2016 CVE Vulnerabilities

10,647 CVEs published in 2016.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2016-10372The Eir D1000 modem does not properly restrict the TR-064 protocol, which allows remote attackers to execute arbitrary c...
CVE-2016-10242A time-of-check time-of-use race condition could potentially exist in the secure file system in all Android releases fro...
CVE-2016-10239In TrustZone access control policy may potentially be bypassed in all Android releases from CAF using the Linux kernel d...
CVE-2016-10238In QSEE in all Android releases from CAF using the Linux kernel access control may potentially be bypassed due to a page...
CVE-2016-10237If shared content protection memory were passed as the secure camera memory buffer by the HLOS to a trusted application ...
CVE-2016-9750IBM QRadar 7.2 and 7.3 stores user credentials in plain in clear text which can be read by an authenticated user. IBM X-...
CVE-2016-9735IBM Jazz Foundation could allow an authenticated user to obtain sensitive information from stack traces. IBM X-Force ID:...
CVE-2016-5979IBM Distributed Marketing 8.6, 9.0, and 10.0 could allow a privileged authenticated user to create an instance that gets...
CVE-2016-10331Directory traversal vulnerability in download.php in Synology Photo Station before 6.5.3-3226 allows remote attackers to...
CVE-2016-10330Directory traversal vulnerability in synophoto_dsm_user, a SUID program, as used in Synology Photo Station before 6.5.3-...
CVE-2016-10329Command injection vulnerability in login.php in Synology Photo Station before 6.5.3-3226 allows remote attackers to exec...
CVE-2016-4887Cross-site request forgery (CSRF) vulnerability in baserCMS plugin Uploader version 3.0.10 and earlier allows remote att...
CVE-2016-4886Cross-site request forgery (CSRF) vulnerability in baserCMS plugin Mail version 3.0.10 and earlier allows remote attacke...
CVE-2016-4885Cross-site request forgery (CSRF) vulnerability in baserCMS plugin Feed version 3.0.10 and earlier allows remote attacke...
CVE-2016-4884Cross-site request forgery (CSRF) vulnerability in baserCMS plugin Blog version 3.0.10 and earlier allows remote attacke...
CVE-2016-4883Cross-site scripting vulnerability in baserCMS version 3.0.10 and earlier allows remote attackers to inject arbitrary we...
CVE-2016-4882Cross-site request forgery (CSRF) vulnerability in baserCMS version 3.0.10 and earlier allows remote attackers to hijack...
CVE-2016-4881Cross-site request forgery (CSRF) vulnerability in baserCMS plugin Blog version 3.0.10 and earlier allows remote attacke...
CVE-2016-4880Cross-site scripting vulnerability in baserCMS plugin Blog version 3.0.10 and earlier allows remote authenticated attack...
CVE-2016-4878Cross-site request forgery (CSRF) vulnerability in baserCMS version 3.0.10 and earlier allows remote attackers to hijack...
CVE-2016-4876Cross-site request forgery (CSRF) vulnerability in baserCMS version 3.0.10 and earlier allows remote attackers to hijack...
CVE-2016-4864H2O versions 2.0.3 and earlier and 2.1.0-beta2 and earlier allows remote attackers to cause a denial-of-service (DoS) vi...
CVE-2016-4859Open redirect vulnerability in Splunk Enterprise 6.4.x prior to 6.4.3, Splunk Enterprise 6.3.x prior to 6.3.6, Splunk En...
CVE-2016-4858Cross-site scripting vulnerability in Splunk Enterprise 6.4.x prior to 6.4.2, Splunk Enterprise 6.3.x prior to 6.3.6, Sp...
CVE-2016-4857Open redirect vulnerability in Splunk Enterprise 6.4.x prior to 6.4.2, Splunk Enterprise 6.3.x prior to 6.3.6, Splunk En...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now