Vulnerability index

Browse CVEs

183 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 10.0 CVE-2026-15409 KEVEPSS 74% A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attack… Sma6210 Firmware Mitigation only Fix from $2,3002026-07-14 HIGH 7.2 CVE-2026-15410 KEVEPSS 76% Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management C… Sma6210 Firmware Mitigation only Fix from $1,9502026-07-14 HIGH 8.0 CVE-2026-0204 A vulnerability in the access control mechanism of SonicOS may allow certain management interface functions to be accessible under specific condition… Sonicos 6.5.5.2-28n / 7.3.2-7010+ Fix from $1,9502026-04-29 MEDIUM 6.8 CVE-2026-0205 A post-authentication Path Traversal vulnerability in SonicOS allows an attacker to interact with usually restricted services. Sonicos 6.5.5.2-28n / 7.3.2-7010+ Fix from $1,6002026-04-29 HIGH 7.2 CVE-2026-4116 Improper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote authenticated SSLVPN user to bypass Workplace/Connect Tu… Sma6210 Firmware 12.4.3-03387 / 12.5.0-02624+ Fix from $1,9502026-04-09 HIGH 7.2 CVE-2026-4112 Improper neutralization of special elements used in an SQL command (“SQL Injection”) in SonicWall SMA1000 series appliances allows a remote authentic… Sma6210 Firmware 12.4.3-03387 / 12.5.0-02624+ Fix from $1,9502026-04-09 HIGH 7.2 CVE-2026-4113 An observable response discrepancy vulnerability in the SonicWall SMA1000 series appliances allows a remote attacker to enumerate SSL VPN user creden… Sma6210 Firmware 12.4.3-03387 / 12.5.0-02624+ Fix from $1,9502026-04-09 MEDIUM 6.6 CVE-2026-4114 Improper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote authenticated SSLVPN admin to bypass AMC TOTP authentica… Sma6210 Firmware 12.4.3-03387 / 12.5.0-02624+ Fix from $1,6002026-04-09 MEDIUM 6.6 CVE-2025-40602 KEV A local privilege escalation vulnerability due to insufficient authorization in the SonicWall SMA1000 appliance management console (AMC). Sma6200 Firmware 12.4.3-03245 / 12.5.0-02283+ Fix from $1,6002025-12-18 CRITICAL 9.8 CVE-2025-40604 Download of Code Without Integrity Check Vulnerability in the SonicWall Email Security appliance loads root filesystem images without verifying signa… Email Security Appliance 5000 Firmware after 10.0.33.8195 Fix from $2,3002025-11-20 HIGH 7.5 CVE-2025-40601 A Stack-based buffer overflow vulnerability in the SonicOS SSLVPN service allows a remote unauthenticated attacker to cause Denial of Service (DoS), … Sonicos 7.3.1-7013 / 8.0.3-8011+ Fix from $1,9502025-11-20 MEDIUM 5.3 CVE-2025-40605 A Path Traversal vulnerability has been identified in the Email Security appliance allows an attacker to manipulate file system paths by injecting cr… Email Security Appliance 5000 Firmware after 10.0.33.8195 Fix from $1,6002025-11-20 CRITICAL 9.8 CVE-2025-40600 Use of Externally-Controlled Format String vulnerability in the SonicOS SSL VPN interface allows a remote unauthenticated attacker to cause service d… Sonicos 7.3.0-7012+ Fix from $2,3002025-07-29 HIGH 7.5 CVE-2025-40597EPSS 28% A Heap-based buffer overflow vulnerability in the SMA100 series web interface allows remote, unauthenticated attacker to cause Denial of Service (DoS… Sma 500v Firmware 10.2.2.1-90sv+ Fix from $1,9502025-07-23 HIGH 7.3 CVE-2025-40596EPSS 52% A Stack-based buffer overflow vulnerability in the SMA100 