2016 CVE Vulnerabilities

10,648 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-10256——The Symantec ProxySG 6.5 (prior to 6.5.10.6), 6.6, and 6.7 (prior to 6.7.2.1) management console is susceptible to a ref...
CVE-2016-10704MEDIUM6.1Magento Community Edition and Enterprise Edition before 2.0.10 and 2.1.x before 2.1.2 have XSS via e-mail templates that...
CVE-2016-3695——The einj_error_inject function in drivers/acpi/apei/einj.c in the Linux kernel allows local users to simulate hardware e...
CVE-2016-6914HIGH7.8Ubiquiti UniFi Video before 3.8.0 for Windows uses weak permissions for the installation directory, which allows local u...
CVE-2016-10703HIGH7.5A regular expression Denial of Service (DoS) vulnerability in the file lib/ecstatic.js of the ecstatic npm package, befo...
CVE-2016-6904——Versions of VASA Provider for Clustered Data ONTAP prior to 7.0P1 contain a web server that accepts plain text authentic...
CVE-2016-5713——Versions of Puppet Agent prior to 1.6.0 included a version of the Puppet Execution Protocol (PXP) agent that passed envi...
CVE-2016-1255——The pg_ctlcluster script in postgresql-common package in Debian wheezy before 134wheezy5, in Debian jessie before 165+de...
CVE-2016-1254——Tor before 0.2.8.12 might allow remote attackers to cause a denial of service (client crash) via a crafted hidden servic...
CVE-2016-1253——The most package in Debian wheezy before 5.0.0a-2.2, in Debian jessie before 5.0.0a-2.3+deb8u1, and in Debian unstable b...
CVE-2016-1252MEDIUM5.9The apt package in Debian jessie before 1.0.9.8.4, in Debian unstable before 1.4~beta2, in Ubuntu 14.04 LTS before 1.0.1...
CVE-2016-10702——Pebble Smartwatch devices through 4.3 mishandle UUID storage, which allows attackers to read an arbitrary application's ...
CVE-2016-10701——In Hitachi Vantara Pentaho BA Platform through 8.0, a CSRF issue exists in the Business Analytics application.
CVE-2016-6024——IBM Jazz technology based products might divulge information that might be useful in helping attackers through error mes...
CVE-2016-10700——auth_login.php in Cacti before 1.0.0 allows remote authenticated users who use web authentication to bypass intended acc...
CVE-2016-6804HIGH7.8The Apache OpenOffice installer (versions prior to 4.1.3, including some branded as OpenOffice.org) for Windows contains...
CVE-2016-8610HIGH7.5A denial of service flaw was found in OpenSSL 0.9.8, 1.0.1, 1.0.2 through 1.0.2h, and 1.1.0 in the way the TLS/SSL proto...
CVE-2016-8234——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was...
CVE-2016-6803——An installer defect known as an "unquoted Windows search path vulnerability" affected the Apache OpenOffice before 4.1.3...
CVE-2016-0872——A Plaintext Storage of a Password issue was discovered in Kabona AB WebDatorCentral (WDC) versions prior to Version 3.4....
CVE-2016-3048——IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to e...
CVE-2016-0759——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-4003. Reason: This candidate is a reservation ...
CVE-2016-10699——D-Link DSL-2740E 1.00_BG_20150720 devices are prone to persistent XSS attacks in the username and password fields: a rem...
CVE-2016-3090——The TextParseUtil.translateVariables method in Apache Struts 2.x before 2.3.20 allows remote attackers to execute arbitr...
CVE-2016-5003——The Apache XML-RPC (aka ws-xmlrpc) library 3.1.3, as used in Apache Archiva, allows remote attackers to execute arbitrar...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now