Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
CRITICAL 9.8
CVE-2019-7475
A vulnerability in SonicWall SonicOS and SonicOSv with management enabled system on specific configuration allow unprivileged user to access advanced…
Sonicosv
after 5.9.1.10
HIGH 7.5
CVE-2019-7477
A vulnerability in SonicWall SonicOS and SonicOSv TLS CBC Cipher allow remote attackers to obtain sensitive plaintext data when CBC cipher suites are…
Sonicosv
after 5.9.1.10
MEDIUM 6.5
CVE-2019-7474
A vulnerability in SonicWall SonicOS and SonicOSv, allow authenticated read-only admin to leave the firewall in an unstable state by downloading cert…
Sonicosv
after 5.9.1.10
MEDIUM 5.5
CVE-2018-9867
In SonicWall SonicOS, administrators without full permissions can download imported certificates. Occurs when administrators who are not in the Sonic…
Sonicosv
after 5.9.1.10
CRITICAL 9.8
CVE-2018-9866
A vulnerability in lack of validation of user-supplied parameters pass to XML-RPC calls on SonicWall Global Management System (GMS) virtual appliance…
Global Management System
after 8.1
MEDIUM 5.4
CVE-2018-5691
SonicWall Global Management System (GMS) 8.1 has XSS via the `newName` and `Name` values of the `/sgms/TreeControl` module.
Analyzer
after 8.4
MEDIUM 5.4
CVE-2018-5280
SonicWall SonicOS on Network Security Appliance (NSA) 2016 Q4 devices has XSS via the Configure SSO screens.
Sonicos
No fix yet
MEDIUM 5.4
CVE-2018-5281
SonicWall SonicOS on Network Security Appliance (NSA) 2017 Q4 devices has XSS via the CFS Custom Category and Cloud AV DB Exclusion Settings screens.
Sonicos
No fix yet
CRITICAL 9.8
CVE-2016-2397EPSS 6%
The cliserver implementation in Dell SonicWALL GMS, Analyzer, and UMA EM5000 7.2, 8.0, and 8.1 before Hotfix 168056 allows remote attackers to deseri…
Uma Em5000 Firmware
Mitigation only
CRITICAL 9.9
CVE-2016-2396
The GMS ViewPoint (GMSVP) web application in Dell SonicWALL GMS, Analyzer, and UMA EM5000 7.2, 8.0, and 8.1 before Hotfix 168056 allows remote authen…
Analyzer
Mitigation only
MEDIUM 6.9
CVE-2015-4173
Unquoted Windows search path vulnerability in the autorun value in Dell SonicWall NetExtender before 7.5.227 and 8.0.x before 8.0.238, as used in the…
Netextender
7.5.227 / 8.0.238+
HIGH 9.0
CVE-2015-3990
The GMS ViewPoint (GMSVP) web application in Dell Sonicwall GMS, Analyzer, and UMA EM5000 before 7.2 SP4 allows remote authenticated users to execute…
Uma Em5000 Firmware
after 7.2
MEDIUM 6.8
CVE-2015-2248
Cross-site request forgery (CSRF) vulnerability in the user portal in Dell SonicWALL Secure Remote Access (SRA) products with firmware before 7.5.1.0…
Remote Access Firmware
7.5.1.0-38sv / 8.0.0.1-16sv+
HIGH 9.0
CVE-2014-8420EPSS 24%
The ViewPoint web application in Dell SonicWALL Global Management System (GMS) before 7.2 SP2, SonicWALL Analyzer before 7.2 SP2, and SonicWALL UMA b…
Analyzer
Mitigation only
MEDIUM 6.5
CVE-2014-4977EPSS 75%
Multiple SQL injection vulnerabilities in Dell SonicWall Scrutinizer 11.0.1 allow remote authenticated users to execute arbitrary SQL commands via th…
Scrutinizer
No fix yet
MEDIUM 5.5
CVE-2014-4976
Dell SonicWall Scrutinizer 11.0.1 allows remote authenticated users to change user passwords via the user ID in the savePrefs parameter in a change p…
Scrutinizer
No fix yet
HIGH 7.5
CVE-2011-5262
SQL injection vulnerability in prodpage.cfm in SonicWALL Aventail allows remote attackers to execute arbitrary SQL commands via the CategoryID parame…
Aventail Sra Ex Virtual Appliance
No fix yet
HIGH 7.5
CVE-2012-3951EPSS 52%
The MySQL component in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) 9.0.1.19899 and earlier has a default password of admin for the (1) scruti…
Scrutinizer
after 9.0.1.19899
HIGH 9.4
CVE-2012-2627EPSS 6%
d4d/uploader.php in the web console in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) before 9.5.0 allows remote attackers to create or overwrit…
Scrutinizer
9.5.0+
MEDIUM 5.0
CVE-2012-2626EPSS 44%
cgi-bin/admin.cgi in the web console in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) before 9.5.0 does not require token authentication, which…
Scrutinizer
9.5.0+
MEDIUM 6.5
CVE-2012-2962EPSS 67%
SQL injection vulnerability in d4d/statusFilter.php in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) before 9.5.2 allows remote authenticated u…
Scrutinizer
9.5.2+
HIGH 9.3
CVE-2010-2583
Stack-based buffer overflow in SonicWALL SSL-VPN End-Point Interrogator/Installer ActiveX control (Aventail.EPInstaller) before 10.5.2 and 10.0.5 hot…
Ssl Vpn End Point Interrogator\/installer Activex Control
after 10.5.1
HIGH 9.3
CVE-2007-6273EPSS 6%
Multiple format string vulnerabilities in the configuration file in SonicWALL GLobal VPN Client 3.1.556 and 4.0.0.810 allow user-assisted remote atta…
Global Vpn Client
No fix yet
HIGH 10.0
CVE-2007-5815
Absolute path traversal vulnerability in the WebCacheCleaner ActiveX control 1.3.0.3 in SonicWall SSL-VPN 200 before 2.1, and SSL-VPN 2000/4000 befor…
Ssl Vpn 200
after 2.5
HIGH 9.3
CVE-2007-5603EPSS 38%
Stack-based buffer overflow in the SonicWall SSL-VPN NetExtender NELaunchCtrl ActiveX control before 2.1.0.51, and 2.5.x before 2.5.0.56, allows remo…
Ssl Vpn
after 2.5
HIGH 9.3
CVE-2007-5814EPSS 6%
Multiple buffer overflows in the SonicWall SSL-VPN NetExtender NELaunchCtrl ActiveX control before 2.1.0.51, and 2.5.x before 2.5.0.56, allow remote …
Ssl Vpn
after 2.5
HIGH 7.8
CVE-2003-1490
SonicWall Pro running firmware 6.4.0.1 allows remote attackers to cause a denial of service (device reset) via a long HTTP POST to the internal inter…
Pro100
Mitigation only
MEDIUM 5.1
CVE-2003-1320
SonicWALL firmware before 6.4.0.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted Internet Key E…
Firmware
after 6.4.0.1
MEDIUM 5.0
CVE-2002-2181
SonicWall Content Filtering allows local users to access prohibited web sites via requests to the web site's IP address instead of the domain name.
Content Filtering
Mitigation only
HIGH 7.5
CVE-2001-1104EPSS 7%
SonicWALL SOHO uses easily predictable TCP sequence numbers, which allows remote attackers to spoof or hijack sessions.
Soho Firmware
Mitigation only