2016 CVE Vulnerabilities

10,647 CVEs published in 2016.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2016-10700auth_login.php in Cacti before 1.0.0 allows remote authenticated users who use web authentication to bypass intended acc...
CVE-2016-8234Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was...
CVE-2016-6803An installer defect known as an "unquoted Windows search path vulnerability" affected the Apache OpenOffice before 4.1.3...
CVE-2016-0872A Plaintext Storage of a Password issue was discovered in Kabona AB WebDatorCentral (WDC) versions prior to Version 3.4....
CVE-2016-3048IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to e...
CVE-2016-0759Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-4003. Reason: This candidate is a reservation ...
CVE-2016-10699D-Link DSL-2740E 1.00_BG_20150720 devices are prone to persistent XSS attacks in the username and password fields: a rem...
CVE-2016-3090The TextParseUtil.translateVariables method in Apache Struts 2.x before 2.3.20 allows remote attackers to execute arbitr...
CVE-2016-5003The Apache XML-RPC (aka ws-xmlrpc) library 3.1.3, as used in Apache Archiva, allows remote attackers to execute arbitrar...
CVE-2016-5002XML external entity (XXE) vulnerability in the Apache XML-RPC (aka ws-xmlrpc) library 3.1.3, as used in Apache Archiva, ...
CVE-2016-3049IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 is vulnerable to HTML injection. A remote attacker could inject malicious H...
CVE-2016-10517networking.c in Redis before 3.2.7 allows "Cross Protocol Scripting" because it lacks a check for POST and Host: strings...
CVE-2016-10516Cross-site scripting (XSS) vulnerability in the render_full function in debug/tbtools.py in the debugger in Pallets Werk...
CVE-2016-8748In Apache NiFi before 1.0.1 and 1.1.x before 1.1.1, there is a cross-site scripting vulnerability in connection details ...
CVE-2016-10515In Redmine before 3.2.3, there are stored XSS vulnerabilities affecting Textile and Markdown text formatting, and projec...
CVE-2016-4461Apache Struts 2.x before 2.3.29 allows remote attackers to execute arbitrary code via a "%{}" sequence in a tag attribut...
CVE-2016-8734Apache Subversion's mod_dontdothat module and HTTP clients 1.4.0 through 1.8.16, and 1.9.0 through 1.9.4 are vulnerable ...
CVE-2016-6815In Apache Ranger before 0.6.2, users with "keyadmin" role should not be allowed to change password for users with "admin...
CVE-2016-5791An Improper Authentication issue was discovered in JanTek JTC-200, all versions. The improper authentication could provi...
CVE-2016-5789A Cross-site Request Forgery issue was discovered in JanTek JTC-200, all versions. An attacker could perform actions wit...
CVE-2016-8736Apache OpenMeetings before 3.1.2 is vulnerable to Remote Code Execution via RMI deserialization attack.
CVE-2016-9263WordPress through 4.8.2, when domain-based flashmediaelement.swf sandboxing is not used, allows remote attackers to cond...
CVE-2016-10514url_check_format in include/functions.inc.php in Piwigo before 2.8.3 allows remote attackers to bypass intended access r...
CVE-2016-10513Cross Site Scripting (XSS) exists in Piwigo before 2.8.3 via a crafted search expression to include/functions_search.inc...
CVE-2016-8937The IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) default authentication protocol is vulnerable to a bru...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now