Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 10.0
CVE-2026-15409 KEVEPSS 74%
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attack…
Sma6210 Firmware
Mitigation only
HIGH 7.2
CVE-2026-15410 KEVEPSS 76%
Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management C…
Sma6210 Firmware
Mitigation only
CRITICAL 9.8
CVE-2024-22394
An improper authentication vulnerability has been identified in SonicWall SonicOS SSL-VPN feature, which in specific conditions could allow a remote …
Sonicos
Mitigation only
HIGH 7.5
CVE-2023-0126EPSS 73%
Pre-authentication path traversal vulnerability in SMA1000 firmware version 12.4.2, which allows an unauthenticated attacker to access arbitrary file…
Sma1000 Firmware
Mitigation only
CRITICAL 9.8
CVE-2022-22282EPSS 8%
SonicWall SMA1000 series firmware 12.4.0, 12.4.1-02965 and earlier versions incorrectly restricts access to a resource using HTTP connections from an…
Sma 6200 Firmware
Mitigation only
HIGH 7.5
CVE-2022-1701
SonicWall SMA1000 series firmware 12.4.0, 12.4.1-02965 and earlier versions uses a shared and hard-coded encryption key to store data.
Sma 6200 Firmware
Mitigation only
MEDIUM 6.1
CVE-2022-1702EPSS 9%
SonicWall SMA1000 series firmware 12.4.0, 12.4.1-02965 and earlier versions accept a user-controlled input that specifies a link to an external site …
Sma 6200 Firmware
Mitigation only
CRITICAL 9.8
CVE-2021-20042
An unauthenticated remote attacker can use SMA 100 as an unintended proxy or intermediary undetectable proxy to bypass firewall rules. This vulnerabi…
Sma 200 Firmware
Mitigation only
CRITICAL 9.8
CVE-2021-20045EPSS 25%
A buffer overflow vulnerability in SMA100 sonicfiles RAC_COPY_TO (RacNumber 36) method allows a remote unauthenticated attacker to potentially execut…
Sma 200 Firmware
Mitigation only
HIGH 8.8
CVE-2021-20043EPSS 23%
A Heap-based buffer overflow vulnerability in SonicWall SMA100 getBookmarks method allows a remote authenticated attacker to potentially execute code…
Sma 200 Firmware
Mitigation only
HIGH 8.8
CVE-2021-20044EPSS 40%
A post-authentication remote command injection vulnerability in SonicWall SMA100 allows a remote authenticated attacker to execute OS system commands…
Sma 200 Firmware
Mitigation only
HIGH 7.5
CVE-2021-20041EPSS 7%
An unauthenticated and remote adversary can consume all of the device's CPU due to crafted HTTP requests sent to SMA100 /fileshare/sonicfiles/sonicfi…
Sma 200 Firmware
Mitigation only
CRITICAL 9.8
CVE-2021-20038 KEVEPSS 100%
A Stack-based buffer overflow vulnerability in SMA100 Apache httpd server's mod_cgi module environment variables allows a remote unauthenticated atta…
Sma 200 Firmware
Mitigation only
HIGH 8.8
CVE-2021-20039EPSS 78%
Improper neutralization of special elements in the SMA100 management interface '/cgi-bin/viewcert' POST http method allows a remote authenticated att…
Sma 200 Firmware
No fix yet
HIGH 7.5
CVE-2021-20040EPSS 26%
A relative path traversal vulnerability in the SMA100 upload funtion allows a remote unauthenticated attacker to upload crafted web pages or files as…
Sma 200 Firmware
Mitigation only
CRITICAL 9.8
CVE-2021-20020
A command execution vulnerability in SonicWall GMS 9.3 allows a remote unauthenticated attacker to locally escalate privilege to root.
Global Management System
Mitigation only
MEDIUM 5.3
CVE-2020-5132
SonicWall SSL-VPN products and SonicWall firewall SSL-VPN feature misconfiguration leads to possible DNS flaw known as domain name collision vulnerab…
Sma100 Firmware
Mitigation only
CRITICAL 9.8
CVE-2013-1359EPSS 89%
An Authentication Bypass Vulnerability exists in DELL SonicWALL Analyzer 7.0, Global Management System (GMS) 4.1, 5.0, 5.1, 6.0, and 7.0; Universal M…
Analyzer
No fix yet
CRITICAL 9.8
CVE-2013-1360EPSS 23%
An Authentication Bypass vulnerability exists in DELL SonicWALL Global Management System (GMS) 4.1, 5.0, 5.1, 6.0, and 7.0, Analyzer 7.0, Universal M…
Analyzer
No fix yet
CRITICAL 9.8
CVE-2019-7478
A vulnerability in GMS allow unauthenticated user to SQL injection in Webservice module. This vulnerability affected GMS versions GMS 8.4, 8.5, 8.6, …
Global Management System
Mitigation only
MEDIUM 5.4
CVE-2018-5280
SonicWall SonicOS on Network Security Appliance (NSA) 2016 Q4 devices has XSS via the Configure SSO screens.
Sonicos
No fix yet
MEDIUM 5.4
CVE-2018-5281
SonicWall SonicOS on Network Security Appliance (NSA) 2017 Q4 devices has XSS via the CFS Custom Category and Cloud AV DB Exclusion Settings screens.
Sonicos
No fix yet
CRITICAL 9.8
CVE-2016-2397EPSS 6%
The cliserver implementation in Dell SonicWALL GMS, Analyzer, and UMA EM5000 7.2, 8.0, and 8.1 before Hotfix 168056 allows remote attackers to deseri…
Uma Em5000 Firmware
Mitigation only
CRITICAL 9.9
CVE-2016-2396
The GMS ViewPoint (GMSVP) web application in Dell SonicWALL GMS, Analyzer, and UMA EM5000 7.2, 8.0, and 8.1 before Hotfix 168056 allows remote authen…
Analyzer
Mitigation only
HIGH 9.0
CVE-2014-8420EPSS 24%
The ViewPoint web application in Dell SonicWALL Global Management System (GMS) before 7.2 SP2, SonicWALL Analyzer before 7.2 SP2, and SonicWALL UMA b…
Analyzer
Mitigation only
MEDIUM 6.5
CVE-2014-4977EPSS 75%
Multiple SQL injection vulnerabilities in Dell SonicWall Scrutinizer 11.0.1 allow remote authenticated users to execute arbitrary SQL commands via th…
Scrutinizer
No fix yet
MEDIUM 5.5
CVE-2014-4976
Dell SonicWall Scrutinizer 11.0.1 allows remote authenticated users to change user passwords via the user ID in the savePrefs parameter in a change p…
Scrutinizer
No fix yet
HIGH 7.5
CVE-2011-5262
SQL injection vulnerability in prodpage.cfm in SonicWALL Aventail allows remote attackers to execute arbitrary SQL commands via the CategoryID parame…
Aventail Sra Ex Virtual Appliance
No fix yet
HIGH 9.3
CVE-2007-6273EPSS 6%
Multiple format string vulnerabilities in the configuration file in SonicWALL GLobal VPN Client 3.1.556 and 4.0.0.810 allow user-assisted remote atta…
Global Vpn Client
No fix yet
HIGH 7.8
CVE-2003-1490
SonicWall Pro running firmware 6.4.0.1 allows remote attackers to cause a denial of service (device reset) via a long HTTP POST to the internal inter…
Pro100
Mitigation only