2016 CVE Vulnerabilities

10,647 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-10704MEDIUM6.1Magento Community Edition and Enterprise Edition before 2.0.10 and 2.1.x before 2.1.2 have XSS via e-mail templates that...
CVE-2016-3695The einj_error_inject function in drivers/acpi/apei/einj.c in the Linux kernel allows local users to simulate hardware e...
CVE-2016-6914HIGH7.8Ubiquiti UniFi Video before 3.8.0 for Windows uses weak permissions for the installation directory, which allows local u...
CVE-2016-10703HIGH7.5A regular expression Denial of Service (DoS) vulnerability in the file lib/ecstatic.js of the ecstatic npm package, befo...
CVE-2016-6904Versions of VASA Provider for Clustered Data ONTAP prior to 7.0P1 contain a web server that accepts plain text authentic...
CVE-2016-5713Versions of Puppet Agent prior to 1.6.0 included a version of the Puppet Execution Protocol (PXP) agent that passed envi...
CVE-2016-1255The pg_ctlcluster script in postgresql-common package in Debian wheezy before 134wheezy5, in Debian jessie before 165+de...
CVE-2016-1254Tor before 0.2.8.12 might allow remote attackers to cause a denial of service (client crash) via a crafted hidden servic...
CVE-2016-1253The most package in Debian wheezy before 5.0.0a-2.2, in Debian jessie before 5.0.0a-2.3+deb8u1, and in Debian unstable b...
CVE-2016-1252MEDIUM5.9The apt package in Debian jessie before 1.0.9.8.4, in Debian unstable before 1.4~beta2, in Ubuntu 14.04 LTS before 1.0.1...
CVE-2016-10702Pebble Smartwatch devices through 4.3 mishandle UUID storage, which allows attackers to read an arbitrary application's ...
CVE-2016-10701In Hitachi Vantara Pentaho BA Platform through 8.0, a CSRF issue exists in the Business Analytics application.
CVE-2016-6024IBM Jazz technology based products might divulge information that might be useful in helping attackers through error mes...
CVE-2016-10700auth_login.php in Cacti before 1.0.0 allows remote authenticated users who use web authentication to bypass intended acc...
CVE-2016-6804HIGH7.8The Apache OpenOffice installer (versions prior to 4.1.3, including some branded as OpenOffice.org) for Windows contains...
CVE-2016-8610HIGH7.5A denial of service flaw was found in OpenSSL 0.9.8, 1.0.1, 1.0.2 through 1.0.2h, and 1.1.0 in the way the TLS/SSL proto...
CVE-2016-8234Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was...
CVE-2016-6803An installer defect known as an "unquoted Windows search path vulnerability" affected the Apache OpenOffice before 4.1.3...
CVE-2016-0872A Plaintext Storage of a Password issue was discovered in Kabona AB WebDatorCentral (WDC) versions prior to Version 3.4....
CVE-2016-3048IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to e...
CVE-2016-0759Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-4003. Reason: This candidate is a reservation ...
CVE-2016-10699D-Link DSL-2740E 1.00_BG_20150720 devices are prone to persistent XSS attacks in the username and password fields: a rem...
CVE-2016-3090The TextParseUtil.translateVariables method in Apache Struts 2.x before 2.3.20 allows remote attackers to execute arbitr...
CVE-2016-5003The Apache XML-RPC (aka ws-xmlrpc) library 3.1.3, as used in Apache Archiva, allows remote attackers to execute arbitrar...
CVE-2016-5002XML external entity (XXE) vulnerability in the Apache XML-RPC (aka ws-xmlrpc) library 3.1.3, as used in Apache Archiva, ...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now