Known vulnerabilities in SonicWall On-premise Email Security (ES)

Vendor: SonicWall
Software CPE: cpe:2.3:a:sonicwall:sonicwall_on-premise_email_security_es:*:*:*:*:*:*:*:*
Total vulnerabilities: 13
Public exploits: 0
Known exploited (KEV): 3
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting SonicWall On-premise Email Security (ES) SonicWall On-premise Email Security (ES) is affected by 13 known vulnerabilities: 1 critical, 2 high, 2 medium, 8 low Critical High Medium Low

Vulnerabilities (13)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU141442 - Improper Control of Generation of Code ('Code Injection')
CVE-2026-66149
CWE-94 Low
No
No
10.0.36 11.08.2026 SB2026081135
#VU141443 - Improper Control of Generation of Code ('Code Injection')
CVE-2026-66150
CWE-94 Low
No
No
10.0.36 11.08.2026 SB2026081135
#VU124784 - Improper input validation
CVE-2026-3470
CWE-20 Low
No
No
10.0.35.8405 01.04.2026 SB2026040168
#VU124783 - Improper input validation
CVE-2026-3469
CWE-20 Low
No
No
10.0.35.8405 01.04.2026 SB2026040168
#VU124782 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2026-3468
CWE-79 Low
No
No
10.0.35.8405 01.04.2026 SB2026040168
#VU118632 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2025-40605
CWE-22 Low
No
No
10.0.34.8215, 10.0.34.8223 20.11.2025 SB2025112002
#VU118631 - Download of Code Without Integrity Check
CVE-2025-40604
CWE-494 Low
No
No
10.0.34.8215, 10.0.34.8223 20.11.2025 SB2025112002
#VU87484 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2024-22398
CWE-22 Low
No
No
10.0.28.7941 13.03.2024 SB2024031307
#VU72332 - Exposure of sensitive information to an unauthorized actor
CVE-2023-0655
CWE-200 Medium
No
No
10.0.21.7607 16.02.2023 SB2023021647
#VU53230 - Use of Hard-coded Credentials
CVE-2021-20025
CWE-798 Medium
No
No
10.0.10 13.05.2021 SB2021051315
#VU52377 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2021-20023
CWE-22 High
No
Exploited
10.0.9.6173 20.04.2021 SB2021042016
#VU52039 - Unrestricted Upload of File with Dangerous Type
CVE-2021-20022
CWE-434 High
No
Exploited
10.0.9.6103, 10.0.9.6105 12.04.2021 SB2021041210
#VU52038 - Improper Authentication
CVE-2021-20021
CWE-287 Critical
No
Exploited
10.0.9.6103, 10.0.9.6105 12.04.2021 SB2021041210