Vulnerability index

Browse CVEs

183 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Sma6210 Firmware CRITICAL 10.0
CVE-2026-15409 KEVEPSS 74%

A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attack…

Mitigation only
Fix from $2,300 2026-07-14
Sma6210 Firmware HIGH 7.2
CVE-2026-15410 KEVEPSS 76%

Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management C…

Mitigation only
Fix from $1,950 2026-07-14
Sonicos HIGH 8.0
CVE-2026-0204

A vulnerability in the access control mechanism of SonicOS may allow certain management interface functions to be accessible under specific condition…

Fix: 6.5.5.2-28n / 7.3.2-7010+
Fix from $1,950 2026-04-29
Sonicos MEDIUM 6.8
CVE-2026-0205

A post-authentication Path Traversal vulnerability in SonicOS allows an attacker to interact with usually restricted services.

Fix: 6.5.5.2-28n / 7.3.2-7010+
Fix from $1,600 2026-04-29
Sma6210 Firmware HIGH 7.2
CVE-2026-4116

Improper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote authenticated SSLVPN user to bypass Workplace/Connect Tu…

Fix: 12.4.3-03387 / 12.5.0-02624+
Fix from $1,950 2026-04-09
Sma6210 Firmware HIGH 7.2
CVE-2026-4112

Improper neutralization of special elements used in an SQL command (“SQL Injection”) in SonicWall SMA1000 series appliances allows a remote authentic…

Fix: 12.4.3-03387 / 12.5.0-02624+
Fix from $1,950 2026-04-09
Sma6210 Firmware HIGH 7.2
CVE-2026-4113

An observable response discrepancy vulnerability in the SonicWall SMA1000 series appliances allows a remote attacker to enumerate SSL VPN user creden…

Fix: 12.4.3-03387 / 12.5.0-02624+
Fix from $1,950 2026-04-09
Sma6210 Firmware MEDIUM 6.6
CVE-2026-4114

Improper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote authenticated SSLVPN admin to bypass AMC TOTP authentica…

Fix: 12.4.3-03387 / 12.5.0-02624+
Fix from $1,600 2026-04-09
Sma6200 Firmware MEDIUM 6.6
CVE-2025-40602 KEV

A local privilege escalation vulnerability due to insufficient authorization in the SonicWall SMA1000 appliance management console (AMC).

Fix: 12.4.3-03245 / 12.5.0-02283+
Fix from $1,600 2025-12-18
Email Security Appliance 5000 Firmware CRITICAL 9.8
CVE-2025-40604

Download of Code Without Integrity Check Vulnerability in the SonicWall Email Security appliance loads root filesystem images without verifying signa…

Fix: after 10.0.33.8195
Fix from $2,300 2025-11-20
Sonicos HIGH 7.5
CVE-2025-40601

A Stack-based buffer overflow vulnerability in the SonicOS SSLVPN service allows a remote unauthenticated attacker to cause Denial of Service (DoS), …

Fix: 7.3.1-7013 / 8.0.3-8011+
Fix from $1,950 2025-11-20
Email Security Appliance 5000 Firmware MEDIUM 5.3
CVE-2025-40605

A Path Traversal vulnerability has been identified in the Email Security appliance allows an attacker to manipulate file system paths by injecting cr…

Fix: after 10.0.33.8195
Fix from $1,600 2025-11-20
Sonicos CRITICAL 9.8
CVE-2025-40600

Use of Externally-Controlled Format String vulnerability in the SonicOS SSL VPN interface allows a remote unauthenticated attacker to cause service d…

Fix: 7.3.0-7012+
Fix from $2,300 2025-07-29
Sma 500v Firmware HIGH 7.5
CVE-2025-40597EPSS 28%

A Heap-based buffer overflow vulnerability in the SMA100 series web interface allows remote, unauthenticated attacker to cause Denial of Service (DoS…

Fix: 10.2.2.1-90sv+
Fix from $1,950 2025-07-23
Sma 500v Firmware HIGH 7.3
CVE-2025-40596EPSS 52%

A Stack-based buffer overflow vulnerability in the SMA100 series web interface allows remote, unauthenticated attacker to cause Denial of Service (Do…

