CWE-16
100 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-16page 1 of 2
- CVE-2003-1357HIGHCVSS v2 10.0EG 10.02003-12-31
ProxyView has a default administrator password of Administrator for Embedded Windows NT, which allows remote attackers to gain access.
- CVE-2003-1422HIGHCVSS v2 10.0EG 10.02003-12-31
Multiple unspecified vulnerabilities in the installer for SYSLINUX 2.01, when running setuid root, allow local users to gain privileges via unknown vectors.
- CVE-2024-46909CRITICALCVSS 9.8EG 9.82024-12-02
In WhatsUp Gold versions released before 2024.0.1, a remote unauthenticated attacker could leverage this vulnerability to execute code in the context of the service account.
- CVE-2018-11922CRITICALCVSS 9.8EG 9.82024-11-26
Wrong configuration in Touch Pal application can collect user behavior data without awareness by the user.
- CVE-2021-20032CRITICALCVSS 9.8EG 9.82021-08-10
SonicWall Analytics 2.5 On-Prem is vulnerable to Java Debug Wire Protocol (JDWP) interface security misconfiguration vulnerability which potentially leads to Remote Code Execution. This vulnerability impacts Analytics On-Prem 2.5.2518 and …
- CVE-2019-3949CRITICALCVSS 9.8EG 9.82019-07-09
Arlo Basestation firmware 1.12.0.1_27940 and prior firmware contain a networking misconfiguration that allows access to restricted network interfaces. This could allow an attacker to upload or download arbitrary files and possibly execute …
- CVE-2019-3939CRITICALCVSS 9.8EG 9.82019-04-30
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 use default credentials admin/admin and moderator/moderator for the web interface. An unauthenticated, remote attacker can use these credentials to gain privileged acce…
- CVE-2018-15386CRITICALCVSS 9.8EG 9.82018-10-05
A vulnerability in Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, remote attacker to bypass authentication and have direct unauthorized access to critical management functions. The vulnerability is due to a…
- CVE-2015-9197CRITICALCVSS 9.8EG 9.82018-04-18
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9635M, MDM9640, MDM9645, MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 615/16/SD 415, SD 617, SD 65…
- CVE-2016-10388CRITICALCVSS 9.8EG 9.82017-08-18
In all Qualcomm products with Android releases from CAF using the Linux kernel, a configuration vulnerability exists when loading a 3rd-party QTEE application.
- CVE-2017-6639CRITICALCVSS 9.8EG 9.82017-06-08
A vulnerability in the role-based access control (RBAC) functionality of Cisco Prime Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to access sensitive information or execute arbitrary code with root pri…
- CVE-2022-37397CRITICALCVSS 8.3EG 9.82022-08-12
An issue was discovered in the YugabyteDB 2.6.1 when using LDAP-based authentication in YCQL with Microsoft’s Active Directory. When anonymous or unauthenticated LDAP binding is enabled, it allows bypass of authentication with an empty p…
- CVE-2022-43516CRITICALCVSS 6.5EG 9.82022-12-05
A Firewall Rule which allows all incoming TCP connections to all programs from any source and to all ports is created in Windows Firewall after Zabbix agent installation (MSI)
- CVE-2022-29095CRITICALCVSS 8.3EG 9.62022-06-10
Dell SupportAssist Client Consumer versions (3.10.4 and prior) and Dell SupportAssist Client Commercial versions (3.1.1 and prior) contain a cross-site scripting vulnerability. A remote unauthenticated malicious user could potentially expl…
- CVE-2004-2687HIGHCVSS v2 9.3EG 9.32004-12-31
distcc 2.x, as used in XCode 1.5 and others, when not configured to restrict access to the server port, allows remote attackers to execute arbitrary commands via compilation jobs, which are executed by the server without authorization chec…
- CVE-2004-2692HIGHCVSS v2 9.3EG 9.32004-12-31
The exec_dir PHP patch (php-exec-dir) 4.3.2 through 4.3.7 with safe mode disabled allows remote attackers to bypass restrictions and execute arbitrary commands via a backtick operator, which is not handled using the php_escape_shell_cmd fu…
- CVE-1999-0766HIGHCVSS v2 9.3EG 9.31999-10-21
The Microsoft Java Virtual Machine allows a malicious Java applet to execute arbitrary commands outside of the sandbox environment.
