2016 CVE Vulnerabilities

10,647 CVEs published in 2016.

CVE IDSeverityCVSSDescription
CVE-2016-10321web2py before 2.14.6 does not properly check if a host is denied before verifying passwords, allowing a remote attacker ...
CVE-2016-10304MEDIUM6.5The SAP EP-RUNTIME component in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to cause a denial of service...
CVE-2016-6534Opmantek NMIS before 4.3.7c has command injection via man, finger, ping, trace, and nslookup in the tools.pl CGI script....
CVE-2016-5682MEDIUM6.1Swagger-UI before 2.2.1 has XSS via the Default field in the Definitions section.
CVE-2016-5642Opmantek NMIS before 8.5.12G has XSS via SNMP.
CVE-2016-5078Paessler PRTG before 16.2.24.4045 has XSS via SNMP.
CVE-2016-5077Netikus EventSentry before 3.2.1.44 has XSS via SNMP.
CVE-2016-5076CloudView NMS before 2.10a allows remote attackers to obtain sensitive information via a direct request for admin/auto.d...
CVE-2016-5075CloudView NMS before 2.10a has XSS via a TELNET login.
CVE-2016-5074CloudView NMS before 2.10a has a format string issue exploitable over SNMP.
CVE-2016-5073CloudView NMS before 2.10a has XSS via SNMP.
CVE-2016-5072OXID eShop before 2016-06-13 allows remote attackers to execute arbitrary code via a GET or POST request to the oxuser c...
CVE-2016-5071Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 execute the management web application as root.
CVE-2016-5070Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 store passwords in cleartext.
CVE-2016-5069Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 use guessable session tokens, which are in the URL.
CVE-2016-5068Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 do not require authentication for Embedded_Ace_Get_Task.cgi req...
CVE-2016-5067Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 allow Hayes AT command injection.
CVE-2016-5066Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 have weak passwords for admin, rauser, sconsole, and user.
CVE-2016-5065Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 allow Embedded_Ace_Set_Task.cgi command injection.
CVE-2016-5059OSRAM SYLVANIA Osram Lightify Pro before 2016-07-26 allows attackers to obtain sensitive information by reading screensh...
CVE-2016-5058OSRAM SYLVANIA Osram Lightify Pro through 2016-07-26 allows Zigbee replay.
CVE-2016-5057OSRAM SYLVANIA Osram Lightify Pro through 2016-07-26 does not use SSL pinning.
CVE-2016-5056OSRAM SYLVANIA Osram Lightify Pro before 2016-07-26 uses only 8 hex digits for a PSK.
CVE-2016-5055OSRAM SYLVANIA Osram Lightify Pro before 2016-07-26 has XSS in the username field and Wireless Client Mode configuration...
CVE-2016-5054OSRAM SYLVANIA Osram Lightify Home through 2016-07-26 allows Zigbee replay.

Check if your code is affected by 2016 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now