, and (3) util/XMLUri.cpp in the XML Parser ... |
| CVE-2016-2510 | HIGH | 8.1 | 70.4% | Apr 7, 2016 | BeanShell (bsh) before 2.0b6, when included on the classpath by an application that uses Java serialization or XStream, ... |
| CVE-2016-3975 | MEDIUM | 6.1 | 1.6% | Apr 7, 2016 | Cross-site scripting (XSS) vulnerability in SAP NetWeaver AS Java 7.1 through 7.5 allows remote attackers to inject arbi... |
| CVE-2016-3974 | CRITICAL | 9.1 | 15.1% | Apr 7, 2016 | XML external entity (XXE) vulnerability in the Configuration Wizard in SAP NetWeaver Java AS 7.1 through 7.5 allows remo... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now