- CVE-2023-39385CRITICALCVSS 9.1EG 9.12023-08-13
Vulnerability of configuration defects in the media module of certain products.. Successful exploitation of this vulnerability may cause unauthorized access.
- CVE-2017-12249CRITICALCVSS 9.1EG 9.12017-09-13
A vulnerability in the Traversal Using Relay NAT (TURN) server included with Cisco Meeting Server (CMS) could allow an authenticated, remote attacker to gain unauthenticated or unauthorized access to components of or sensitive information …
- CVE-1999-0886HIGHCVSS v2 9.0EG 9.01999-09-17
The security descriptor for RASMAN allows users to point to an alternate location via the Windows NT Service Control Manager.
- CVE-2025-12221HIGHCVSS 8.8EG 8.82025-10-25
Busybox 1.31.1 - Multiple Known Vulnerabilities.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
- CVE-2021-22957HIGHCVSS 8.8EG 8.82021-11-24
A Cross-Origin Resource Sharing (CORS) vulnerability found in UniFi Protect application Version 1.19.2 and earlier allows a malicious actor who has convinced a privileged user to access a URL with malicious code to take over said user’s …
- CVE-2018-0262HIGHCVSS 8.1EG 8.12018-05-02
A vulnerability in Cisco Meeting Server could allow an unauthenticated, remote attacker to gain unauthorized access to components of, or sensitive information in, an affected system, leading to Remote Code Execution. The vulnerability is d…
- CVE-2010-0386HIGHCVSS 8.1EG 8.12010-01-25
The default configuration of Sun Java System Application Server 7 and 7 2004Q2 enables the HTTP TRACE method, which makes it easier for remote attackers to steal cookies and authentication credentials via a cross-site tracing (XST) attack,…
- CVE-2022-33233HIGHCVSS 7.8EG 7.82023-02-12
Memory corruption due to configuration weakness in modem wile sending command to write protected files.
- CVE-2020-8351HIGHCVSS 7.8EG 7.82020-11-30
A privilege escalation vulnerability was reported in Lenovo PCManager prior to version 3.0.50.9162 that could allow an authenticated user to execute code with elevated privileges.
- CVE-2017-3210HIGHCVSS 7.8EG 7.82018-07-24
Applications developed using the Portrait Display SDK, versions 2.30 through 2.34, default to insecure configurations which allow arbitrary code execution. A number of applications developed using the Portrait Displays SDK do not use secur…
- CVE-2022-28762HIGHCVSS 7.3EG 7.82022-10-14
Zoom Client for Meetings for macOS (Standard and for IT Admin) starting with 5.10.6 and prior to 5.12.0 contains a debugging port misconfiguration. When camera mode rendering context is enabled as part of the Zoom App Layers API by running…
- CVE-2019-1585HIGHCVSS 6.7EG 7.82019-03-06
A vulnerability in the controller authorization functionality of Cisco Nexus 9000 Series ACI Mode Switch Software could allow an authenticated, local attacker to escalate standard users with root privilege on an affected device. The vulner…
- CVE-2003-1362HIGHCVSS v2 7.8EG 7.82003-12-31
Bastille B.02.00.00 of HP-UX 11.00 and 11.11 does not properly configure the (1) NOVRFY and (2) NOEXPN options in the sendmail.cf file, which could allow remote attackers to verify the existence of system users and expand defined sendmail …
- CVE-2003-1367HIGHCVSS v2 7.8EG 7.82003-12-31
The which_access variable for Majordomo 2.0 through 1.94.4, and possibly earlier versions, is set to "open" by default, which allows remote attackers to identify the email addresses of members of mailing lists via a "which" command.
- CVE-2024-42031HIGHCVSS 7.5EG 7.52024-08-08
Access permission verification vulnerability in the Settings module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2024-32991HIGHCVSS 7.5EG 7.52024-05-14
Permission verification vulnerability in the wpa_supplicant module Impact: Successful exploitation of this vulnerability will affect availability.
- CVE-2023-33105HIGHCVSS 7.5EG 7.52024-03-04
Transient DOS in WLAN Host and Firmware when large number of open authentication frames are sent with an invalid transaction sequence number.
- CVE-2023-39392HIGHCVSS 7.5EG 7.52023-08-13
Vulnerability of insecure signatures in the OsuLogin module. Successful exploitation of this vulnerability may cause OsuLogin to be maliciously modified and overwritten.
