2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-5068 | — | — | 1.6% | Apr 10, 2017 | Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 do not require authentication for Embedded_Ace_Get_Task.cgi req... |
| CVE-2016-5067 | — | — | 3.6% | Apr 10, 2017 | Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 allow Hayes AT command injection. |
| CVE-2016-5066 | — | — | 1.8% | Apr 10, 2017 | Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 have weak passwords for admin, rauser, sconsole, and user. |
| CVE-2016-5065 | — | — | 2.8% | Apr 10, 2017 | Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 allow Embedded_Ace_Set_Task.cgi command injection. |
| CVE-2016-5059 | — | — | 1.2% | Apr 10, 2017 | OSRAM SYLVANIA Osram Lightify Pro before 2016-07-26 allows attackers to obtain sensitive information by reading screensh... |
| CVE-2016-5058 | — | — | 1.1% | Apr 10, 2017 | OSRAM SYLVANIA Osram Lightify Pro through 2016-07-26 allows Zigbee replay. |
| CVE-2016-5057 | — | — | 1.2% | Apr 10, 2017 | OSRAM SYLVANIA Osram Lightify Pro through 2016-07-26 does not use SSL pinning. |
| CVE-2016-5056 | — | — | 0.9% | Apr 10, 2017 | OSRAM SYLVANIA Osram Lightify Pro before 2016-07-26 uses only 8 hex digits for a PSK. |
| CVE-2016-5055 | — | — | 0.8% | Apr 10, 2017 | OSRAM SYLVANIA Osram Lightify Pro before 2016-07-26 has XSS in the username field and Wireless Client Mode configuration... |
| CVE-2016-5054 | — | — | 1.1% | Apr 10, 2017 | OSRAM SYLVANIA Osram Lightify Home through 2016-07-26 allows Zigbee replay. |
| CVE-2016-5053 | — | — | 2.7% | Apr 10, 2017 | OSRAM SYLVANIA Osram Lightify Home before 2016-07-26 allows remote attackers to execute arbitrary commands via TCP port ... |
| CVE-2016-5052 | — | — | 1.1% | Apr 10, 2017 | OSRAM SYLVANIA Osram Lightify Home through 2016-07-26 does not use SSL pinning. |
| CVE-2016-5051 | — | — | 1.4% | Apr 10, 2017 | OSRAM SYLVANIA Osram Lightify Home before 2016-07-26 stores a PSK in cleartext under /private/var/mobile/Containers/Data... |
| CVE-2016-4320 | — | — | 1.8% | Apr 10, 2017 | Atlassian Bitbucket Server before 4.7.1 allows remote attackers to read the first line of an arbitrary file via a direct... |
| CVE-2016-4319 | — | — | 0.7% | Apr 10, 2017 | Atlassian JIRA Server before 7.1.9 has CSRF in auditing/settings. |
| CVE-2016-4318 | — | — | 0.8% | Apr 10, 2017 | Atlassian JIRA Server before 7.1.9 has XSS in project/ViewDefaultProjectRoleActors.jspa via a role name. |
| CVE-2016-4317 | — | — | 0.7% | Apr 10, 2017 | Atlassian Confluence Server before 5.9.11 has XSS on the viewmyprofile.action page. |
| CVE-2016-1517 | — | — | 1.0% | Apr 10, 2017 | OpenCV 3.0.0 allows remote attackers to cause a denial of service (segfault) via vectors involving corrupt chunks. |
| CVE-2016-7786 | — | — | 7.0% | Apr 7, 2017 | Sophos Cyberoam UTM CR25iNG 10.6.3 MR-5 allows remote authenticated users to bypass intended access restrictions via dir... |
| CVE-2016-6805 | — | — | 2.0% | Apr 7, 2017 | Apache Ignite before 1.9 allows man-in-the-middle attackers to read arbitrary files via XXE in modified update-notifier ... |
| CVE-2016-9197 | — | — | 0.3% | Apr 7, 2017 | A vulnerability in the CLI command parser of the Cisco Mobility Express 2800 and 3800 Series Wireless LAN Controllers co... |
| CVE-2016-9196 | — | — | 0.4% | Apr 7, 2017 | A vulnerability in login authentication management in Cisco Aironet 1800, 2800, and 3800 Series Access Point platforms c... |
| CVE-2016-9195 | — | — | 2.0% | Apr 7, 2017 | A vulnerability in RADIUS Change of Authorization (CoA) request processing in the Cisco Wireless LAN Controller (WLC) co... |
| CVE-2016-1000307 | — | — | 0.8% | Apr 6, 2017 | Multiple Cross Site Scripting (XSS) Vulnerabilities in ClipBucket v2.8.1 and probably prior allow Remote Attackers to in... |
| CVE-2016-1000306 | — | — | — | Apr 6, 2017 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-1000307. Reason: This candidate is a reservatio... |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now