sonicwall kayıtları
sonicwall üreticisine ait 236 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 23 · %9,7
- Silahlaştırılmış
- 36 · %15,3
- Pre-auth RCE
- 22
- Düzeltme kaydı olan
- %5,5
- Yayından KEV’e ortanca
- 197 gün
Tekrar eden sınıflar
- CWE-121 Stack-based Buffer Overflow23
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')17
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')12
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')12
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')12
- CWE-287 Improper Authentication9
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
236 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
100Hemen | CVE-2021-44228Silahlaştırılmış | Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpointsapache · log4j · CWE-20 | Kritik10,0 | KEV | %100,0 | 10 Ara 2021 |
99Hemen | CVE-2021-20038Silahlaştırılmış | A Stack-based buffer overflow vulnerability in SMA100 Apache httpd server's mod_cgi module environment variables allows a remote unauthenticsonicwall · sma 200 firmware · CWE-121 | Kritik9,8 | KEV | %99,9 | 8 Ara 2021 |
98Hemen | CVE-2024-53704Silahlaştırılmış | An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication.sonicwall · sonicos · CWE-287 | Kritik9,8 | KEV | %95,1 | 9 Oca 2025 |
96Hemen | CVE-2021-45046Silahlaştırılmış | Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attackapache · log4j · CWE-917 | Kritik9,0 | KEV | %100,0 | 14 Ara 2021 |
96Hemen | CVE-2024-38475Silahlaştırılmış | Apache HTTP Server weakness in mod_rewrite when first segment of substitution matches filesystem path.apache · http server · CWE-116 | Kritik9,1 | KEV | %100,0 | 1 Tem 2024 |
96Hemen | CVE-2021-20021Silahlaştırılmış | A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a craftedsonicwall · email security · CWE-269 | Kritik9,8 | KEV | %88,7 | 9 Nis 2021 |
90Hemen | CVE-2019-7481Silahlaştırılmış | Vulnerability in SonicWall SMA100 allow unauthenticated user to gain read-only access to unauthorized resources.sonicwall · sma 100 firmware · CWE-89 | Yüksek7,5 | KEV | %99,9 | 17 Ara 2019 |
89Hemen | CVE-2022-0847Silahlaştırılmış | A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe linux · linux kernel · CWE-665 | Yüksek7,8 | KEV | %92,8 | 10 Mar 2022 |
81Hemen | CVE-2023-44221Silahlaştırılmış | Improper neutralization of special elements in the SMA100 SSL-VPN management interface allows a remote authenticated attacker with administrsonicwall · sma 200 firmware · CWE-78 | Yüksek7,2 | KEV | %76,3 | 5 Ara 2023 |
81Hemen | CVE-2021-20016Silahlaştırılmış | A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform SQL query to accesssonicwall · sma 100 firmware · CWE-89 | Kritik9,8 | KEV | %40,0 | 4 Şub 2021 |
78Bu hafta | CVE-2021-20028Silahlaştırılmış | Improper neutralization of a SQL Command leading to SQL Injection vulnerability impacting end-of-life Secure Remote Access (SRA) products, ssonicwall · sma 210 firmware · CWE-89 | Kritik9,8 | KEV | %30,1 | 4 Ağu 2021 |
77Bu hafta | CVE-2020-5135Silahlaştırılmış | A buffer overflow vulnerability in SonicOS allows a remote attacker to cause Denial of Service (DoS) and potentially execute arbitrary code sonicwall · sonicos · CWE-120 | Kritik9,8 | KEV | %26,9 | 12 Eki 2020 |
76Bu hafta | CVE-2025-23006Silahlaştırılmış | Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) andsonicwall · sma8200v · CWE-502 | Kritik9,8 | KEV | %23,4 | 23 Oca 2025 |
