Vulnerability index

Browse CVEs

32 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Sma6210 Firmware CRITICAL 10.0
CVE-2026-15409 KEVEPSS 74%

A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attack…

Mitigation only
Fix from $2,300 2026-07-14
Sma6210 Firmware HIGH 7.2
CVE-2026-15410 KEVEPSS 76%

Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management C…

Mitigation only
Fix from $1,950 2026-07-14
Sonicos CRITICAL 9.8
CVE-2024-22394

An improper authentication vulnerability has been identified in SonicWall SonicOS SSL-VPN feature, which in specific conditions could allow a remote …

Mitigation only
Fix from $2,300 2024-02-08
Sma1000 Firmware HIGH 7.5
CVE-2023-0126EPSS 73%

Pre-authentication path traversal vulnerability in SMA1000 firmware version 12.4.2, which allows an unauthenticated attacker to access arbitrary file…

Mitigation only
Fix from $1,950 2023-01-19
Sma 6200 Firmware CRITICAL 9.8
CVE-2022-22282EPSS 8%

SonicWall SMA1000 series firmware 12.4.0, 12.4.1-02965 and earlier versions incorrectly restricts access to a resource using HTTP connections from an…

Mitigation only
Fix from $2,300 2022-05-13
Sma 6200 Firmware HIGH 7.5
CVE-2022-1701

SonicWall SMA1000 series firmware 12.4.0, 12.4.1-02965 and earlier versions uses a shared and hard-coded encryption key to store data.

Mitigation only
Fix from $1,950 2022-05-13
Sma 6200 Firmware MEDIUM 6.1
CVE-2022-1702EPSS 9%

SonicWall SMA1000 series firmware 12.4.0, 12.4.1-02965 and earlier versions accept a user-controlled input that specifies a link to an external site …

Mitigation only
Fix from $1,600 2022-05-13
Sma 200 Firmware CRITICAL 9.8
CVE-2021-20042

An unauthenticated remote attacker can use SMA 100 as an unintended proxy or intermediary undetectable proxy to bypass firewall rules. This vulnerabi…

Mitigation only
Fix from $2,300 2021-12-08
Sma 200 Firmware CRITICAL 9.8
CVE-2021-20045EPSS 25%

A buffer overflow vulnerability in SMA100 sonicfiles RAC_COPY_TO (RacNumber 36) method allows a remote unauthenticated attacker to potentially execut…

Mitigation only
Fix from $2,300 2021-12-08
Sma 200 Firmware HIGH 8.8
CVE-2021-20043EPSS 23%

A Heap-based buffer overflow vulnerability in SonicWall SMA100 getBookmarks method allows a remote authenticated attacker to potentially execute code…

Mitigation only
Fix from $1,950 2021-12-08
Sma 200 Firmware HIGH 8.8
CVE-2021-20044EPSS 40%

A post-authentication remote command injection vulnerability in SonicWall SMA100 allows a remote authenticated attacker to execute OS system commands…

Mitigation only
Fix from $1,950 2021-12-08
Sma 200 Firmware HIGH 7.5
CVE-2021-20041EPSS 7%

An unauthenticated and remote adversary can consume all of the device's CPU due to crafted HTTP requests sent to SMA100 /fileshare/sonicfiles/sonicfi…

Mitigation only
Fix from $1,950 2021-12-08
Sma 200 Firmware CRITICAL 9.8
CVE-2021-20038 KEVEPSS 100%

A Stack-based buffer overflow vulnerability in SMA100 Apache httpd server's mod_cgi module environment variables allows a remote unauthenticated atta…

Mitigation only
Fix from $2,300 2021-12-08
Sma 200 Firmware HIGH 8.8
CVE-2021-20039EPSS 78%

Improper neutralization of special elements in the SMA100 management interface '/cgi-bin/viewcert' POST http method allows a remote authenticated att…

No fix yet
Fix from $1,950 2021-12-08
Sma 200 Firmware HIGH 7.5
CVE-2021-20040EPSS 26%

A relative path traversal vulnerability in the SMA100 upload funtion allows a remote unauthenticated attacker to upload crafted web pages or files as…

Mitigation only
Fix from $1,950 2021-12-08
Global Management System CRITICAL 9.8
CVE-2021-20020

A command execution vulnerability in SonicWall GMS 9.3 allows a remote unauthenticated attacker to locally escalate privilege to root.