- CVE-2022-22183HIGHCVSS 7.5EG 7.52022-04-14
An Improper Access Control vulnerability in Juniper Networks Junos OS Evolved allows a network-based unauthenticated attacker who is able to connect to a specific open IPv4 port, which in affected releases should otherwise be unreachable, …
- CVE-2020-2041HIGHCVSS 7.5EG 7.52020-09-09
An insecure configuration of the appweb daemon of Palo Alto Networks PAN-OS 8.1 allows a remote unauthenticated user to send a specifically crafted request to the device that causes the appweb service to crash. Repeated attempts to send th…
- CVE-2019-1868HIGHCVSS 7.5EG 7.52019-06-05
A vulnerability in the web-based management interface of Cisco Webex Meetings Server could allow an unauthenticated, remote attacker to access sensitive system information. The vulnerability is due to improper access control to files withi…
- CVE-2018-15448HIGHCVSS 7.5EG 7.52018-11-08
A vulnerability in the user management functions of Cisco Registered Envelope Service could allow an unauthenticated, remote attacker to discover sensitive user information. The attacker could use this information to conduct additional rec…
- CVE-2016-10446HIGHCVSS 7.5EG 7.52018-04-18
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear MDM9206, MDM9650, SD 210/SD 212/SD 205, SD 820, SD 820A, and SD 835, incorrect configuration of the OCIM…
- CVE-2019-19097HIGHCVSS 5.9EG 7.52020-04-02
ABB eSOMS versions 4.0 to 6.0.3 accept connections using medium strength ciphers. If a connection is enabled using such a cipher, an attacker might be able to eavesdrop and/or intercept the connection.
- CVE-2003-1341HIGHCVSS v2 7.5EG 7.52003-12-31
The default installation of Trend Micro OfficeScan 3.0 through 3.54 and 5.x allows remote attackers to bypass authentication from cgiChkMasterPasswd.exe and gain access to the web management console via a direct request to cgiMasterPwd.exe.
- CVE-2003-1449HIGHCVSS v2 7.5EG 7.52003-12-31
Aladdin Knowlege Systems eSafe Gateway 3.5.126.0 does not check the entire stream of Content Vectoring Protocol (CVP) data, which allows remote attackers to bypass virus protection.
- CVE-2003-1491HIGHCVSS v2 7.5EG 7.52003-12-31
Kerio Personal Firewall (KPF) 2.1.4 has a default rule to accept incoming packets from DNS (UDP port 53), which allows remote attackers to bypass the firewall filters via packets with a source port of 53.
- CVE-2002-2373HIGHCVSS v2 7.5EG 7.52002-12-31
The default configuration of the TCP/IP printer configuration utility in Apple LaserWriter 12/640 PS printer contains a blank Telnet password, which allows remote attackers to gain access.
- CVE-1999-0875HIGHCVSS v2 7.5EG 7.51999-08-11
DHCP clients with ICMP Router Discovery Protocol (IRDP) enabled allow remote attackers to modify their default routes.
- CVE-2022-36423HIGHCVSS 7.4EG 7.42022-09-09
OpenHarmony-v3.1.2 and prior versions have an incorrect configuration of the cJSON library, which leads a Stack overflow vulnerability during recursive parsing. LAN attackers can lead a DoS attack to all network devices.
- CVE-2021-0222HIGHCVSS 7.4EG 7.42021-01-15
A vulnerability in Juniper Networks Junos OS allows an attacker to cause a Denial of Service (DoS) to the device by sending certain crafted protocol packets from an adjacent device with invalid payloads to the device. These crafted packets…
- CVE-2018-0263HIGHCVSS 7.4EG 7.42018-06-07
A vulnerability in Cisco Meeting Server (CMS) could allow an unauthenticated, adjacent attacker to access services running on internal device interfaces of an affected system. The vulnerability is due to incorrect default configuration of …
- CVE-2023-43088HIGHCVSS 6.8EG 7.22023-12-22
Dell Client BIOS contains a pre-boot direct memory access (DMA) vulnerability. An authenticated attacker with physical access to the system may potentially exploit this vulnerability in order to execute arbitrary code on the device.
Map vulnerabilities like CWE-16 to your infrastructure
EchelonGraph correlates every CVE — across CWE-16 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →