Email Security
SonicWall · 13 CVEs
Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allow…
Aug 11, 2026
Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allow…
Aug 11, 2026
A vulnerability exists in the SonicWall Email Security appliance due to improper input sanitization that may lead to da…
Mar 31, 2026
A denial-of-service (DoS) vulnerability exists due to improper input validation in the SonicWall Email Security applian…
Mar 31, 2026
A stored Cross-Site Scripting (XSS) vulnerability has been identified in the SonicWall Email Security appliance due to…
Mar 31, 2026
A Path Traversal vulnerability has been identified in the Email Security appliance allows an attacker to manipulate fil…
Nov 20, 2025
Download of Code Without Integrity Check Vulnerability in the SonicWall Email Security appliance loads root filesystem…
Nov 20, 2025
An improper Limitation of a Pathname to a Restricted Directory (Path Traversal) vulnerability in SonicWall Email Securi…
Mar 14, 2024
SonicWall Email Security contains a vulnerability that could permit a remote unauthenticated attacker access to an erro…
Feb 14, 2023
Apache Log4j2 does not always protect from infinite recursion in lookup evaluation
Dec 18, 2021
Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack
Dec 14, 2021
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
Dec 10, 2021
SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to read an…
Apr 20, 2021
SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload…
Apr 9, 2021
A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account…
Apr 9, 2021
CA certificate check bypass with X509_V_FLAG_X509_STRICT
Mar 25, 2021
hw: cpu: speculative store bypass
May 22, 2018
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-66150 | Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated attacker with access… | HIGH | 0.26% | Aug 11, 2026 |
| CVE-2026-66149 | Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated attacker with access… | HIGH | 0.26% | Aug 11, 2026 |
| CVE-2026-3470 | A vulnerability exists in the SonicWall Email Security appliance due to improper input sanitization that may lead to data corruption, allowing a remote authent… | LOW | 0.41% | Mar 31, 2026 |
| CVE-2026-3469 | A denial-of-service (DoS) vulnerability exists due to improper input validation in the SonicWall Email Security appliance, allowing a remote authenticated atta… | LOW | 0.47% | Mar 31, 2026 |
| CVE-2026-3468 | A stored Cross-Site Scripting (XSS) vulnerability has been identified in the SonicWall Email Security appliance due to improper neutralization of user-supplied… | MEDIUM | 0.29% | Mar 31, 2026 |
| CVE-2025-40605 | A Path Traversal vulnerability has been identified in the Email Security appliance allows an attacker to manipulate file system paths by injecting crafted dire… | MEDIUM | 0.33% | Nov 20, 2025 |
| CVE-2025-40604 | Download of Code Without Integrity Check Vulnerability in the SonicWall Email Security appliance loads root filesystem images without verifying signatures, all… | CRITICAL | 0.19% | Nov 20, 2025 |
| CVE-2024-22398 | An improper Limitation of a Pathname to a Restricted Directory (Path Traversal) vulnerability in SonicWall Email Security Appliance could allow a remote attack… | MEDIUM | 0.90% | Mar 14, 2024 |
| CVE-2023-0655 | SonicWall Email Security contains a vulnerability that could permit a remote unauthenticated attacker access to an error page that includes sensitive informati… | MEDIUM | 0.72% | Feb 14, 2023 |
| CVE-2021-45105 | Apache Log4j2 does not always protect from infinite recursion in lookup evaluation | HIGH | 100.00% | Dec 18, 2021 |
| CVE-2021-45046 KEV | Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack | CRITICAL | 99.98% | Dec 14, 2021 |
| CVE-2021-44228 KEV | Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints | CRITICAL | 100.00% | Dec 10, 2021 |
| CVE-2021-20023 KEV | SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to read an arbitrary file on the remote host. | MEDIUM | 51.69% | Apr 20, 2021 |
| CVE-2021-20022 KEV | SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to the remote host. | HIGH | 16.64% | Apr 9, 2021 |
| CVE-2021-20021 KEV | A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to th… | CRITICAL | 88.78% | Apr 9, 2021 |
| CVE-2021-3450 | CA certificate check bypass with X509_V_FLAG_X509_STRICT | HIGH | 18.34% | Mar 25, 2021 |
| CVE-2018-3639 | hw: cpu: speculative store bypass | MEDIUM | 60.63% | May 22, 2018 |
Showing 1 to 13 of 13 CVEs