2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-10704 | MEDIUM | 6.1 | 0.6% | Dec 30, 2017 | Magento Community Edition and Enterprise Edition before 2.0.10 and 2.1.x before 2.1.2 have XSS via e-mail templates that... |
| CVE-2016-3695 | — | — | 0.5% | Dec 29, 2017 | The einj_error_inject function in drivers/acpi/apei/einj.c in the Linux kernel allows local users to simulate hardware e... |
| CVE-2016-6914 | HIGH | 7.8 | 1.2% | Dec 27, 2017 | Ubiquiti UniFi Video before 3.8.0 for Windows uses weak permissions for the installation directory, which allows local u... |
| CVE-2016-10703 | HIGH | 7.5 | 2.6% | Dec 14, 2017 | A regular expression Denial of Service (DoS) vulnerability in the file lib/ecstatic.js of the ecstatic npm package, befo... |
| CVE-2016-6904 | — | — | 1.2% | Dec 11, 2017 | Versions of VASA Provider for Clustered Data ONTAP prior to 7.0P1 contain a web server that accepts plain text authentic... |
| CVE-2016-5713 | — | — | 2.0% | Dec 6, 2017 | Versions of Puppet Agent prior to 1.6.0 included a version of the Puppet Execution Protocol (PXP) agent that passed envi... |
| CVE-2016-1255 | — | — | 0.4% | Dec 5, 2017 | The pg_ctlcluster script in postgresql-common package in Debian wheezy before 134wheezy5, in Debian jessie before 165+de... |
| CVE-2016-1254 | — | — | 3.0% | Dec 5, 2017 | Tor before 0.2.8.12 might allow remote attackers to cause a denial of service (client crash) via a crafted hidden servic... |
| CVE-2016-1253 | — | — | 4.8% | Dec 5, 2017 | The most package in Debian wheezy before 5.0.0a-2.2, in Debian jessie before 5.0.0a-2.3+deb8u1, and in Debian unstable b... |
| CVE-2016-1252 | MEDIUM | 5.9 | 7.2% | Dec 5, 2017 | The apt package in Debian jessie before 1.0.9.8.4, in Debian unstable before 1.4~beta2, in Ubuntu 14.04 LTS before 1.0.1... |
| CVE-2016-10702 | — | — | 0.7% | Nov 28, 2017 | Pebble Smartwatch devices through 4.3 mishandle UUID storage, which allows attackers to read an arbitrary application's ... |
| CVE-2016-10701 | — | — | 0.8% | Nov 28, 2017 | In Hitachi Vantara Pentaho BA Platform through 8.0, a CSRF issue exists in the Business Analytics application. |
| CVE-2016-6024 | — | — | 0.7% | Nov 27, 2017 | IBM Jazz technology based products might divulge information that might be useful in helping attackers through error mes... |
| CVE-2016-10700 | — | — | 2.5% | Nov 24, 2017 | auth_login.php in Cacti before 1.0.0 allows remote authenticated users who use web authentication to bypass intended acc... |
| CVE-2016-6804 | HIGH | 7.8 | 3.0% | Nov 20, 2017 | The Apache OpenOffice installer (versions prior to 4.1.3, including some branded as OpenOffice.org) for Windows contains... |
| CVE-2016-8610 | HIGH | 7.5 | 39.7% | Nov 13, 2017 | A denial of service flaw was found in OpenSSL 0.9.8, 1.0.1, 1.0.2 through 1.0.2h, and 1.1.0 in the way the TLS/SSL proto... |
| CVE-2016-8234 | — | — | — | Nov 13, 2017 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was... |
| CVE-2016-6803 | — | — | 2.1% | Nov 13, 2017 | An installer defect known as an "unquoted Windows search path vulnerability" affected the Apache OpenOffice before 4.1.3... |
| CVE-2016-0872 | — | — | 1.2% | Nov 7, 2017 | A Plaintext Storage of a Password issue was discovered in Kabona AB WebDatorCentral (WDC) versions prior to Version 3.4.... |
| CVE-2016-3048 | — | — | 0.7% | Nov 1, 2017 | IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to e... |
| CVE-2016-0759 | — | — | — | Oct 31, 2017 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-4003. Reason: This candidate is a reservation ... |
| CVE-2016-10699 | — | — | 1.4% | Oct 31, 2017 | D-Link DSL-2740E 1.00_BG_20150720 devices are prone to persistent XSS attacks in the username and password fields: a rem... |
| CVE-2016-3090 | — | — | 6.1% | Oct 30, 2017 | The TextParseUtil.translateVariables method in Apache Struts 2.x before 2.3.20 allows remote attackers to execute arbitr... |
| CVE-2016-5003 | — | — | 14.9% | Oct 27, 2017 | The Apache XML-RPC (aka ws-xmlrpc) library 3.1.3, as used in Apache Archiva, allows remote attackers to execute arbitrar... |
| CVE-2016-5002 | — | — | 8.3% | Oct 27, 2017 | XML external entity (XXE) vulnerability in the Apache XML-RPC (aka ws-xmlrpc) library 3.1.3, as used in Apache Archiva, ... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now