Skip to content
VulniPulse

Complete feed

Action required

Critical/high still unreviewed, or CISA KEV listed

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

High8.8SonicWall Updated

High [CVE-2026-66152 +1] NetExtender: Path traversal vulnerability in OPSWAT tarball in the SonicWall NetExtender Linux client allows an attacker to write arbitrar…

A Path traversal vulnerability in OPSWAT tarball in the SonicWall NetExtender Linux client allows an attacker to write arbitrary file as root.

CVE-2026-66152CVE-2026-66153
SSL-VPN & Clients
Aug 25, 2026
Critical9.4SonicWall Updated

Critical [CVE-2026-66145 +5] GMS: unauthenticated remote code execution vulnerability was identified in GMS 9.5.1 (Build 9510.1044) and earlier versions which…

An unauthenticated remote code execution vulnerability was identified in GMS 9.5.1 (Build 9510.1044) and earlier versions which allows remote attacker to read sensitive data and perform arbitrary file write via zipslip.

CVE-2026-66145CVE-2026-66146CVE-2026-18634+3
GMS / Analytics
Aug 11, 2026
High7.8SonicWall Updated

High [CVE-2026-66149 +1] Email Security: Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an aut…

Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated attacker with access to the SonicWall Email Security restricted CLI can inject arbitrary OS commands that execute as root via netmask.

CVE-2026-66149CVE-2026-66150
Email Security
Aug 11, 2026
Critical10.0SonicWall Exploited CISA KEV

Critical [CVE-2026-15409 +1] Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface.

A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.

CVE-2026-15409CVE-2026-15410
Unclassified
Jul 14, 2026
High8.0SonicWall

High [CVE-2026-0204 +2] SonicOS: vulnerability in the access control mechanism of SonicOS may allow certain management interface functions to be accessible un…

A vulnerability in the access control mechanism of SonicOS may allow certain management interface functions to be accessible under specific conditions.

CVE-2026-0204CVE-2026-0205CVE-2026-0206
SonicOS Firewalls
Apr 29, 2026
High7.2SonicWall

High [CVE-2026-4112 +3] Improper neutralization of special elements used in an SQL command (“SQL Injection”) in SonicWall SMA1000 series appliances all…

Improper neutralization of special elements used in an SQL command (“SQL Injection”) in SonicWall SMA1000 series appliances allows a remote authenticated attacker with read-only administrator privileges to escalate privileges to primary administrator. Affected product named by the advisory: SSL VPN.

CVE-2026-4112CVE-2026-4113CVE-2026-4114+1
SSL-VPN & Clients
Apr 9, 2026
UnratedSonicWall Exploited CISA KEV

Advisory [CVE-2025-23006] Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC), which in specific conditions could potentially enable a remote unauthenticated attacker to execute arbitrary OS commands

Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC), which in specific conditions could potentially enable a remote unauthenticated attacker to execute arbitrary OS commands.

CVE-2025-23006
Unclassified
Jan 23, 2025
UnratedSonicWall Exploited CISA KEV

Advisory [CVE-2024-53704] SonicOS: Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication

An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication. Affected product named by the advisory: SonicOS.

CVE-2024-53704
SonicOS Firewalls
Jan 9, 2025
UnratedSonicWall Exploited CISA KEV

Advisory [CVE-2021-20023] SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to read an arbitrary file on the remote host

SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to read an arbitrary file on the remote host.

CVE-2021-20023
Email Security
Apr 20, 2021
UnratedSonicWall Exploited CISA KEV

Advisory [CVE-2021-20022] SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to the remote host

SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to the remote host.

CVE-2021-20022
Email Security
Apr 9, 2021
UnratedSonicWall Exploited CISA KEV

Advisory [CVE-2021-20021] vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host

A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host.

CVE-2021-20021
Email Security
Apr 9, 2021
UnratedSonicWall Exploited CISA KEV

Advisory [CVE-2021-20016] SonicWall SMA100: SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform SQL query to access username password and other session related information

A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform SQL query to access username password and other session related information. This vulnerability impacts SMA100 build version 10.x. Affected product named by the advisory: SonicWall SMA100.

CVE-2021-20016
Unclassified
Feb 3, 2021
UnratedSonicWall Exploited CISA KEV

Advisory [CVE-2019-7481] Vulnerability in SonicWall SMA100 allow unauthenticated user to gain read-only access to unauthorized resources

Vulnerability in SonicWall SMA100 allow unauthenticated user to gain read-only access to unauthorized resources. This vulnerablity impacted SMA100 version 9.0.0.3 and earlier.

CVE-2019-7481
Unclassified
Dec 17, 2019