2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-7812 | — | — | 0.8% | Aug 2, 2017 | The Bank of Tokyo-Mitsubishi UFJ, Ltd. App for Android ver5.3.1, ver5.2.2 and earlier allow a man-in-the-middle attacker... |
| CVE-2016-9719 | — | — | 1.2% | Jul 31, 2017 | IBM InfoSphere Master Data Management Server 10.1. 11.0. 11.3, 11.4, 11.5, and 11.6 could allow a remote attacker to hij... |
| CVE-2016-9718 | — | — | 0.7% | Jul 31, 2017 | IBM InfoSphere Master Data Management Server 10.1. 11.0. 11.3, 11.4, 11.5, and 11.6 is vulnerable to cross-site scriptin... |
| CVE-2016-9717 | — | — | 1.1% | Jul 31, 2017 | HTTP Parameter Override is identified in the IBM Infosphere Master Data Management (MDM) 10.1. 11.0. 11.3, 11.4, 11.5, a... |
| CVE-2016-9716 | — | — | 0.7% | Jul 31, 2017 | IBM InfoSphere Master Data Management Server 11.0, 11.3, 11.4, 11.5, and 11.6 is vulnerable to cross-site request forger... |
| CVE-2016-9715 | — | — | 0.7% | Jul 31, 2017 | IBM InfoSphere Master Data Management Server 11.0, 11.3, 11.4, 11.5, and 11.6 is vulnerable to cross-site scripting. Thi... |
| CVE-2016-9714 | — | — | 0.6% | Jul 31, 2017 | IBM InfoSphere Master Data Management Server 10.1, 11.0, 11.3, 11.4, 11.5, and 11.6 is vulnerable to cross-site request ... |
| CVE-2016-2161 | — | — | 21.0% | Jul 27, 2017 | In Apache HTTP Server versions 2.4.0 to 2.4.23, malicious input to mod_auth_digest can cause the server to crash, and ea... |
| CVE-2016-0736 | — | — | 49.0% | Jul 27, 2017 | In Apache HTTP Server versions 2.4.0 to 2.4.23, mod_session_crypto was encrypting its data/cookie using the configured c... |
| CVE-2016-10399 | — | — | 1.4% | Jul 27, 2017 | Sendio versions before 8.2.1 were affected by a Local File Inclusion vulnerability that allowed an unauthenticated, remo... |
| CVE-2016-6133 | — | — | 0.8% | Jul 25, 2017 | Cross-site scripting (XSS) vulnerability in Ektron Content Management System before 9.1.0.184SP3(9.1.0.184.3.127) allows... |
| CVE-2016-10401 | — | — | 12.3% | Jul 25, 2017 | ZyXEL PK5001Z devices have zyad5001 as the su password, which makes it easier for remote attackers to obtain root access... |
| CVE-2016-7539 | — | — | 4.9% | Jul 25, 2017 | Memory leak in AcquireVirtualMemory in ImageMagick before 7 allows remote attackers to cause a denial of service (memory... |
| CVE-2016-8975 | — | — | 0.7% | Jul 24, 2017 | IBM Rhapsody DM 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Ja... |
| CVE-2016-6118 | — | — | 0.7% | Jul 24, 2017 | IBM Emptoris Supplier Lifecycle Management 10.1.0.x is vulnerable to cross-site scripting. This vulnerability allows use... |
| CVE-2016-10400 | — | — | 1.9% | Jul 22, 2017 | Directory Traversal exists in ATutor before 2.2.2 via the icon parameter to /mods/_core/courses/users/create_course.php.... |
| CVE-2016-7059 | — | — | — | Jul 21, 2017 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was... |
| CVE-2016-7058 | — | — | — | Jul 21, 2017 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was... |
| CVE-2016-7057 | — | — | — | Jul 21, 2017 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was... |
| CVE-2016-6018 | — | — | 1.0% | Jul 19, 2017 | IBM Emptoris Contract Management 10.0 and 10.1 reveals detailed error messages in certain features that could cause an a... |
| CVE-2016-6798 | — | — | 3.7% | Jul 19, 2017 | In the XSS Protection API module before 1.0.12 in Apache Sling, the method XSS.getValidXML() uses an insecure SAX parser... |
| CVE-2016-7509 | — | — | 0.6% | Jul 19, 2017 | Cross-site scripting (XSS) vulnerability in GLPI 0.90.4 allows remote authenticated attackers to inject arbitrary web sc... |
| CVE-2016-7507 | — | — | 0.5% | Jul 19, 2017 | Cross-Site Request Forgery (CSRF) vulnerability in GLPI 0.90.4 allows remote authenticated attackers to submit a request... |
| CVE-2016-6793 | — | — | 8.5% | Jul 17, 2017 | The DiskFileItem class in Apache Wicket 6.x before 6.25.0 and 1.5.x before 1.5.17 allows remote attackers to cause a den... |
| CVE-2016-6312 | — | — | 2.2% | Jul 17, 2017 | The mod_dontdothat component of the mod_dav_svn Apache module in Subversion as packaged in Red Hat Enterprise Linux 5.11... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now