2016 CVE Vulnerabilities

10,648 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-5002——XML external entity (XXE) vulnerability in the Apache XML-RPC (aka ws-xmlrpc) library 3.1.3, as used in Apache Archiva, ...
CVE-2016-3049——IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 is vulnerable to HTML injection. A remote attacker could inject malicious H...
CVE-2016-10517——networking.c in Redis before 3.2.7 allows "Cross Protocol Scripting" because it lacks a check for POST and Host: strings...
CVE-2016-10516——Cross-site scripting (XSS) vulnerability in the render_full function in debug/tbtools.py in the debugger in Pallets Werk...
CVE-2016-8748——In Apache NiFi before 1.0.1 and 1.1.x before 1.1.1, there is a cross-site scripting vulnerability in connection details ...
CVE-2016-5714HIGH7.2Puppet Enterprise 2015.3.3 and 2016.x before 2016.4.0, and Puppet Agent 1.3.6 through 1.7.0 allow remote attackers to by...
CVE-2016-10515——In Redmine before 3.2.3, there are stored XSS vulnerabilities affecting Textile and Markdown text formatting, and projec...
CVE-2016-4461——Apache Struts 2.x before 2.3.29 allows remote attackers to execute arbitrary code via a "%{}" sequence in a tag attribut...
CVE-2016-8734——Apache Subversion's mod_dontdothat module and HTTP clients 1.4.0 through 1.8.16, and 1.9.0 through 1.9.4 are vulnerable ...
CVE-2016-4925HIGH7.5Receipt of a specifically malformed IPv6 packet processed by the router may trigger a line card reset: processor excepti...
CVE-2016-4924HIGH8.4An incorrect permissions vulnerability in Juniper Networks Junos OS on vMX may allow local unprivileged users on a host ...
CVE-2016-4923HIGH8Insufficient cross site scripting protection in J-Web component in Juniper Networks Junos OS may potentially allow a rem...
CVE-2016-4922HIGH8.4Certain combinations of Junos OS CLI commands and arguments have been found to be exploitable in a way that can allow un...
CVE-2016-4921HIGH7.5By flooding a Juniper Networks router running Junos OS with specially crafted IPv6 traffic, all available resources can ...
CVE-2016-1265CRITICAL9.8A remote unauthenticated network based attacker with access to Junos Space may execute arbitrary code on Junos Space or ...
CVE-2016-1261HIGH7.1J-Web does not validate certain input that may lead to cross-site request forgery (CSRF) issues or cause a denial of J-W...
CVE-2016-6815——In Apache Ranger before 0.6.2, users with "keyadmin" role should not be allowed to change password for users with "admin...
CVE-2016-5791——An Improper Authentication issue was discovered in JanTek JTC-200, all versions. The improper authentication could provi...
CVE-2016-5789——A Cross-site Request Forgery issue was discovered in JanTek JTC-200, all versions. An attacker could perform actions wit...
CVE-2016-8736——Apache OpenMeetings before 3.1.2 is vulnerable to Remote Code Execution via RMI deserialization attack.
CVE-2016-9263——WordPress through 4.8.2, when domain-based flashmediaelement.swf sandboxing is not used, allows remote attackers to cond...
CVE-2016-10514——url_check_format in include/functions.inc.php in Piwigo before 2.8.3 allows remote attackers to bypass intended access r...
CVE-2016-10513——Cross Site Scripting (XSS) exists in Piwigo before 2.8.3 via a crafted search expression to include/functions_search.inc...
CVE-2016-8937——The IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) default authentication protocol is vulnerable to a bru...
CVE-2016-6806——Apache Wicket 6.x before 6.25.0, 7.x before 7.5.0, and 8.0.0-M1 provide a CSRF prevention measure that fails to discover...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now