2016 CVE Vulnerabilities

10,648 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-6118——IBM Emptoris Supplier Lifecycle Management 10.1.0.x is vulnerable to cross-site scripting. This vulnerability allows use...
CVE-2016-10400——Directory Traversal exists in ATutor before 2.2.2 via the icon parameter to /mods/_core/courses/users/create_course.php....
CVE-2016-7059——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was...
CVE-2016-7058——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was...
CVE-2016-7057——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was...
CVE-2016-6018——IBM Emptoris Contract Management 10.0 and 10.1 reveals detailed error messages in certain features that could cause an a...
CVE-2016-6798——In the XSS Protection API module before 1.0.12 in Apache Sling, the method XSS.getValidXML() uses an insecure SAX parser...
CVE-2016-5394MEDIUM6.1In the XSS Protection API module before 1.0.12 in Apache Sling, the encoding done by the XSSAPI.encodeForJSString() meth...
CVE-2016-7509——Cross-site scripting (XSS) vulnerability in GLPI 0.90.4 allows remote authenticated attackers to inject arbitrary web sc...
CVE-2016-7507——Cross-Site Request Forgery (CSRF) vulnerability in GLPI 0.90.4 allows remote authenticated attackers to submit a request...
CVE-2016-6793——The DiskFileItem class in Apache Wicket 6.x before 6.25.0 and 1.5.x before 1.5.17 allows remote attackers to cause a den...
CVE-2016-6312——The mod_dontdothat component of the mod_dav_svn Apache module in Subversion as packaged in Red Hat Enterprise Linux 5.11...
CVE-2016-4996——discovery-debug in Foreman before 6.2 when the ssh service has been enabled on discovered nodes displays the root passwo...
CVE-2016-4984——/usr/libexec/openldap/generate-server-cert.sh in openldap-servers sets weak permissions for the TLS certificate, which a...
CVE-2016-4982——authd sets weak permissions for /etc/ident.key, which allows local users to obtain the key by leveraging a race conditio...
CVE-2016-10398——Android 6.0 has an authentication bypass for attackers with root and physical access. Cryptographic authentication token...
CVE-2016-0764MEDIUM6.2Race condition in Network Manager before 1.0.12 as packaged in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Li...
CVE-2016-8964——IBM BigFix Inventory v9 9.2 uses an inadequate account lockout setting that could allow a remote attacker to brute force...
CVE-2016-8952——IBM Emptoris Strategic Supply Management Platform 10.0.0.x through 10.1.1.x is vulnerable to cross-site scripting. This ...
CVE-2016-8951——IBM Emptoris Strategic Supply Management Platform 10.0.0.x through 10.1.1.x is vulnerable to a denial of service attack....
CVE-2016-6019——IBM Emptoris Strategic Supply Management Platform 10.0.0.x through 10.1.1.x is vulnerable to cross-site scripting. This ...
CVE-2016-8953——IBM Emptoris Sourcing 9.5.x through 10.1.x could allow a remote attacker to conduct phishing attacks, using an open redi...
CVE-2016-8950——IBM Emptoris Sourcing 9.5.x through 10.1.x is vulnerable to cross-site scripting. This vulnerability allows users to emb...
CVE-2016-8948——IBM Emptoris Sourcing 9.5.x through 10.1.x is vulnerable to cross-site scripting. This vulnerability allows users to emb...
CVE-2016-8947——IBM Emptoris Sourcing 9.5.x through 10.1.x could allow a remote attacker to conduct phishing attacks, using an open redi...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now