← Back

Sonicwall

sonicwall

229 CVEs • 352 products

Products (352)

Click to collapse
Toggle
Sonicos
sonicos
Sonicosv
sonicosv
Analytics
analytics
Analyzer
analyzer
Netextender
netextender
Sma8200v
sma8200v
Scrutinizer
scrutinizer
Ssl Vpn
ssl_vpn
Sma 500v
sma_500v
Soho Firewall
soho_firewall
Soho Firmware
soho_firmware
Uma Em5000
uma_em5000
Viewpoint
viewpoint

CVEs (229)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Sonicwall
3Sma6210 Firmware
Sma7210 FirmwareSma8200v
Jul 16, 2026
Jul 14, 2026
N/A· v4
7.2 HIGH· v3
N/A· v2
Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a re...Show more
Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.Show less
1Sonicwall
3Sma6210 Firmware
Sma7210 FirmwareSma8200v
Jul 16, 2026
Jul 14, 2026
N/A· v4
10.0 CRITICAL· v3
N/A· v2
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended...Show more
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.Show less
1Sonicwall
1Sonicos
Jun 17, 2026
Apr 29, 2026
N/A· v4
4.9 MEDIUM· v3
N/A· v2
A post-authentication Stack-based Buffer Overflow vulnerabilities in SonicOS allows a remote attacker to crash a firewall.
1Sonicwall
1Sonicos
Jun 17, 2026
Apr 29, 2026
N/A· v4
6.8 MEDIUM· v3
N/A· v2
A post-authentication Path Traversal vulnerability in SonicOS allows an attacker to interact with usually restricted services.
1Sonicwall
1Sonicos
Jun 17, 2026
Apr 29, 2026
N/A· v4
8.0 HIGH· v3
N/A· v2
A vulnerability in the access control mechanism of SonicOS may allow certain management interface functions to be accessible under specific conditions.
1Sonicwall
5Sma6200 Firmware
Sma6210 FirmwareSma7200 Firmware+2 more
Jun 17, 2026
Apr 9, 2026
N/A· v4
7.2 HIGH· v3
N/A· v2
Improper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote authenticated SSLVPN user to bypass Workplace/Connect Tunnel TOTP authentication.
1Sonicwall
5Sma6200 Firmware
Sma6210 FirmwareSma7200 Firmware+2 more
Jun 17, 2026
Apr 9, 2026
N/A· v4
6.6 MEDIUM· v3
N/A· v2
Improper handling of Unicode encoding in SonicWall SMA1000 series appliances allows a remote authenticated SSLVPN admin to bypass AMC TOTP authentication.
1Sonicwall
5Sma6200 Firmware
Sma6210 FirmwareSma7200 Firmware+2 more
Jun 17, 2026
Apr 9, 2026
N/A· v4
7.2 HIGH· v3
N/A· v2
An observable response discrepancy vulnerability in the SonicWall SMA1000 series appliances allows a remote attacker to enumerate SSL VPN user credentials.
1Sonicwall
5Sma6200 Firmware
Sma6210 FirmwareSma7200 Firmware+2 more
Jun 17, 2026
Apr 9, 2026
N/A· v4
7.2 HIGH· v3
N/A· v2
Improper neutralization of special elements used in an SQL command (“SQL Injection”) in SonicWall SMA1000 series appliances allows a remote authenticated attacker with read-only administrator privileges to escalate privi...Show more
Improper neutralization of special elements used in an SQL command (“SQL Injection”) in SonicWall SMA1000 series appliances allows a remote authenticated attacker with read-only administrator privileges to escalate privileges to primary administrator.Show less
1Sonicwall
1Email Security
Jul 24, 2026
Mar 31, 2026
N/A· v4
3.8 LOW· v3
N/A· v2
A vulnerability exists in the SonicWall Email Security appliance due to improper input sanitization that may lead to data corruption, allowing a remote authenticated attacker as admin user could exploit this issue by pro...Show more
A vulnerability exists in the SonicWall Email Security appliance due to improper input sanitization that may lead to data corruption, allowing a remote authenticated attacker as admin user could exploit this issue by providing crafted input that corrupts application database.Show less
1Sonicwall
1Email Security
Jul 24, 2026
Mar 31, 2026
N/A· v4
2.7 LOW· v3
N/A· v2