series web interface allows remote, unauthenticated attacker to cause Denial of Service (Do… Sma 500v Firmware 10.2.2.1-90sv+ Fix from $1,9502025-07-23 MEDIUM 6.1 CVE-2025-40598EPSS 55% A Reflected cross-site scripting (XSS) vulnerability exists in the SMA100 series web interface, allowing a remote unauthenticated attacker to potenti… Sma 500v Firmware 10.2.2.1-90sv+ Fix from $1,6002025-07-23 CRITICAL 9.1 CVE-2025-40599EPSS 10% An authenticated arbitrary file upload vulnerability exists in the SMA 100 series web management interface. A remote attacker with administrative pri… Sma 210 Firmware 10.2.2.1-90sv+ Fix from $2,3002025-07-23 HIGH 8.8 CVE-2025-32819EPSS 6% A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN user privileges to bypass the path traversal checks and delete an arbitr… Sma 100 Firmware 10.2.1.15-81sv+ Fix from $1,9502025-05-07 HIGH 8.8 CVE-2025-32820 A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN user privileges can inject a path traversal sequence to make any directo… Sma 100 Firmware 10.2.1.15-81sv+ Fix from $1,9502025-05-07 HIGH 7.2 CVE-2025-32821EPSS 20% A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN admin privileges can with admin privileges can inject shell command argu… Sma 100 Firmware 10.2.1.15-81sv+ Fix from $1,9502025-05-07 HIGH 7.2 CVE-2025-2170 A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface, which in specific conditions co… Sma1000 Firmware 12.4.3-02925+ Fix from $1,9502025-04-30 CRITICAL 9.8 CVE-2025-23006 KEVEPSS 23% Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and Central … Sma8200v 12.4.3-02854+ Fix from $2,3002025-01-23 CRITICAL 9.8 CVE-2024-53704 KEVEPSS 95% An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication. Sonicos after 7.1.1-7058 Fix from $2,3002025-01-09 HIGH 8.1 CVE-2024-53703EPSS 13% A vulnerability in the SonicWall SMA100 SSLVPN firmware 10.2.1.13-72sv and earlier versions mod_httprp library loaded by the Apache web server allows… Sma 200 Firmware 10.2.1.14-75sv+ Fix from $1,9502024-12-05 HIGH 8.1 CVE-2024-45318 A vulnerability in the SonicWall SMA100 SSLVPN web management interface allows remote attackers to cause Stack-based buffer overflow and potentially … Sma 200 Firmware 10.2.1.14-75sv+ Fix from $1,9502024-12-05 MEDIUM 6.3 CVE-2024-45319 A vulnerability in the SonicWall SMA100 SSLVPN firmware 10.2.1.13-72sv and earlier versions allows a remote authenticated attacker can circumvent t… Sma 200 Firmware 10.2.1.14-75sv+ Fix from $1,6002024-12-05 MEDIUM 5.3 CVE-2024-53702 Use of cryptographically weak pseudo-random number generator (PRNG) vulnerability in the SonicWall SMA100 SSLVPN backup code generator that, in certa… Sma 200 Firmware 10.2.1.14-75sv+ Fix from $1,6002024-12-05 HIGH 7.5 CVE-2024-40763 Heap-based buffer overflow vulnerability in the SonicWall SMA100 SSLVPN due to the use of strcpy. This allows remote authenticated attackers to cause… Sma 200 Firmware 10.2.1.14-75sv+ Fix from $1,9502024-12-05 CRITICAL 9.8 CVE-2024-40766 KEVEPSS 18% An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource… Sonicos 5.9.2.14-13o / 6.5.2.8-2n+ Fix from $2,3002024-08-23 HIGH 8.8 CVE-2024-29014 Vulnerability in SonicWall SMA100 NetExtender Windows (32 and 64-bit) client 10.2.339 and earlier versions allows an attacker to arbitrary code execu… Netextender 10.2.341+ Fix from $1,9502024-07-18