2016 CVE Vulnerabilities

10,648 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-8514——A remote information disclosure in HPE Version Control Repository Manager (VCRM) was found. The problem impacts all vers...
CVE-2016-8513——A Cross-Site Request Forgery (CSRF) vulnerability in HPE Version Control Repository Manager (VCRM) was found. The proble...
CVE-2016-8512——A Remote Code Execution vulnerability in all versions of HPE LoadRunner and Performance Center was found.
CVE-2016-8511——A Remote Code Execution vulnerability in HPE Network Automation using RPCServlet and Java Deserialization version v9.1x,...
CVE-2016-10713——An issue was discovered in GNU patch before 2.7.6. Out-of-bounds access within pch_write_line() in pch.c can possibly le...
CVE-2016-9570——cb.exe in Carbon Black 5.1.1.60603 allows attackers to cause a denial of service (out-of-bounds read, invalid pointer de...
CVE-2016-9569——The cbstream.sys driver in Carbon Black 5.1.1.60603 allows local users with admin privileges to cause a denial of servic...
CVE-2016-8742——The Windows installer that the Apache CouchDB team provides was vulnerable to local privilege escalation. All files in t...
CVE-2016-5397——The Apache Thrift Go client library exposed the potential during code generation for command injection due to using an e...
CVE-2016-10712——In PHP before 5.5.32, 5.6.x before 5.6.18, and 7.x before 7.0.3, all of the return values of stream_get_meta_data can be...
CVE-2016-6169——Heap-based buffer overflow in Foxit Reader and PhantomPDF 7.3.4.311 and earlier on Windows allows remote attackers to ca...
CVE-2016-6168——Use-after-free vulnerability in Foxit Reader and PhantomPDF 7.3.4.311 and earlier on Windows allows remote attackers to ...
CVE-2016-2541——Audacity before 2.1.2 allows remote attackers to cause a denial of service (memory corruption and application crash) via...
CVE-2016-2540——Audacity before 2.1.2 allows remote attackers to cause a denial of service (memory corruption and application crash) via...
CVE-2016-3957——The secure_load function in gluon/utils.py in web2py before 2.14.2 uses pickle.loads to deserialize session information ...
CVE-2016-3954——web2py before 2.14.2 allows remote attackers to obtain the session_cookie_key value via a direct request to examples/sim...
CVE-2016-3953——The sample web application in web2py before 2.14.2 might allow remote attackers to execute arbitrary code via vectors in...
CVE-2016-3952——web2py before 2.14.1, when using the standalone version, allows remote attackers to obtain environment variable values v...
CVE-2016-7394——tiki wiki cms groupware <=15.2 has a xss vulnerability, allow attackers steal user's cookie.
CVE-2016-6813CRITICAL9.8Apache CloudStack 4.1 to 4.8.1.0 and 4.9.0.0 contain an API call designed to allow a user to register for the developer ...
CVE-2016-0342——IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.3, and 3.5 before 3.5.0.1 allows remote authentica...
CVE-2016-0329——Open redirect vulnerability in IBM Emptoris Sourcing 10.0.0.x before 10.0.0.1_iFix3, 10.0.1.x before 10.0.1.3_iFix3, 10....
CVE-2016-0312——IBM TRIRIGA Application Platform before 3.3.2 allows remote attackers to obtain sensitive information via vectors relate...
CVE-2016-0311——Cross-site scripting (XSS) vulnerability in IBM Tivoli Business Service Manager 6.1.0 before 6.1.0-TIV-BSM-FP0004 and 6....
CVE-2016-0303——Cross-site scripting (XSS) vulnerability in IBM Tivoli Integrated Portal 2.2.0.0 through 2.2.0.15 allows remote attacker...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now