A denial-of-service (DoS) vulnerability exists due to improper input validation in the SonicWall Email Security appliance, allowing a remote authenticated attacker as admin user to cause the application to become unrespo...Show more
A denial-of-service (DoS) vulnerability exists due to improper input validation in the SonicWall Email Security appliance, allowing a remote authenticated attacker as admin user to cause the application to become unresponsive.Show less
1Sonicwall
1Email Security
Jul 24, 2026
Mar 31, 2026
N/A· v4
4.8 MEDIUM· v3
N/A· v2
A stored Cross-Site Scripting (XSS) vulnerability has been identified in the SonicWall Email Security appliance due to improper neutralization of user-supplied input during web page generation, allowing a remote authenti...Show more
A stored Cross-Site Scripting (XSS) vulnerability has been identified in the SonicWall Email Security appliance due to improper neutralization of user-supplied input during web page generation, allowing a remote authenticated attacker as admin user to potentially execute arbitrary JavaScript code.Show less
1Sonicwall
1Sonicos
Jun 17, 2026
Mar 4, 2026
N/A· v4
4.9 MEDIUM· v3
N/A· v2
A post-authentication Stack-based Buffer Overflow vulnerability in SonicOS certificate handling allows a remote attacker to crash a firewall.
1Sonicwall
1Sonicos
Jun 17, 2026
Feb 24, 2026
N/A· v4
4.9 MEDIUM· v3
N/A· v2
A post-authentication Out-of-bounds Read vulnerability in SonicOS allows a remote attacker to crash a firewall.
1Sonicwall
1Sonicos
Jun 17, 2026
Feb 24, 2026
N/A· v4
4.9 MEDIUM· v3
N/A· v2
A post-authentication NULL Pointer Dereference vulnerability in SonicOS allows a remote attacker to crash a firewall.
1Sonicwall
1Sonicos
Jun 17, 2026
Feb 24, 2026
N/A· v4
4.9 MEDIUM· v3
N/A· v2
A post-authentication Format String vulnerability in SonicOS allows a remote attacker to crash a firewall.
1Sonicwall
1Sonicos
Jun 17, 2026
Feb 24, 2026
N/A· v4
4.9 MEDIUM· v3
N/A· v2
Multiple post-authentication stack-based buffer overflow vulnerabilities in the SonicOS management interface due to improper bounds checking in a API endpoint.
1Sonicwall
5Sma6200 Firmware
Sma6210 FirmwareSma7200 Firmware+2 more
Jun 17, 2026
Dec 18, 2025
N/A· v4
6.6 MEDIUM· v3
N/A· v2
A local privilege escalation vulnerability due to insufficient authorization in the SonicWall SMA1000 appliance management console (AMC).
1Sonicwall
5Email Security Appliance 5000 Firmware
Email Security Appliance 5050 FirmwareEmail Security Appliance 7000 Firmware+2 more
Jun 17, 2026
Nov 20, 2025
N/A· v4
5.3 MEDIUM· v3
N/A· v2
A Path Traversal vulnerability has been identified in the Email Security appliance allows an attacker to manipulate file system paths by injecting crafted directory-traversal sequences (such as ../) and may access files...Show more
A Path Traversal vulnerability has been identified in the Email Security appliance allows an attacker to manipulate file system paths by injecting crafted directory-traversal sequences (such as ../) and may access files and directories outside the intended restricted path.Show less
1Sonicwall
5Email Security Appliance 5000 Firmware
Email Security Appliance 5050 FirmwareEmail Security Appliance 7000 Firmware+2 more
Jun 17, 2026
Nov 20, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Download of Code Without Integrity Check Vulnerability in the SonicWall Email Security appliance loads root filesystem images without verifying signatures, allowing attackers with VMDK or datastore access to modify syste...Show more
Download of Code Without Integrity Check Vulnerability in the SonicWall Email Security appliance loads root filesystem images without verifying signatures, allowing attackers with VMDK or datastore access to modify system files and gain persistent arbitrary code execution.Show less