2016 CVE Vulnerabilities

10,647 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-4383The glance-manage db in all versions of HPE Helion Openstack Glance allows deleted image ids to be reassigned, which all...
CVE-2016-0959Use after free vulnerability in Adobe Flash Player Desktop Runtime before 20.0.0.267, Adobe Flash Player Extended Suppor...
CVE-2016-9972IBM QRadar 7.2 and 7.3 could allow a remote attacker to obtain sensitive information, caused by the failure to properly ...
CVE-2016-9738IBM QRadar 7.2 and 7.3 does not require that users should have strong passwords by default, which makes it easier for at...
CVE-2016-6083IBM Tivoli Monitoring V6 could allow an unauthenticated user to access SOAP queries that could contain sensitive informa...
CVE-2016-8498Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca...
CVE-2016-8493In FortiClientWindows 5.4.1 and 5.4.2, an attacker may escalate privilege via a FortiClientNamedPipe vulnerability.
CVE-2016-5893IBM Sterling B2B Integrator Standard Edition 5.2 allows web pages to be stored locally which can be read by another user...
CVE-2016-9983IBM Sterling B2B Integrator Standard Edition 5.2 could allow an authenticated user with special privileges to view files...
CVE-2016-9982IBM Sterling B2B Integrator Standard Edition 5.2 could allow an authenticated user to obtain sensitive information such ...
CVE-2016-9747IBM RELM 4.0, 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Java...
CVE-2016-7508Multiple SQL injection vulnerabilities in GLPI 0.90.4 allow an authenticated remote attacker to execute arbitrary SQL co...
CVE-2016-8731CRITICAL9.8Hard-coded FTP credentials (r:r) are included in the Foscam C1 running firmware 1.9.1.12. Knowledge of these credentials...
CVE-2016-10366Kibana versions after and including 4.3 and before 4.6.2 are vulnerable to a cross-site scripting (XSS) attack.
CVE-2016-10365Kibana versions before 4.6.3 and 5.0.1 have an open redirect vulnerability that would enable an attacker to craft a link...
CVE-2016-10364With X-Pack installed, Kibana versions 5.0.0 and 5.0.1 were not properly authenticating requests to advanced settings an...
CVE-2016-10363Logstash versions prior to 2.3.3, when using the Netflow Codec plugin, a remote attacker crafting malicious Netflow v5, ...
CVE-2016-10362Prior to Logstash version 5.0.1, Elasticsearch Output plugin when updating connections after sniffing, would log to file...
CVE-2016-1000222Logstash prior to version 2.1.2, the CSV output can be attacked via engineered input that will create malicious formulas...
CVE-2016-1000221Logstash prior to version 2.3.4, Elasticsearch Output plugin would log to file HTTP authorization headers which could co...
CVE-2016-1000220Kibana before 4.5.4 and 4.1.11 are vulnerable to an XSS attack that would allow an attacker to execute arbitrary JavaScr...
CVE-2016-1000219Kibana before 4.5.4 and 4.1.11 when a custom output is configured for logging in, cookies and authorization headers coul...
CVE-2016-1000218Kibana Reporting plugin version 2.4.0 is vulnerable to a CSRF vulnerability that could allow an attacker to generate sup...
CVE-2016-10395In FlexNet Publisher versions before Luton SP1 (11.14.1.1) running FlexNet Publisher Licensing Service on Windows platfo...
CVE-2016-8751Apache Ranger before 0.6.3 is vulnerable to a Stored Cross-Site Scripting in when entering custom policy conditions. Adm...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now