CVE Database and Vulnerability Search
Search CVE and GHSA vulnerability records by identifier, title, vendor, product, package, or CWE. Filter by severity, CISA KEV, ransomware association, linked artifacts, and Nuclei templates; sort by publication date, CVSS, or EPSS.
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2023-44221HIGH | SonicWall SMA100 Appliances OS Command Injection VulnerabilityImproper neutralization of special elements in the SMA100 SSL-VPN management interface allows a remote authenticated attacker with administrative privilege to inject arbitrary commands as a 'nobody' user, potentially leading to OS Command Injection Vulnerability. CWE-78Dec 5, 2023 | CVSS7.2v3.1 | EPSS74.9% | PoCs0 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-20035MEDIUM | SonicWall SMA100 Appliances OS Command Injection VulnerabilityImproper neutralization of special elements in the SMA100 management interface allows a remote authenticated attacker to inject arbitrary commands as a 'nobody' user which potentially leads to DoS. CWE-78Sep 27, 2021 | CVSS6.5v3.1 | EPSS4.18% | PoCs0 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |