2016 CVE Vulnerabilities

10,647 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-3049IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 is vulnerable to HTML injection. A remote attacker could inject malicious H...
CVE-2016-10517networking.c in Redis before 3.2.7 allows "Cross Protocol Scripting" because it lacks a check for POST and Host: strings...
CVE-2016-10516Cross-site scripting (XSS) vulnerability in the render_full function in debug/tbtools.py in the debugger in Pallets Werk...
CVE-2016-8748In Apache NiFi before 1.0.1 and 1.1.x before 1.1.1, there is a cross-site scripting vulnerability in connection details ...
CVE-2016-5714HIGH7.2Puppet Enterprise 2015.3.3 and 2016.x before 2016.4.0, and Puppet Agent 1.3.6 through 1.7.0 allow remote attackers to by...
CVE-2016-10515In Redmine before 3.2.3, there are stored XSS vulnerabilities affecting Textile and Markdown text formatting, and projec...
CVE-2016-4461Apache Struts 2.x before 2.3.29 allows remote attackers to execute arbitrary code via a "%{}" sequence in a tag attribut...
CVE-2016-8734Apache Subversion's mod_dontdothat module and HTTP clients 1.4.0 through 1.8.16, and 1.9.0 through 1.9.4 are vulnerable ...
CVE-2016-4925HIGH7.5Receipt of a specifically malformed IPv6 packet processed by the router may trigger a line card reset: processor excepti...
CVE-2016-4924HIGH8.4An incorrect permissions vulnerability in Juniper Networks Junos OS on vMX may allow local unprivileged users on a host ...
CVE-2016-4923HIGH8Insufficient cross site scripting protection in J-Web component in Juniper Networks Junos OS may potentially allow a rem...
CVE-2016-4922HIGH8.4Certain combinations of Junos OS CLI commands and arguments have been found to be exploitable in a way that can allow un...
CVE-2016-4921HIGH7.5By flooding a Juniper Networks router running Junos OS with specially crafted IPv6 traffic, all available resources can ...
CVE-2016-1265CRITICAL9.8A remote unauthenticated network based attacker with access to Junos Space may execute arbitrary code on Junos Space or ...
CVE-2016-1261HIGH7.1J-Web does not validate certain input that may lead to cross-site request forgery (CSRF) issues or cause a denial of J-W...
CVE-2016-6815In Apache Ranger before 0.6.2, users with "keyadmin" role should not be allowed to change password for users with "admin...
CVE-2016-5791An Improper Authentication issue was discovered in JanTek JTC-200, all versions. The improper authentication could provi...
CVE-2016-5789A Cross-site Request Forgery issue was discovered in JanTek JTC-200, all versions. An attacker could perform actions wit...
CVE-2016-8736Apache OpenMeetings before 3.1.2 is vulnerable to Remote Code Execution via RMI deserialization attack.
CVE-2016-9263WordPress through 4.8.2, when domain-based flashmediaelement.swf sandboxing is not used, allows remote attackers to cond...
CVE-2016-10514url_check_format in include/functions.inc.php in Piwigo before 2.8.3 allows remote attackers to bypass intended access r...
CVE-2016-10513Cross Site Scripting (XSS) exists in Piwigo before 2.8.3 via a crafted search expression to include/functions_search.inc...
CVE-2016-8937The IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) default authentication protocol is vulnerable to a bru...
CVE-2016-6806Apache Wicket 6.x before 6.25.0, 7.x before 7.5.0, and 8.0.0-M1 provide a CSRF prevention measure that fails to discover...
CVE-2016-4434Apache Tika before 1.13 does not properly initialize the XML parser or choose handlers, which might allow remote attacke...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now