2016 CVE Vulnerabilities
10,647 CVEs published in 2016.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2016-10321 | — | — | 2.6% | Apr 10, 2017 | web2py before 2.14.6 does not properly check if a host is denied before verifying passwords, allowing a remote attacker ... |
| CVE-2016-10304 | MEDIUM | 6.5 | 1.6% | Apr 10, 2017 | The SAP EP-RUNTIME component in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to cause a denial of service... |
| CVE-2016-6534 | — | — | 1.3% | Apr 10, 2017 | Opmantek NMIS before 4.3.7c has command injection via man, finger, ping, trace, and nslookup in the tools.pl CGI script.... |
| CVE-2016-5682 | MEDIUM | 6.1 | 1.0% | Apr 10, 2017 | Swagger-UI before 2.2.1 has XSS via the Default field in the Definitions section. |
| CVE-2016-5642 | — | — | 0.5% | Apr 10, 2017 | Opmantek NMIS before 8.5.12G has XSS via SNMP. |
| CVE-2016-5078 | — | — | 0.7% | Apr 10, 2017 | Paessler PRTG before 16.2.24.4045 has XSS via SNMP. |
| CVE-2016-5077 | — | — | 0.6% | Apr 10, 2017 | Netikus EventSentry before 3.2.1.44 has XSS via SNMP. |
| CVE-2016-5076 | — | — | 1.4% | Apr 10, 2017 | CloudView NMS before 2.10a allows remote attackers to obtain sensitive information via a direct request for admin/auto.d... |
| CVE-2016-5075 | — | — | 0.7% | Apr 10, 2017 | CloudView NMS before 2.10a has XSS via a TELNET login. |
| CVE-2016-5074 | — | — | 1.3% | Apr 10, 2017 | CloudView NMS before 2.10a has a format string issue exploitable over SNMP. |
| CVE-2016-5073 | — | — | 0.7% | Apr 10, 2017 | CloudView NMS before 2.10a has XSS via SNMP. |
| CVE-2016-5072 | — | — | 1.9% | Apr 10, 2017 | OXID eShop before 2016-06-13 allows remote attackers to execute arbitrary code via a GET or POST request to the oxuser c... |
| CVE-2016-5071 | — | — | 1.7% | Apr 10, 2017 | Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 execute the management web application as root. |
| CVE-2016-5070 | — | — | 1.3% | Apr 10, 2017 | Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 store passwords in cleartext. |
| CVE-2016-5069 | — | — | 1.3% | Apr 10, 2017 | Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 use guessable session tokens, which are in the URL. |
| CVE-2016-5068 | — | — | 1.6% | Apr 10, 2017 | Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 do not require authentication for Embedded_Ace_Get_Task.cgi req... |
| CVE-2016-5067 | — | — | 3.6% | Apr 10, 2017 | Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 allow Hayes AT command injection. |
| CVE-2016-5066 | — | — | 1.8% | Apr 10, 2017 | Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 have weak passwords for admin, rauser, sconsole, and user. |
| CVE-2016-5065 | — | — | 2.8% | Apr 10, 2017 | Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 allow Embedded_Ace_Set_Task.cgi command injection. |
| CVE-2016-5059 | — | — | 1.2% | Apr 10, 2017 | OSRAM SYLVANIA Osram Lightify Pro before 2016-07-26 allows attackers to obtain sensitive information by reading screensh... |
| CVE-2016-5058 | — | — | 1.1% | Apr 10, 2017 | OSRAM SYLVANIA Osram Lightify Pro through 2016-07-26 allows Zigbee replay. |
| CVE-2016-5057 | — | — | 1.2% | Apr 10, 2017 | OSRAM SYLVANIA Osram Lightify Pro through 2016-07-26 does not use SSL pinning. |
| CVE-2016-5056 | — | — | 0.9% | Apr 10, 2017 | OSRAM SYLVANIA Osram Lightify Pro before 2016-07-26 uses only 8 hex digits for a PSK. |
| CVE-2016-5055 | — | — | 0.8% | Apr 10, 2017 | OSRAM SYLVANIA Osram Lightify Pro before 2016-07-26 has XSS in the username field and Wireless Client Mode configuration... |
| CVE-2016-5054 | — | — | 1.1% | Apr 10, 2017 | OSRAM SYLVANIA Osram Lightify Home through 2016-07-26 allows Zigbee replay. |
Check if your code is affected by 2016 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now