75Bu hafta | CVE-2024-40766Silahlaştırılmış | An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorizedsonicwall · sonicos · CWE-284 | Kritik9,8 | KEV | %18,4 | 23 Ağu 2024 |
73Bu hafta | CVE-2026-83548Silahlaştırılmış | A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path.sonicwall · sma8200v · CWE-441 | Kritik10,0 | KEV | %8,8 | 1 Eyl 2026 |
72Bu hafta | CVE-2026-15409Silahlaştırılmış | A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface.sonicwall · sma6210 firmware · CWE-918 | Kritik10,0 | KEV | %6,8 | 14 Tem 2026 |
66Bu hafta | CVE-2013-1359Silahlaştırılmış | An Authentication Bypass Vulnerability exists in DELL SonicWALL Analyzer 7.0, Global Management System (GMS) 4.1, 5.0, 5.1, 6.0, and 7.0; Unsonicwall · analyzer · CWE-287 | Kritik9,8 | — | %89,4 | 11 Şub 2020 |
64Bu hafta | CVE-2021-20023Silahlaştırılmış | SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to read an arbitrary file on thsonicwall · email security · CWE-22 | Orta4,9 | KEV | %51,4 | 20 Nis 2021 |
64Bu hafta | CVE-2026-83549Silahlaştırılmış | Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identisonicwall · sma8200v · CWE-78 | Yüksek7,8 | KEV | %10,8 | 1 Eyl 2026 |
63Bu hafta | CVE-2021-20022Silahlaştırılmış | SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to sonicwall · email security · CWE-434 | Yüksek7,2 | KEV | %16,5 | 9 Nis 2021 |
62Bu hafta | CVE-2024-6387Kavram kanıtı | Openssh: regresshion - race condition in ssh allows rce/dossonicwall · sma 6200 firmware · CWE-364 | Yüksek8,1 | — | %99,5 | 1 Tem 2024 |
62Bu hafta | CVE-2022-22274Kavram kanıtı | A Stack-based buffer overflow vulnerability in the SonicOS via HTTP request allows a remote unauthenticated attacker to cause Denial of Servsonicwall · sonicos · CWE-121 | Kritik9,8 | — | %75,5 | 25 Mar 2022 |
62Bu hafta | CVE-2019-12255Kavram kanıtı | Wind River VxWorks has a Buffer Overflow in the TCP component (issue 1 of 4).windriver · vxworks · CWE-120 | Kritik9,8 | — | %75,3 | 9 Ağu 2019 |
62Bu hafta | CVE-2026-15410Silahlaştırılmış | Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Mansonicwall · sma6210 firmware · CWE-94 | Yüksek7,2 | KEV | %11,8 | 14 Tem 2026 |
61Bu hafta | CVE-2023-34127Silahlaştırılmış | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in SonicWall GMS, SonicWall Analytisonicwall · analytics · CWE-78 | Yüksek8,8 | — | %86,5 | 12 Tem 2023 |
- CVE-2021-44228100Hemen
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
KritikCVSS 10,0KEVSilahlaştırılmışEPSS %100apache · log4j10 Ara 2021
- CVE-2021-2003899Hemen
A Stack-based buffer overflow vulnerability in SMA100 Apache httpd server's mod_cgi module environment variables allows a remote unauthentic
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100sonicwall · sma 200 firmware8 Ara 2021
- CVE-2024-5370498Hemen
An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication.
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %95sonicwall · sonicos9 Oca 2025
- CVE-2021-4504696Hemen
Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack
KritikCVSS 9,0KEVSilahlaştırılmışEPSS %100apache · log4j14 Ara 2021
- CVE-2024-3847596Hemen
Apache HTTP Server weakness in mod_rewrite when first segment of substitution matches filesystem path.
KritikCVSS 9,1KEVSilahlaştırılmışEPSS %100apache · http server1 Tem 2024
- CVE-2021-2002196Hemen
A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %89sonicwall · email security9 Nis 2021
- CVE-2019-748190Hemen
Vulnerability in SonicWall SMA100 allow unauthenticated user to gain read-only access to unauthorized resources.
YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %100sonicwall · sma 100 firmware17 Ara 2019
- CVE-2022-084789Hemen
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe
YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %93linux · linux kernel10 Mar 2022
- CVE-2023-4422181Hemen
Improper neutralization of special elements in the SMA100 SSL-VPN management interface allows a remote authenticated attacker with administr
YüksekCVSS 7,2KEVSilahlaştırılmışEPSS %76sonicwall · sma 200 firmware5 Ara 2023
- CVE-2021-2001681Hemen
A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform SQL query to access
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %40sonicwall · sma 100 firmware4 Şub 2021
- CVE-2021-2002878Bu hafta
Improper neutralization of a SQL Command leading to SQL Injection vulnerability impacting end-of-life Secure Remote Access (SRA) products, s
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %30sonicwall · sma 210 firmware4 Ağu 2021
- CVE-2020-513577Bu hafta
A buffer overflow vulnerability in SonicOS allows a remote attacker to cause Denial of Service (DoS) and potentially execute arbitrary code
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %27sonicwall · sonicos12 Eki 2020
- CVE-2025-2300676Bu hafta
Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %23sonicwall · sma8200v23 Oca 2025
- CVE-2024-4076675Bu hafta
An improper access control vulnerability has been identified in the SonicWall SonicOS management access, potentially leading to unauthorized
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %18sonicwall · sonicos23 Ağu 2024
- CVE-2026-8354873Bu hafta
A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path.
KritikCVSS 10,0KEVSilahlaştırılmışEPSS %9sonicwall · sma8200v1 Eyl 2026
- CVE-2026-1540972Bu hafta
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface.
KritikCVSS 10,0KEVSilahlaştırılmışEPSS %7sonicwall · sma6210 firmware14 Tem 2026
- CVE-2013-135966Bu hafta
An Authentication Bypass Vulnerability exists in DELL SonicWALL Analyzer 7.0, Global Management System (GMS) 4.1, 5.0, 5.1, 6.0, and 7.0; Un
KritikCVSS 9,8SilahlaştırılmışEPSS %89sonicwall · analyzer11 Şub 2020
- CVE-2021-2002364Bu hafta
SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to read an arbitrary file on th
OrtaCVSS 4,9KEVSilahlaştırılmışEPSS %51sonicwall · email security20 Nis 2021
- CVE-2026-8354964Bu hafta
Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identi
YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %11sonicwall · sma8200v1 Eyl 2026
- CVE-2021-2002263Bu hafta
SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to
YüksekCVSS 7,2KEVSilahlaştırılmışEPSS %17sonicwall · email security9 Nis 2021
- CVE-2024-638762Bu hafta
Openssh: regresshion - race condition in ssh allows rce/dos
YüksekCVSS 8,1Kavram kanıtıEPSS %100sonicwall · sma 6200 firmware1 Tem 2024
- CVE-2022-2227462Bu hafta
A Stack-based buffer overflow vulnerability in the SonicOS via HTTP request allows a remote unauthenticated attacker to cause Denial of Serv
KritikCVSS 9,8Kavram kanıtıEPSS %76sonicwall · sonicos25 Mar 2022
- CVE-2019-1225562Bu hafta
Wind River VxWorks has a Buffer Overflow in the TCP component (issue 1 of 4).
KritikCVSS 9,8Kavram kanıtıEPSS %75windriver · vxworks9 Ağu 2019
- CVE-2026-1541062Bu hafta
Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Man
YüksekCVSS 7,2KEVSilahlaştırılmışEPSS %12sonicwall · sma6210 firmware14 Tem 2026
- CVE-2023-3412761Bu hafta
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in SonicWall GMS, SonicWall Analyti
YüksekCVSS 8,8SilahlaştırılmışEPSS %86sonicwall · analytics12 Tem 2023