2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-6599 | — | — | 12.5% | Jan 30, 2018 | BMC Track-It! 11.4 before Hotfix 3 exposes an unauthenticated .NET remoting configuration service (ConfigurationService)... |
| CVE-2016-6598 | — | — | 19.6% | Jan 30, 2018 | BMC Track-It! 11.4 before Hotfix 3 exposes an unauthenticated .NET remoting file storage service (FileStorageService) on... |
| CVE-2016-10711 | — | — | 2.9% | Jan 29, 2018 | Apsis Pound before 2.8a allows request smuggling via crafted headers, a different vulnerability than CVE-2005-3751. |
| CVE-2016-2983 | — | — | 1.7% | Jan 26, 2018 | IBM Tealeaf Customer Experience 8.7, 8.8, and 9.0.2 could allow a remote attacker under unusual circumstances to read op... |
| CVE-2016-6217 | — | — | 1.0% | Jan 26, 2018 | Cross-site scripting (XSS) vulnerability in Sophos PureMessage for UNIX before 6.3.2 allows remote attackers to inject a... |
| CVE-2016-10710 | — | — | 1.1% | Jan 25, 2018 | Biscom Secure File Transfer (SFT) 5.0.1000 through 5.0.1048 does not validate the dataFieldId value, and uses sequential... |
| CVE-2016-5345 | — | — | 0.5% | Jan 23, 2018 | Buffer overflow in the Qualcomm radio driver in Android before 2017-01-05 on Android One devices allows local users to g... |
| CVE-2016-10709 | — | — | 34.3% | Jan 22, 2018 | pfSense before 2.3 allows remote authenticated users to execute arbitrary OS commands via a '|' character in the status_... |
| CVE-2016-10708 | HIGH | 7.5 | 16.0% | Jan 21, 2018 | sshd in OpenSSH before 7.4 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon cra... |
| CVE-2016-10707 | HIGH | 7.5 | 2.9% | Jan 18, 2018 | jQuery 3.0.0-rc.1 is vulnerable to Denial of Service (DoS) due to removing a logic that lowercased attribute names. Any ... |
| CVE-2016-6814 | — | — | 17.5% | Jan 18, 2018 | When an application with unsupported Codehaus versions of Groovy from 1.7.0 to 2.4.3, Apache Groovy 2.4.4 to 2.4.7 on cl... |
| CVE-2016-0219 | — | — | 1.3% | Jan 16, 2018 | XML external entity (XXE) vulnerability in IBM Rational Team Concert 3.0 before 3.0.1.6 iFix7 Interim Fix 1, 4.0 before ... |
| CVE-2016-0215 | — | — | 1.6% | Jan 16, 2018 | IBM DB2 9.7, 10.1 before FP6, and 10.5 before FP8 on AIX, Linux, HP, Solaris and Windows allow remote authenticated user... |
| CVE-2016-0207 | — | — | 0.7% | Jan 16, 2018 | IBM Algorithmics One-Algo Risk Application (ARA) 4.9.1 through 5.1.0 allows remote authenticated users to conduct clickj... |
| CVE-2016-10706 | — | — | 1.0% | Jan 12, 2018 | The Jetpack plugin before 4.0.3 for WordPress has XSS via a crafted Vimeo link. |
| CVE-2016-10705 | — | — | 1.0% | Jan 12, 2018 | The Jetpack plugin before 4.0.4 for WordPress has XSS via the Likes module. |
| CVE-2016-0336 | — | — | 0.6% | Jan 12, 2018 | Cross-site scripting (XSS) vulnerability in IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1... |
| CVE-2016-0335 | — | — | 0.8% | Jan 12, 2018 | Cross-site request forgery (CSRF) vulnerability in IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 throug... |
| CVE-2016-0332 | — | — | 2.3% | Jan 12, 2018 | IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.0 before 7.0.1-ISS-SIM-FP0001 do not proper... |
| CVE-2016-0327 | — | — | 0.3% | Jan 12, 2018 | IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.0 before 7.0.1-ISS-SIM-FP0001 allows local ... |
| CVE-2016-0324 | — | — | 3.7% | Jan 12, 2018 | IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.0 before 7.0.1-ISS-SIM-FP0001 allows remote... |
| CVE-2016-9722 | — | — | 12.0% | Jan 10, 2018 | IBM QRadar 7.2 and 7.3 specifies permissions for a security-critical resource in a way that allows that resource to be r... |
| CVE-2016-6810 | — | — | 6.1% | Jan 10, 2018 | In Apache ActiveMQ 5.x before 5.14.2, an instance of a cross-site scripting vulnerability was identified to be present i... |
| CVE-2016-10257 | — | — | 1.5% | Jan 10, 2018 | The Symantec Advanced Secure Gateway (ASG) 6.6, ASG 6.7 (prior to 6.7.2.1), ProxySG 6.5 (prior to 6.5.10.6), ProxySG 6.6... |
| CVE-2016-10256 | — | — | 1.5% | Jan 10, 2018 | The Symantec ProxySG 6.5 (prior to 6.5.10.6), 6.6, and 6.7 (prior to 6.7.2.1) management console is susceptible to a ref... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now