2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-2245 | — | — | 5.9% | Mar 19, 2016 | HP Support Assistant before 8.1.52.1 allows remote attackers to bypass authentication via unspecified vectors. |
| CVE-2016-0283 | — | — | 1.4% | Mar 19, 2016 | Cross-site scripting (XSS) vulnerability in the OpenID Connect (OIDC) client web application in IBM WebSphere Applicatio... |
| CVE-2016-2287 | — | — | 0.9% | Mar 19, 2016 | Cross-site scripting (XSS) vulnerability in XZERES 442SR OS on 442SR wind turbines allows remote attackers to inject arb... |
| CVE-2016-3155 | — | — | 0.3% | Mar 18, 2016 | Siemens APOGEE Insight uses weak permissions for the application folder, which allows local users to obtain sensitive in... |
| CVE-2016-2281 | — | — | 0.3% | Mar 18, 2016 | Untrusted search path vulnerability in ABB Panel Builder 800 5.1 allows local users to gain privileges via a Trojan hors... |
| CVE-2016-1996 | — | — | 0.5% | Mar 18, 2016 | HPE System Management Homepage before 7.5.4 allows local users to obtain sensitive information or modify data via unspec... |
| CVE-2016-1995 | — | — | 10.2% | Mar 18, 2016 | HPE System Management Homepage before 7.5.4 allows remote attackers to execute arbitrary code via unspecified vectors. |
| CVE-2016-1994 | — | — | 1.9% | Mar 18, 2016 | HPE System Management Homepage before 7.5.4 allows remote authenticated users to obtain sensitive information via unspec... |
| CVE-2016-1993 | — | — | 2.0% | Mar 18, 2016 | HPE System Management Homepage before 7.5.4 allows remote authenticated users to obtain sensitive information or modify ... |
| CVE-2016-3191 | — | — | 8.4% | Mar 17, 2016 | The compile_branch function in pcre_compile.c in PCRE 8.x before 8.39 and pcre2_compile.c in PCRE2 before 10.22 mishandl... |
| CVE-2016-2345 | — | — | 51.2% | Mar 17, 2016 | Stack-based buffer overflow in dwrcs.exe in the dwmrcs daemon in SolarWinds DameWare Mini Remote Control 12.0 allows rem... |
| CVE-2016-2342 | — | — | 12.1% | Mar 17, 2016 | The bgp_nlri_parse_vpnv4 function in bgp_mplsvpn.c in the VPNv4 NLRI parser in bgpd in Quagga before 1.0.20160309, when ... |
| CVE-2016-1992 | — | — | 1.8% | Mar 17, 2016 | HPE ArcSight ESM before 6.8c, and ArcSight ESM Express before 6.9.1, allows remote authenticated users to obtain sensiti... |
| CVE-2016-2846 | — | — | 1.7% | Mar 16, 2016 | Siemens SIMATIC S7-1200 CPU devices before 4.0 allow remote attackers to bypass a "user program block" protection mechan... |
| CVE-2016-2075 | MEDIUM | 5.4 | 0.8% | Mar 16, 2016 | Cross-site scripting (XSS) vulnerability in VMware vRealize Business Advanced and Enterprise 8.x before 8.2.5 on Linux a... |
| CVE-2016-1991 | — | — | 1.6% | Mar 16, 2016 | HPE ArcSight ESM 5.x before 5.6, 6.0, 6.5.x before 6.5C SP1 Patch 2, and 6.8c before P1, and ArcSight ESM Express before... |
| CVE-2016-1990 | — | — | 0.4% | Mar 16, 2016 | HPE ArcSight ESM 5.x before 5.6, 6.0, 6.5.x before 6.5C SP1 Patch 2, and 6.8c before P1, and ArcSight ESM Express before... |
| CVE-2016-1989 | — | — | 10.6% | Mar 15, 2016 | HPE Network Automation 9.22 through 9.22.02 and 10.x before 10.00.02 allows remote attackers to execute arbitrary code o... |
| CVE-2016-1988 | — | — | 10.6% | Mar 15, 2016 | HPE Network Automation 9.22 through 9.22.02 and 10.x before 10.00.02 allows remote attackers to execute arbitrary code o... |
| CVE-2016-2856 | — | — | 1.1% | Mar 14, 2016 | pt_chown in the glibc package before 2.19-18+deb8u4 on Debian jessie; the elibc package before 2.15-0ubuntu10.14 on Ubun... |
| CVE-2016-1731 | — | — | 0.9% | Mar 14, 2016 | Apple Software Update before 2.2 on Windows does not use HTTPS, which makes it easier for man-in-the-middle attackers to... |
| CVE-2016-0262 | — | — | 0.6% | Mar 14, 2016 | Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.1.1 through 7.1.1.3, 7.5.0 before 7.5.0.9 IFIX... |
| CVE-2016-0222 | — | — | 0.8% | Mar 14, 2016 | IBM Maximo Asset Management 7.6 before 7.6.0.3 IFIX001 allows remote authenticated users to bypass intended access restr... |
| CVE-2016-0208 | — | — | 1.3% | Mar 14, 2016 | IBM WebSphere Commerce 6.x through 6.0.0.11, 7.x through 7.0.0.9, and 8.x before 8.0.0.3 allows remote attackers to caus... |
| CVE-2016-1645 | HIGH | 8.8 | 2.0% | Mar 13, 2016 | Multiple integer signedness errors in the opj_j2k_update_image_data function in j2k.c in OpenJPEG, as used in PDFium in ... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now