CVE & Exploit Intelligence Database

Updated 55m ago

Search and track vulnerabilities with real-time exploit intelligence. Cross-reference CVEs against public exploits from ExploitDB, Metasploit, GitHub, and Nuclei — with CVSS and EPSS scoring, CISA KEV monitoring, and AI-powered exploit analysis.

337,123 CVEs tracked 53,219 with exploits 4,686 exploited in wild 1,539 CISA KEV 3,912 Nuclei templates 37,757 vendors 42,422 researchers
13 results Clear all
CVE-2025-32821 7.2 HIGH EPSS 0.01
Sonicwall Sma 100 Firmware < 10.2.1.15-81sv - OS Command Injection
A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN admin privileges can with admin privileges can inject shell command arguments to upload a file on the appliance.
CWE-78 May 07, 2025
CVE-2025-32820 8.8 HIGH EPSS 0.01
Sonicwall Sma 100 Firmware < 10.2.1.15-81sv - Path Traversal
A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN user privileges can inject a path traversal sequence to make any directory on the SMA appliance writable.
CWE-22 May 07, 2025
CVE-2025-32819 8.8 HIGH EXPLOITED EPSS 0.01
Sonicwall Sma 100 Firmware < 10.2.1.15-81sv - Path Traversal
A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN user privileges to bypass the path traversal checks and delete an arbitrary file potentially resulting in a reboot to factory default settings.
CWE-552 May 07, 2025
CVE-2021-20050 7.5 HIGH EPSS 0.00
Sonicwall Sma 100 Firmware < 10.0.0.0 - Improper Access Control
An Improper Access Control Vulnerability in the SMA100 series leads to multiple restricted management APIs being accessible without a user login, potentially exposing configuration meta-data.
CWE-284 Dec 23, 2021
CVE-2021-20049 7.5 HIGH EPSS 0.00
Sonicwall Sma 100 Firmware < 10.0.0.0 - Information Disclosure
A vulnerability in SonicWall SMA100 password change API allows a remote unauthenticated attacker to perform SMA100 username enumeration based on the server responses. This vulnerability impacts 10.2.1.2-24sv, 10.2.0.8-37sv and earlier 10.x versions.
CWE-204 Dec 23, 2021
CVE-2021-20016 9.8 CRITICAL KEV RANSOMWARE EPSS 0.78
Sonicwall Sma 100 Firmware < 10.2.0.5-d-29sv - SQL Injection
A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform SQL query to access username password and other session related information. This vulnerability impacts SMA100 build version 10.x.
CWE-89 Feb 04, 2021
CVE-2020-5146 7.2 HIGH EPSS 0.02
Sonicwall Sma 100 Firmware < 10.2.0.2-20sv - OS Command Injection
A vulnerability in SonicWall SMA100 appliance allow an authenticated management-user to perform OS command injection using HTTP POST parameters. This vulnerability affected SMA100 Appliance version 10.2.0.2-20sv and earlier.
CWE-78 Jan 09, 2021
CVE-2019-7486 8.8 HIGH EPSS 0.01
SonicWall SMA100 <9.0.0.4 - Code Injection
Code injection in SonicWall SMA100 allows an authenticated user to execute arbitrary code in viewcacert CGI script. This vulnerability impacted SMA100 version 9.0.0.4 and earlier.
CWE-94 Dec 19, 2019
CVE-2019-7485 8.8 HIGH EPSS 0.01
SonicWall SMA100 <9.0.0.3 - RCE
Buffer overflow in SonicWall SMA100 allows an authenticated user to execute arbitrary code in DEARegister CGI script. This vulnerability impacted SMA100 version 9.0.0.3 and earlier.
CWE-120 Dec 19, 2019
CVE-2019-7484 6.5 MEDIUM EPSS 0.00
SonicWall SMA100 <9.0.0.3 - SQL Injection
Authenticated SQL Injection in SonicWall SMA100 allow user to gain read-only access to unauthorized resources using viewcacert CGI script. This vulnerability impacted SMA100 version 9.0.0.3 and earlier.
CWE-89 Dec 19, 2019
CVE-2019-7483 7.5 HIGH KEV EPSS 0.39
SonicWall SMA100 - Path Traversal
In SonicWall SMA100, an unauthenticated Directory Traversal vulnerability in the handleWAFRedirect CGI allows the user to test for the presence of a file on the server.
CWE-22 Dec 19, 2019
CVE-2019-7482 9.8 CRITICAL 3 PoCs Analysis EPSS 0.65
SonicWall SMA100 <9.0.0.3 - Buffer Overflow
Stack-based buffer overflow in SonicWall SMA100 allows an unauthenticated user to execute arbitrary code in function libSys.so. This vulnerability impacted SMA100 version 9.0.0.3 and earlier.
CWE-121 Dec 19, 2019
CVE-2019-7481 7.5 HIGH KEV RANSOMWARE NUCLEI EPSS 0.94
SonicWall SMA100 <9.0.0.3 - Info Disclosure
Vulnerability in SonicWall SMA100 allow unauthenticated user to gain read-only access to unauthorized resources. This vulnerablity impacted SMA100 version 9.0.0.3 and earlier.
CWE-89 Dec 17, 2019