2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-10700 | — | — | 2.5% | Nov 24, 2017 | auth_login.php in Cacti before 1.0.0 allows remote authenticated users who use web authentication to bypass intended acc... |
| CVE-2016-8234 | — | — | — | Nov 13, 2017 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was... |
| CVE-2016-6803 | — | — | 2.1% | Nov 13, 2017 | An installer defect known as an "unquoted Windows search path vulnerability" affected the Apache OpenOffice before 4.1.3... |
| CVE-2016-0872 | — | — | 1.2% | Nov 7, 2017 | A Plaintext Storage of a Password issue was discovered in Kabona AB WebDatorCentral (WDC) versions prior to Version 3.4.... |
| CVE-2016-3048 | — | — | 0.7% | Nov 1, 2017 | IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to e... |
| CVE-2016-0759 | — | — | — | Oct 31, 2017 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-4003. Reason: This candidate is a reservation ... |
| CVE-2016-10699 | — | — | 1.4% | Oct 31, 2017 | D-Link DSL-2740E 1.00_BG_20150720 devices are prone to persistent XSS attacks in the username and password fields: a rem... |
| CVE-2016-3090 | — | — | 6.1% | Oct 30, 2017 | The TextParseUtil.translateVariables method in Apache Struts 2.x before 2.3.20 allows remote attackers to execute arbitr... |
| CVE-2016-5003 | — | — | 14.9% | Oct 27, 2017 | The Apache XML-RPC (aka ws-xmlrpc) library 3.1.3, as used in Apache Archiva, allows remote attackers to execute arbitrar... |
| CVE-2016-5002 | — | — | 8.3% | Oct 27, 2017 | XML external entity (XXE) vulnerability in the Apache XML-RPC (aka ws-xmlrpc) library 3.1.3, as used in Apache Archiva, ... |
| CVE-2016-3049 | — | — | 0.9% | Oct 24, 2017 | IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 is vulnerable to HTML injection. A remote attacker could inject malicious H... |
| CVE-2016-10517 | — | — | 2.1% | Oct 24, 2017 | networking.c in Redis before 3.2.7 allows "Cross Protocol Scripting" because it lacks a check for POST and Host: strings... |
| CVE-2016-10516 | — | — | 2.0% | Oct 23, 2017 | Cross-site scripting (XSS) vulnerability in the render_full function in debug/tbtools.py in the debugger in Pallets Werk... |
| CVE-2016-8748 | — | — | 1.8% | Oct 19, 2017 | In Apache NiFi before 1.0.1 and 1.1.x before 1.1.1, there is a cross-site scripting vulnerability in connection details ... |
| CVE-2016-10515 | — | — | 0.7% | Oct 18, 2017 | In Redmine before 3.2.3, there are stored XSS vulnerabilities affecting Textile and Markdown text formatting, and projec... |
| CVE-2016-4461 | — | — | 8.3% | Oct 16, 2017 | Apache Struts 2.x before 2.3.29 allows remote attackers to execute arbitrary code via a "%{}" sequence in a tag attribut... |
| CVE-2016-8734 | — | — | 6.4% | Oct 16, 2017 | Apache Subversion's mod_dontdothat module and HTTP clients 1.4.0 through 1.8.16, and 1.9.0 through 1.9.4 are vulnerable ... |
| CVE-2016-6815 | — | — | 2.1% | Oct 13, 2017 | In Apache Ranger before 0.6.2, users with "keyadmin" role should not be allowed to change password for users with "admin... |
| CVE-2016-5791 | — | — | 2.4% | Oct 13, 2017 | An Improper Authentication issue was discovered in JanTek JTC-200, all versions. The improper authentication could provi... |
| CVE-2016-5789 | — | — | 0.4% | Oct 13, 2017 | A Cross-site Request Forgery issue was discovered in JanTek JTC-200, all versions. An attacker could perform actions wit... |
| CVE-2016-8736 | — | — | 4.8% | Oct 12, 2017 | Apache OpenMeetings before 3.1.2 is vulnerable to Remote Code Execution via RMI deserialization attack. |
| CVE-2016-9263 | — | — | 2.6% | Oct 12, 2017 | WordPress through 4.8.2, when domain-based flashmediaelement.swf sandboxing is not used, allows remote attackers to cond... |
| CVE-2016-10514 | — | — | 1.2% | Oct 10, 2017 | url_check_format in include/functions.inc.php in Piwigo before 2.8.3 allows remote attackers to bypass intended access r... |
| CVE-2016-10513 | — | — | 0.9% | Oct 10, 2017 | Cross Site Scripting (XSS) exists in Piwigo before 2.8.3 via a crafted search expression to include/functions_search.inc... |
| CVE-2016-8937 | — | — | 1.9% | Oct 5, 2017 | The IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) default authentication protocol is vulnerable to a bru... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now