2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-6114 | — | — | 0.7% | Jul 12, 2017 | IBM Emptoris Sourcing 9.5.x through 10.1.x is vulnerable to cross-site scripting. This vulnerability allows users to emb... |
| CVE-2016-8638 | — | — | 2.1% | Jul 12, 2017 | A vulnerability in ipsilon 2.0 before 2.0.2, 1.2 before 1.2.1, 1.1 before 1.1.2, and 1.0 before 1.0.3 was found that all... |
| CVE-2016-10397 | — | — | 1.9% | Jul 10, 2017 | In PHP before 5.6.28 and 7.x before 7.0.13, incorrect handling of various URI components in the URL parser could be used... |
| CVE-2016-4000 | — | — | 6.6% | Jul 6, 2017 | Jython before 2.7.1rc1 allows attackers to execute arbitrary code via a crafted serialized PyFunction object. |
| CVE-2016-10396 | — | — | 2.9% | Jul 6, 2017 | The racoon daemon in IPsec-Tools 0.8.2 contains a remotely exploitable computational-complexity attack when parsing and ... |
| CVE-2016-9989 | — | — | 0.7% | Jul 5, 2017 | IBM Jazz Foundation Reporting Service (JRS) 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows... |
| CVE-2016-9988 | — | — | 0.7% | Jul 5, 2017 | IBM Jazz Foundation Reporting Service (JRS) 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows... |
| CVE-2016-9987 | — | — | 0.7% | Jul 5, 2017 | IBM Jazz Foundation Reporting Service (JRS) 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows... |
| CVE-2016-9986 | — | — | 0.7% | Jul 5, 2017 | IBM Jazz Foundation Reporting Service (JRS) 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows... |
| CVE-2016-9700 | — | — | 0.7% | Jul 5, 2017 | IBM Jazz Foundation could allow an authenticated attacker to obtain sensitive information from error message stack trace... |
| CVE-2016-9746 | — | — | 0.7% | Jul 5, 2017 | IBM Team Concert (RTC) 4.0, 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed ... |
| CVE-2016-9733 | — | — | 0.7% | Jul 5, 2017 | IBM Team Concert (RTC) 4.0, 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed ... |
| CVE-2016-9701 | — | — | 0.7% | Jul 5, 2017 | IBM Team Concert 4.0, 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitr... |
| CVE-2016-0238 | — | — | 0.9% | Jul 5, 2017 | IBM Security Guardium 9.0, 9.1, 9.5, 10.0, and 10.1 transmits sensitive data in cleartext in the query of the request. T... |
| CVE-2016-6201 | — | — | 0.9% | Jul 3, 2017 | Cross-site scripting (XSS) vulnerability in Ektron Content Management System (CMS) before 9.1.0.184 SP3 (9.1.0.184.3.127... |
| CVE-2016-6127 | — | — | 1.2% | Jul 3, 2017 | Cross-site scripting (XSS) vulnerability in Request Tracker (RT) 4.x before 4.0.25, 4.2.x before 4.2.14, and 4.4.x befor... |
| CVE-2016-5045 | — | — | 1.5% | Jul 3, 2017 | NetApp OnCommand System Manager before 9.0 allows remote attackers to obtain sensitive credentials via vectors related t... |
| CVE-2016-3998 | — | — | 0.9% | Jul 3, 2017 | NetApp AltaVault 4.1 and earlier allows man-in-the-middle attackers to obtain sensitive information, gain privileges, or... |
| CVE-2016-3997 | — | — | 0.8% | Jul 3, 2017 | NetApp Clustered Data ONTAP allows man-in-the-middle attackers to obtain sensitive information, gain privileges, or caus... |
| CVE-2016-3400 | — | — | 1.5% | Jul 3, 2017 | NetApp Data ONTAP 8.1 and 8.2, when operating in 7-Mode, allows man-in-the-middle attackers to obtain sensitive informat... |
| CVE-2016-9358 | — | — | 2.1% | Jun 30, 2017 | A Hard-Coded Passwords issue was discovered in Marel Food Processing Systems M3000 terminal associated with the followin... |
| CVE-2016-10042 | — | — | 0.9% | Jun 29, 2017 | Authorization Bypass in the Web interface of Arcadyan SLT-00 Star* (aka Swisscom Internet-Box) devices before R7.7 allow... |
| CVE-2016-7062 | — | — | 0.4% | Jun 27, 2017 | rhscon-ceph in Red Hat Storage Console 2 x86_64 and Red Hat Storage Console Node 2 x86_64 allows local users to obtain t... |
| CVE-2016-6342 | HIGH | 7.5 | 1.0% | Jun 27, 2017 | elog 3.1.1 allows remote attackers to post data as any username in the logbook. |
| CVE-2016-5414 | — | — | 1.0% | Jun 27, 2017 | FreeIPA 4.4.0 allows remote attackers to request an arbitrary SAN name for services. |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now