CVE-2026-81939
- EPSS 0.73%
- Veröffentlicht 04.09.2026 18:22:16
- Zuletzt bearbeitet 08.09.2026 19:12:59
A Zip Slip vulnerability in the SonicWall Network Security Manager (NSM) On-Prem file upload and archive processing functionality allows an attacker to extract files outside the intended destination directory using a specially crafted archive.
CVE-2026-78328
- EPSS 0.5%
- Veröffentlicht 04.09.2026 18:19:29
- Zuletzt bearbeitet 08.09.2026 19:12:59
A missing authorization vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Management interface allows a lower-privileged Admin user to escalate privileges to SuperAdmin.
CVE-2026-78327
- EPSS 1.55%
- Veröffentlicht 04.09.2026 18:14:54
- Zuletzt bearbeitet 08.09.2026 19:12:59
An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Management interface allows an authenticated attacker with SuperAdmin privileges to in...
CVE-2021-45105
- EPSS 100%
- Veröffentlicht 18.12.2021 12:15:07
- Zuletzt bearbeitet 25.08.2026 16:28:27
Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service wh...
- EPSS 11.64%
- Veröffentlicht 27.05.2021 19:15:08
- Zuletzt bearbeitet 21.11.2024 05:45:48
A vulnerability in the SonicWall NSM On-Prem product allows an authenticated attacker to perform OS command injection using a crafted HTTP request. This vulnerability affects NSM On-Prem 2.2.0-R10 and earlier versions.