2016 CVE Vulnerabilities

10,648 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-5414——FreeIPA 4.4.0 allows remote attackers to request an arbitrary SAN name for services.
CVE-2016-4383——The glance-manage db in all versions of HPE Helion Openstack Glance allows deleted image ids to be reassigned, which all...
CVE-2016-0959——Use after free vulnerability in Adobe Flash Player Desktop Runtime before 20.0.0.267, Adobe Flash Player Extended Suppor...
CVE-2016-9972——IBM QRadar 7.2 and 7.3 could allow a remote attacker to obtain sensitive information, caused by the failure to properly ...
CVE-2016-9738——IBM QRadar 7.2 and 7.3 does not require that users should have strong passwords by default, which makes it easier for at...
CVE-2016-6083——IBM Tivoli Monitoring V6 could allow an unauthenticated user to access SOAP queries that could contain sensitive informa...
CVE-2016-8498——Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this ca...
CVE-2016-8493——In FortiClientWindows 5.4.1 and 5.4.2, an attacker may escalate privilege via a FortiClientNamedPipe vulnerability.
CVE-2016-5893——IBM Sterling B2B Integrator Standard Edition 5.2 allows web pages to be stored locally which can be read by another user...
CVE-2016-9983——IBM Sterling B2B Integrator Standard Edition 5.2 could allow an authenticated user with special privileges to view files...
CVE-2016-9982——IBM Sterling B2B Integrator Standard Edition 5.2 could allow an authenticated user to obtain sensitive information such ...
CVE-2016-9747——IBM RELM 4.0, 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Java...
CVE-2016-7508——Multiple SQL injection vulnerabilities in GLPI 0.90.4 allow an authenticated remote attacker to execute arbitrary SQL co...
CVE-2016-8731CRITICAL9.8Hard-coded FTP credentials (r:r) are included in the Foscam C1 running firmware 1.9.1.12. Knowledge of these credentials...
CVE-2016-10366——Kibana versions after and including 4.3 and before 4.6.2 are vulnerable to a cross-site scripting (XSS) attack.
CVE-2016-10365——Kibana versions before 4.6.3 and 5.0.1 have an open redirect vulnerability that would enable an attacker to craft a link...
CVE-2016-10364——With X-Pack installed, Kibana versions 5.0.0 and 5.0.1 were not properly authenticating requests to advanced settings an...
CVE-2016-10363——Logstash versions prior to 2.3.3, when using the Netflow Codec plugin, a remote attacker crafting malicious Netflow v5, ...
CVE-2016-10362——Prior to Logstash version 5.0.1, Elasticsearch Output plugin when updating connections after sniffing, would log to file...
CVE-2016-1000222——Logstash prior to version 2.1.2, the CSV output can be attacked via engineered input that will create malicious formulas...
CVE-2016-1000221——Logstash prior to version 2.3.4, Elasticsearch Output plugin would log to file HTTP authorization headers which could co...
CVE-2016-1000220——Kibana before 4.5.4 and 4.1.11 are vulnerable to an XSS attack that would allow an attacker to execute arbitrary JavaScr...
CVE-2016-1000219——Kibana before 4.5.4 and 4.1.11 when a custom output is configured for logging in, cookies and authorization headers coul...
CVE-2016-1000218——Kibana Reporting plugin version 2.4.0 is vulnerable to a CSRF vulnerability that could allow an attacker to generate sup...
CVE-2016-10395——In FlexNet Publisher versions before Luton SP1 (11.14.1.1) running FlexNet Publisher Licensing Service on Windows platfo...

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now