2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-9976 | — | — | 1.7% | May 3, 2017 | IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow a remote attacker to include arbitrary files. A remote attacke... |
| CVE-2016-2930 | — | — | 1.6% | May 3, 2017 | IBM BigFix Remote Control 9.1.3 could allow a remote attacker to perform actions reserved for an administrator without a... |
| CVE-2016-0382 | — | — | 0.3% | May 3, 2017 | The IBM Tealeaf Consumer Experience 8.7, 8.8, and 9.0 portal exposes some of its operational state in a form that may be... |
| CVE-2016-10368 | — | — | 2.2% | May 3, 2017 | Open redirect vulnerability in Opsview Monitor Pro (Prior to 5.1.0.162300841, prior to 5.0.2.27475, prior to 4.6.4.16239... |
| CVE-2016-10367 | — | — | 16.1% | May 3, 2017 | In Opsview Monitor Pro (Prior to 5.1.0.162300841, prior to 5.0.2.27475, prior to 4.6.4.162391051, and 4.5.x without a ce... |
| CVE-2016-5810 | — | — | 15.4% | May 2, 2017 | upAdminPg.asp in Advantech WebAccess before 8.1_20160519 allows remote authenticated administrators to obtain sensitive ... |
| CVE-2016-5063 | — | — | 8.4% | May 2, 2017 | The RSCD agent in BMC Server Automation before 8.6 SP1 Patch 2 and 8.7 before Patch 3 on Windows might allow remote atta... |
| CVE-2016-5006 | — | — | 1.1% | May 2, 2017 | The Cloud Controller in Cloud Foundry before 239 logs user-provided service objects at creation, which allows attackers ... |
| CVE-2016-4467 | — | — | 1.6% | May 2, 2017 | The C client and C-based client bindings in the Apache Qpid Proton library before 0.13.1 on Windows do not properly veri... |
| CVE-2016-4442 | — | — | 1.6% | May 2, 2017 | The rack-mini-profiler gem before 0.10.1 for Ruby allows remote attackers to obtain sensitive information about allocate... |
| CVE-2016-10243 | — | — | 7.1% | May 2, 2017 | TeX Live allows remote attackers to execute arbitrary commands by leveraging inclusion of mpost in shell_escape_commands... |
| CVE-2016-8649 | — | — | 2.8% | May 1, 2017 | lxc-attach in LXC before 1.0.9 and 2.x before 2.0.6 allows an attacker inside of an unprivileged container to use an inh... |
| CVE-2016-10351 | — | — | 0.4% | May 1, 2017 | Telegram Desktop 0.10.19 uses 0755 permissions for $HOME/.TelegramDesktop, which allows local users to obtain sensitive ... |
| CVE-2016-10350 | — | — | 1.6% | May 1, 2017 | The archive_read_format_cab_read_header function in archive_read_support_format_cab.c in libarchive 3.2.2 allows remote ... |
| CVE-2016-10349 | — | — | 1.7% | May 1, 2017 | The archive_le32dec function in archive_endian.h in libarchive 3.2.2 allows remote attackers to cause a denial of servic... |
| CVE-2016-8593 | — | — | 7.0% | Apr 28, 2017 | Directory traversal vulnerability in upload.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows ... |
| CVE-2016-8592 | — | — | 6.2% | Apr 28, 2017 | log_query_system.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users ... |
| CVE-2016-8591 | — | — | 6.2% | Apr 28, 2017 | log_query.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to exec... |
| CVE-2016-8590 | — | — | 5.7% | Apr 28, 2017 | log_query_dlp.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to ... |
| CVE-2016-8589 | — | — | 5.7% | Apr 28, 2017 | log_query_dae.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to ... |
| CVE-2016-8588 | — | — | 2.2% | Apr 28, 2017 | The hotfix_upload.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users... |
| CVE-2016-8587 | — | — | 2.5% | Apr 28, 2017 | dlp_policy_upload.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users... |
| CVE-2016-8586 | — | — | 6.1% | Apr 28, 2017 | detected_potential_files.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticate... |
| CVE-2016-8585 | — | — | 7.2% | Apr 28, 2017 | admin_sys_time.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to... |
| CVE-2016-8584 | — | — | 5.5% | Apr 28, 2017 | Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier uses predictable session values, which allows remote attac... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now