Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
CRITICAL 9.8
CVE-2023-34124EPSS 46%
The authentication mechanism in SonicWall GMS and Analytics Web Services had insufficient checks, allowing authentication bypass. This issue affects …
Analytics
9.3.2+
CRITICAL 9.8
CVE-2023-34128
Tomcat application credentials are hardcoded in SonicWall GMS and Analytics configuration file. This issue affects GMS: 9.3.2-SP1 and earlier version…
Analytics
9.3.2+
HIGH 8.8
CVE-2023-34126
Vulnerability in SonicWall GMS and Analytics allows an authenticated attacker to upload files on the underlying filesystem with root privileges. This…
Analytics
9.3.2+
HIGH 8.8
CVE-2023-34127EPSS 86%
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in SonicWall GMS, SonicWall Analytics enable…
Analytics
9.3.2+
MEDIUM 6.5
CVE-2023-34125EPSS 25%
Path Traversal vulnerability in GMS and Analytics allows an authenticated attacker to read arbitrary files from the underlying filesystem with root p…
Analytics
9.3.2+
HIGH 7.5
CVE-2023-34123
Use of Hard-coded Cryptographic Key vulnerability in SonicWall GMS, SonicWall Analytics. This issue affects GMS: 9.3.2-SP1 and earlier versions; Anal…
Global Management System
2.5.0.4 / 9.3.2+
HIGH 8.8
CVE-2023-1101
SonicOS SSLVPN improper restriction of excessive MFA attempts vulnerability allows an authenticated attacker to use excessive MFA codes.
Sonicos
7.0.1-5111+
HIGH 7.5
CVE-2023-0656EPSS 41%
A Stack-based buffer overflow vulnerability in the SonicOS allows a remote unauthenticated attacker to cause Denial of Service (DoS), which could cau…
Sonicos
after 7.0.1-5111
MEDIUM 5.3
CVE-2023-0655
SonicWall Email Security contains a vulnerability that could permit a remote unauthenticated attacker access to an error page that includes sensitive…
Email Security
after 10.0.19.7431
HIGH 7.5
CVE-2023-0126EPSS 73%
Pre-authentication path traversal vulnerability in SMA1000 firmware version 12.4.2, which allows an unauthenticated attacker to access arbitrary file…
Sma1000 Firmware
Mitigation only
HIGH 7.5
CVE-2021-20030
SonicWall GMS is vulnerable to file path manipulation resulting that an unauthenticated attacker can gain access to web directory containing applicat…
Global Management System
9.3.2+
HIGH 8.8
CVE-2022-2915
A Heap-based Buffer Overflow vulnerability in the SonicWall SMA100 appliance allows a remote authenticated attacker to cause Denial of Service (DoS) …
Sma 200 Firmware
after 10.2.1.5-34sv
CRITICAL 9.8
CVE-2022-22280EPSS 10%
Improper Neutralization of Special Elements used in an SQL Command leading to Unauthenticated SQL Injection vulnerability, impacting SonicWall GMS 9.…
Analytics
9.3.1+
HIGH 7.5
CVE-2022-2324
Improperly Implemented Security Check vulnerability in the SonicWall Hosted Email Security leads to bypass of Capture ATP security service in the app…
Hosted Email Security
after 10.0.17.7319
HIGH 8.8
CVE-2022-2323EPSS 6%
Improper neutralization of special elements used in a user input allows an authenticated malicious user to perform remote code execution in the host …
Sws12 10fpoe Firmware
1.2.0.0-3+
HIGH 8.8
CVE-2022-1703EPSS 12%
Improper neutralization of special elements in the SonicWall SSL-VPN SMA100 series management interface allows a remote authenticated attacker to inj…
Sma 210 Firmware
after 10.2.1.4-31sv
CRITICAL 9.8
CVE-2022-22282EPSS 8%
SonicWall SMA1000 series firmware 12.4.0, 12.4.1-02965 and earlier versions incorrectly restricts access to a resource using HTTP connections from an…
Sma 6200 Firmware
Mitigation only
HIGH 7.8
CVE-2022-22281
A buffer overflow vulnerability in the SonicWall SSL-VPN NetExtender Windows Client (32 and 64 bit) in 10.2.322 and earlier versions, allows an attac…
Netextender
after 10.2.322
HIGH 7.5
CVE-2022-1701
SonicWall SMA1000 series firmware 12.4.0, 12.4.1-02965 and earlier versions uses a shared and hard-coded encryption key to store data.
Sma 6200 Firmware
Mitigation only
MEDIUM 6.1
CVE-2022-1702EPSS 9%
SonicWall SMA1000 series firmware 12.4.0, 12.4.1-02965 and earlier versions accept a user-controlled input that specifies a link to an external site …
Sma 6200 Firmware
Mitigation only
HIGH 7.8
CVE-2021-20051
SonicWall Global VPN Client 4.10.7.1117 installer (32-bit and 64-bit) and earlier versions have a DLL Search Order Hijacking vulnerability in one of …
Global Vpn Client
after 4.10.7.1117
HIGH 7.5
CVE-2022-22275
Improper Restriction of TCP Communication Channel in HTTP/S inbound traffic from WAN to DMZ bypassing security policy until TCP handshake potentially…
Sonicos
after 7.0.1-5030-r2007
HIGH 7.5
CVE-2022-22278
A vulnerability in SonicOS CFS (Content filtering service) returns a large 403 forbidden HTTP response message to the source address when users try t…
Tz300p Firmware
7.0.1 / 7.0.1.0+
MEDIUM 5.3
CVE-2022-22276
A vulnerability in SonicOS SNMP service resulting exposure of sensitive information to an unauthorized user.
Tz300p Firmware
7.0.1 / 7.0.1.0+
MEDIUM 5.3
CVE-2022-22277
A vulnerability in SonicOS SNMP service resulting exposure of Wireless Access Point sensitive information in cleartext.
Tz300p Firmware
6.5.4.10 / 7.0.1.0+
CRITICAL 9.8
CVE-2022-22274EPSS 58%
A Stack-based buffer overflow vulnerability in the SonicOS via HTTP request allows a remote unauthenticated attacker to cause Denial of Service (DoS)…
Sonicos
after 7.0.1-5050
CRITICAL 9.8
CVE-2022-22273
Improper neutralization of Special Elements leading to OS Command Injection vulnerability impacting end-of-life Secure Remote Access (SRA) products a…
Sma 200 Firmware
after 9.0.0.9-26sv
HIGH 8.8
CVE-2021-20046
A Stack-based buffer overflow in the SonicOS HTTP Content-Length response header allows a remote authenticated attacker to cause Denial of Service (D…
Sonicos
after 7.0.1-5023-1349
HIGH 8.8
CVE-2021-20048
A Stack-based buffer overflow in the SonicOS SessionID HTTP response header allows a remote authenticated attacker to cause Denial of Service (DoS) a…
Sonicos
after 7.0.1-5023-1349
HIGH 7.5
CVE-2021-20049
A vulnerability in SonicWall SMA100 password change API allows a remote unauthenticated attacker to perform SMA100 username enumeration based on the …
Sma 100 Firmware
10.0.0.0+