Fix: 10.2.2.1-90sv+
Fix from $1,950 2025-07-23
Sma 500v Firmware MEDIUM 6.1
CVE-2025-40598EPSS 55%

A Reflected cross-site scripting (XSS) vulnerability exists in the SMA100 series web interface, allowing a remote unauthenticated attacker to potenti…

Fix: 10.2.2.1-90sv+
Fix from $1,600 2025-07-23
Sma 210 Firmware CRITICAL 9.1
CVE-2025-40599EPSS 10%

An authenticated arbitrary file upload vulnerability exists in the SMA 100 series web management interface. A remote attacker with administrative pri…

Fix: 10.2.2.1-90sv+
Fix from $2,300 2025-07-23
Sma 100 Firmware HIGH 8.8
CVE-2025-32819EPSS 6%

A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN user privileges to bypass the path traversal checks and delete an arbitr…

Fix: 10.2.1.15-81sv+
Fix from $1,950 2025-05-07
Sma 100 Firmware HIGH 8.8
CVE-2025-32820

A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN user privileges can inject a path traversal sequence to make any directo…

Fix: 10.2.1.15-81sv+
Fix from $1,950 2025-05-07
Sma 100 Firmware HIGH 7.2
CVE-2025-32821EPSS 20%

A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN admin privileges can with admin privileges can inject shell command argu…

Fix: 10.2.1.15-81sv+
Fix from $1,950 2025-05-07
Sma1000 Firmware HIGH 7.2
CVE-2025-2170

A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface, which in specific conditions co…

Fix: 12.4.3-02925+
Fix from $1,950 2025-04-30
Sma8200v CRITICAL 9.8
CVE-2025-23006 KEVEPSS 23%

Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and Central …

Fix: 12.4.3-02854+
Fix from $2,300 2025-01-23
Sonicos CRITICAL 9.8
CVE-2024-53704 KEVEPSS 95%

An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication.

Fix: after 7.1.1-7058
Fix from $2,300 2025-01-09
Sma 200 Firmware HIGH 8.1
CVE-2024-53703EPSS 13%

A vulnerability in the SonicWall SMA100 SSLVPN firmware 10.2.1.13-72sv and earlier versions mod_httprp library loaded by the Apache web server allows…

Fix: 10.2.1.14-75sv+
Fix from $1,950 2024-12-05
Sma 200 Firmware HIGH 8.1
CVE-2024-45318

A vulnerability in the SonicWall SMA100 SSLVPN web management interface allows remote attackers to cause Stack-based buffer overflow and potentially …

Fix: 10.2.1.14-75sv+
Fix from $1,950 2024-12-05
Sma 200 Firmware MEDIUM 6.3
CVE-2024-45319

A vulnerability in the SonicWall SMA100 SSLVPN firmware 10.2.1.13-72sv and earlier versions allows a remote authenticated attacker can circumvent t…

Fix: 10.2.1.14-75sv+
Fix from $1,600 2024-12-05
Sma 200 Firmware MEDIUM 5.3
CVE-2024-53702

Use of cryptographically weak pseudo-random number generator (PRNG) vulnerability in the SonicWall SMA100 SSLVPN backup code generator that, in certa…

Fix: 10.2.1.14-75sv+
Fix from $1,600 2024-12-05
Sma 200 Firmware HIGH 7.5
CVE-2024-40763

Heap-based buffer overflow vulnerability in the SonicWall SMA100 SSLVPN due to the use of strcpy. This allows remote authenticated attackers to cause…

Fix: 10.2.1.14-75sv+
Fix from $1,950 2024-12-05
Sonicos CRITICAL 9.8
CVE-2024-40766 KEVEPSS 18%

An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized resource…

Fix: 5.9.2.14-13o / 6.5.2.8-2n+
Fix from $2,300 2024-08-23
Netextender HIGH 8.8
CVE-2024-29014

Vulnerability in SonicWall SMA100 NetExtender Windows (32 and 64-bit) client 10.2.339 and earlier versions allows an attacker to arbitrary code execu…

Fix: 10.2.341+
Fix from $1,950 2024-07-18