Complete feed
Recently updated
Advisories the vendor has revised
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
High [CVE-2026-66152 +1] NetExtender: Path traversal vulnerability in OPSWAT tarball in the SonicWall NetExtender Linux client allows an attacker to write arbitrar…
A Path traversal vulnerability in OPSWAT tarball in the SonicWall NetExtender Linux client allows an attacker to write arbitrary file as root.
Critical [CVE-2026-66145 +5] GMS: unauthenticated remote code execution vulnerability was identified in GMS 9.5.1 (Build 9510.1044) and earlier versions which…
An unauthenticated remote code execution vulnerability was identified in GMS 9.5.1 (Build 9510.1044) and earlier versions which allows remote attacker to read sensitive data and perform arbitrary file write via zipslip.
High [CVE-2026-66149 +1] Email Security: Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an aut…
Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated attacker with access to the SonicWall Email Security restricted CLI can inject arbitrary OS commands that execute as root via netmask.
Medium [CVE-2026-66151] Global VPN Client: SonicWall Global VPN Client version 4.10.8.1108 and earlier is vulnerable to an out-of-bounds kernel memory read in the SWIPsec…
SonicWall Global VPN Client version 4.10.8.1108 and earlier is vulnerable to an out-of-bounds kernel memory read in the SWIPsec.sys driver, which could allow a local attacker to cause a system crash.
Medium [CVE-2026-0516] SonicOS: improper neutralization of HTTP Headers for Scripting Syntax vulnerability in SonicOS could allow a remote attacker to manipu…
A improper neutralization of HTTP Headers for Scripting Syntax vulnerability in SonicOS could allow a remote attacker to manipulate the Host header and redirect firewall management users to arbitrary web domains.
Critical [CVE-2026-15409 +1] Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface.
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.
High [CVE-2026-0204 +2] SonicOS: vulnerability in the access control mechanism of SonicOS may allow certain management interface functions to be accessible un…
A vulnerability in the access control mechanism of SonicOS may allow certain management interface functions to be accessible under specific conditions.
High [CVE-2026-4112 +3] Improper neutralization of special elements used in an SQL command (“SQL Injection”) in SonicWall SMA1000 series appliances all…
Improper neutralization of special elements used in an SQL command (“SQL Injection”) in SonicWall SMA1000 series appliances allows a remote authenticated attacker with read-only administrator privileges to escalate privileges to primary administrator. Affected product named by the advisory: SSL VPN.
Medium [CVE-2026-3468 +2] Email Security: stored Cross-Site Scripting (XSS) vulnerability has been identified in the SonicWall Email Security appliance due to improper…
A stored Cross-Site Scripting (XSS) vulnerability has been identified in the SonicWall Email Security appliance due to improper neutralization of user-supplied input during web page generation, allowing a remote authenticated attacker as admin user to potentially execute arbitrary JavaScript code.