2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-3049 | — | — | 0.9% | Oct 24, 2017 | IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 is vulnerable to HTML injection. A remote attacker could inject malicious H... |
| CVE-2016-10517 | — | — | 2.1% | Oct 24, 2017 | networking.c in Redis before 3.2.7 allows "Cross Protocol Scripting" because it lacks a check for POST and Host: strings... |
| CVE-2016-10516 | — | — | 2.0% | Oct 23, 2017 | Cross-site scripting (XSS) vulnerability in the render_full function in debug/tbtools.py in the debugger in Pallets Werk... |
| CVE-2016-8748 | — | — | 1.8% | Oct 19, 2017 | In Apache NiFi before 1.0.1 and 1.1.x before 1.1.1, there is a cross-site scripting vulnerability in connection details ... |
| CVE-2016-5714 | HIGH | 7.2 | 2.2% | Oct 18, 2017 | Puppet Enterprise 2015.3.3 and 2016.x before 2016.4.0, and Puppet Agent 1.3.6 through 1.7.0 allow remote attackers to by... |
| CVE-2016-10515 | — | — | 0.7% | Oct 18, 2017 | In Redmine before 3.2.3, there are stored XSS vulnerabilities affecting Textile and Markdown text formatting, and projec... |
| CVE-2016-4461 | — | — | 8.3% | Oct 16, 2017 | Apache Struts 2.x before 2.3.29 allows remote attackers to execute arbitrary code via a "%{}" sequence in a tag attribut... |
| CVE-2016-8734 | — | — | 6.4% | Oct 16, 2017 | Apache Subversion's mod_dontdothat module and HTTP clients 1.4.0 through 1.8.16, and 1.9.0 through 1.9.4 are vulnerable ... |
| CVE-2016-4925 | HIGH | 7.5 | 2.7% | Oct 13, 2017 | Receipt of a specifically malformed IPv6 packet processed by the router may trigger a line card reset: processor excepti... |
| CVE-2016-4924 | HIGH | 8.4 | 0.3% | Oct 13, 2017 | An incorrect permissions vulnerability in Juniper Networks Junos OS on vMX may allow local unprivileged users on a host ... |
| CVE-2016-4923 | HIGH | 8 | 1.0% | Oct 13, 2017 | Insufficient cross site scripting protection in J-Web component in Juniper Networks Junos OS may potentially allow a rem... |
| CVE-2016-4922 | HIGH | 8.4 | 0.5% | Oct 13, 2017 | Certain combinations of Junos OS CLI commands and arguments have been found to be exploitable in a way that can allow un... |
| CVE-2016-4921 | HIGH | 7.5 | 2.9% | Oct 13, 2017 | By flooding a Juniper Networks router running Junos OS with specially crafted IPv6 traffic, all available resources can ... |
| CVE-2016-1265 | CRITICAL | 9.8 | 2.3% | Oct 13, 2017 | A remote unauthenticated network based attacker with access to Junos Space may execute arbitrary code on Junos Space or ... |
| CVE-2016-1261 | HIGH | 7.1 | 0.4% | Oct 13, 2017 | J-Web does not validate certain input that may lead to cross-site request forgery (CSRF) issues or cause a denial of J-W... |
| CVE-2016-6815 | — | — | 2.1% | Oct 13, 2017 | In Apache Ranger before 0.6.2, users with "keyadmin" role should not be allowed to change password for users with "admin... |
| CVE-2016-5791 | — | — | 2.4% | Oct 13, 2017 | An Improper Authentication issue was discovered in JanTek JTC-200, all versions. The improper authentication could provi... |
| CVE-2016-5789 | — | — | 0.4% | Oct 13, 2017 | A Cross-site Request Forgery issue was discovered in JanTek JTC-200, all versions. An attacker could perform actions wit... |
| CVE-2016-8736 | — | — | 4.8% | Oct 12, 2017 | Apache OpenMeetings before 3.1.2 is vulnerable to Remote Code Execution via RMI deserialization attack. |
| CVE-2016-9263 | — | — | 2.6% | Oct 12, 2017 | WordPress through 4.8.2, when domain-based flashmediaelement.swf sandboxing is not used, allows remote attackers to cond... |
| CVE-2016-10514 | — | — | 1.2% | Oct 10, 2017 | url_check_format in include/functions.inc.php in Piwigo before 2.8.3 allows remote attackers to bypass intended access r... |
| CVE-2016-10513 | — | — | 0.9% | Oct 10, 2017 | Cross Site Scripting (XSS) exists in Piwigo before 2.8.3 via a crafted search expression to include/functions_search.inc... |
| CVE-2016-8937 | — | — | 1.9% | Oct 5, 2017 | The IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) default authentication protocol is vulnerable to a bru... |
| CVE-2016-6806 | — | — | 0.8% | Oct 3, 2017 | Apache Wicket 6.x before 6.25.0, 7.x before 7.5.0, and 8.0.0-M1 provide a CSRF prevention measure that fails to discover... |
| CVE-2016-4434 | — | — | 3.4% | Sep 30, 2017 | Apache Tika before 1.13 does not properly initialize the XML parser or choose handlers, which might allow remote attacke... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now