Mitigation only
Fix from $2,300 2021-04-10
Sma100 Firmware MEDIUM 5.3
CVE-2020-5132

SonicWall SSL-VPN products and SonicWall firewall SSL-VPN feature misconfiguration leads to possible DNS flaw known as domain name collision vulnerab…

Mitigation only
Fix from $1,600 2020-09-30
Analyzer CRITICAL 9.8
CVE-2013-1359EPSS 89%

An Authentication Bypass Vulnerability exists in DELL SonicWALL Analyzer 7.0, Global Management System (GMS) 4.1, 5.0, 5.1, 6.0, and 7.0; Universal M…

No fix yet
Fix from $2,300 2020-02-11
Analyzer CRITICAL 9.8
CVE-2013-1360EPSS 23%

An Authentication Bypass vulnerability exists in DELL SonicWALL Global Management System (GMS) 4.1, 5.0, 5.1, 6.0, and 7.0, Analyzer 7.0, Universal M…

No fix yet
Fix from $2,300 2020-02-11
Global Management System CRITICAL 9.8
CVE-2019-7478

A vulnerability in GMS allow unauthenticated user to SQL injection in Webservice module. This vulnerability affected GMS versions GMS 8.4, 8.5, 8.6, …

Mitigation only
Fix from $2,300 2019-12-31
Sonicos MEDIUM 5.4
CVE-2018-5280

SonicWall SonicOS on Network Security Appliance (NSA) 2016 Q4 devices has XSS via the Configure SSO screens.

No fix yet
Fix from $1,600 2018-01-08
Sonicos MEDIUM 5.4
CVE-2018-5281

SonicWall SonicOS on Network Security Appliance (NSA) 2017 Q4 devices has XSS via the CFS Custom Category and Cloud AV DB Exclusion Settings screens.

No fix yet
Fix from $1,600 2018-01-08
Uma Em5000 Firmware CRITICAL 9.8
CVE-2016-2397EPSS 6%

The cliserver implementation in Dell SonicWALL GMS, Analyzer, and UMA EM5000 7.2, 8.0, and 8.1 before Hotfix 168056 allows remote attackers to deseri…

Mitigation only
Fix from $2,300 2016-02-17
Analyzer CRITICAL 9.9
CVE-2016-2396

The GMS ViewPoint (GMSVP) web application in Dell SonicWALL GMS, Analyzer, and UMA EM5000 7.2, 8.0, and 8.1 before Hotfix 168056 allows remote authen…

Mitigation only
Fix from $2,300 2016-02-17
Analyzer HIGH 9.0
CVE-2014-8420EPSS 24%

The ViewPoint web application in Dell SonicWALL Global Management System (GMS) before 7.2 SP2, SonicWALL Analyzer before 7.2 SP2, and SonicWALL UMA b…

Mitigation only
Fix from $1,950 2014-11-25
Scrutinizer MEDIUM 6.5
CVE-2014-4977EPSS 75%

Multiple SQL injection vulnerabilities in Dell SonicWall Scrutinizer 11.0.1 allow remote authenticated users to execute arbitrary SQL commands via th…

No fix yet
Fix from $1,600 2014-07-16
Scrutinizer MEDIUM 5.5
CVE-2014-4976

Dell SonicWall Scrutinizer 11.0.1 allows remote authenticated users to change user passwords via the user ID in the savePrefs parameter in a change p…

No fix yet
Fix from $1,600 2014-07-16
Aventail Sra Ex Virtual Appliance HIGH 7.5
CVE-2011-5262

SQL injection vulnerability in prodpage.cfm in SonicWALL Aventail allows remote attackers to execute arbitrary SQL commands via the CategoryID parame…

No fix yet
Fix from $1,950 2013-02-12
Global Vpn Client HIGH 9.3
CVE-2007-6273EPSS 6%

Multiple format string vulnerabilities in the configuration file in SonicWALL GLobal VPN Client 3.1.556 and 4.0.0.810 allow user-assisted remote atta…

No fix yet
Fix from $1,950 2007-12-07
Pro100 HIGH 7.8
CVE-2003-1490

SonicWall Pro running firmware 6.4.0.1 allows remote attackers to cause a denial of service (device reset) via a long HTTP POST to the internal inter…

Mitigation only
Fix from $1,950 2003-12-31