2016 CVE Vulnerabilities

10,648 CVEs published in 2016.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2016-7467——The TMM SSO plugin in F5 BIG-IP APM 12.0.0 - 12.1.1, 11.6.0 - 11.6.1 HF1, 11.5.4 - 11.5.4 HF2, when configured as a SAML...
CVE-2016-6811——In Apache Hadoop 2.x before 2.7.4, a user who can escalate to yarn user can possibly run arbitrary commands as root user...
CVE-2016-10259——Symantec SSL Visibility (SSLV) 3.8.4FC, 3.9, 3.10 before 3.10.4.1, and 3.11 before 3.11.3.1 is susceptible to a denial-o...
CVE-2016-8237——Remote code execution in Lenovo Updates (not Lenovo System Update) allows man-in-the-middle attackers to execute arbitra...
CVE-2016-8235——Privilege escalation in Lenovo Customer Care Software Development Kit (CCSDK) versions earlier than 2.0.16.3 allows loca...
CVE-2016-10323——Synology Photo Station before 6.3-2958 allows local users to gain privileges by leveraging setuid execution of a "synoph...
CVE-2016-10322——Synology Photo Station before 6.3-2958 allows remote authenticated guest users to execute arbitrary commands via shell m...
CVE-2016-6879——The X509_Certificate::allowed_usage function in botan 1.11.x before 1.11.31 might allow attackers to have unspecified im...
CVE-2016-6878——The Curve25519 code in botan before 1.11.31, on systems without a native 128-bit integer type, might allow attackers to ...
CVE-2016-10311——Stack-based buffer overflow in SAP NetWeaver 7.0 through 7.5 allows remote attackers to cause a denial of service () by ...
CVE-2016-10310——Buffer overflow in the MobiLink Synchronization Server component in SAP SQL Anywhere 17 and possibly earlier allows remo...
CVE-2016-6605——Impala in CDH 5.2.0 through 5.7.2 and 5.8.0 allows remote attackers to bypass Setry authorization.
CVE-2016-10321——web2py before 2.14.6 does not properly check if a host is denied before verifying passwords, allowing a remote attacker ...
CVE-2016-6534——Opmantek NMIS before 4.3.7c has command injection via man, finger, ping, trace, and nslookup in the tools.pl CGI script....
CVE-2016-5642——Opmantek NMIS before 8.5.12G has XSS via SNMP.
CVE-2016-5078——Paessler PRTG before 16.2.24.4045 has XSS via SNMP.
CVE-2016-5077——Netikus EventSentry before 3.2.1.44 has XSS via SNMP.
CVE-2016-5076——CloudView NMS before 2.10a allows remote attackers to obtain sensitive information via a direct request for admin/auto.d...
CVE-2016-5075——CloudView NMS before 2.10a has XSS via a TELNET login.
CVE-2016-5074——CloudView NMS before 2.10a has a format string issue exploitable over SNMP.
CVE-2016-5073——CloudView NMS before 2.10a has XSS via SNMP.
CVE-2016-5072——OXID eShop before 2016-06-13 allows remote attackers to execute arbitrary code via a GET or POST request to the oxuser c...
CVE-2016-5071——Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 execute the management web application as root.
CVE-2016-5070——Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 store passwords in cleartext.
CVE-2016-5069——Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 use guessable session tokens, which are in the URL.

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now