E Mail Security
Vendor:
First CVE: May 12, 2008 · Active for 18 years
13
Total CVEs
Bottom 1%
2.6
Avg CVEs / Year
Bottom 1%
6.2
Avg CVSS
Higher Avg CVSS than 2% of tracked products
38.5%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact E Mail Security over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 12, 2008
18 years ago
Most Recent CVE
Mar 31, 2026
116 days ago
CVE Severity & Scoring
E Mail Security13 CVEs
15%
46%
15%
23%
All CVEs352,708 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (7.7%)
Network11 (84.6%)
Unknown1 (7.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (69.2%)
High3 (23.1%)
Unknown1 (7.7%)
User Interaction
None11 (84.6%)
Unknown1 (7.7%)
Required1 (7.7%)
Privileges Required
Low1 (7.7%)
High5 (38.5%)
None6 (46.2%)
Unknown1 (7.7%)
Top CVEs
Signals from CVEs in this product scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-44228CRITICAL Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect agai | Dec 10, 2021 | 10.0 | 99 | YES | YES |
CVE-2021-45046CRITICAL It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Threa | Dec 14, 2021 | 9.0 | 98 | YES | YES |
CVE-2021-20021CRITICAL A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host. | Apr 9, 2021 | 9.8 | 96 | YES | YES |
CVE-2021-20023MEDIUM SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to read an arbitrary file on the remote host. | Apr 20, 2021 | 4.9 | 80 | YES | NO |
CVE-2021-45105MEDIUM Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker wit | Dec 18, 2021 | 5.9 | 76 | NO | NO |
CVE-2018-3639MEDIUM Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthori | May 22, 2018 | 5.5 | 65 | NO | YES |
CVE-2021-20022HIGH SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to the remote host. | Apr 9, 2021 | 7.2 | 64 | YES | NO |
CVE-2021-3450HIGH The X509_V_FLAG_X509_STRICT flag enables additional security checks of the certificates present in a certificate chain. It is not set by default. Starting from OpenSSL version 1.1. | Mar 25, 2021 | 7.4 | 34 | NO | NO |
CVE-2026-3468MEDIUM A stored Cross-Site Scripting (XSS) vulnerability has been identified in the SonicWall Email Security appliance due to improper neutralization of user-supplied input during web pag | Mar 31, 2026 | 4.8 | 22 | NO | NO |
CVE-2008-2162MEDIUM Cross-site scripting (XSS) vulnerability in SonicWall Email Security 6.1.1 allows remote attackers to inject arbitrary web script or HTML via the Host header in a request to a non- | May 12, 2008 | 4.3 | 22 | NO | YES |
Exploit Exposure
Signals from CVEs in this product scope (13 CVEs).
CISA KEV
5 CVEs
38.5% of CVEs· Bottom 1%
Metasploit
2 CVEs
15.4% of CVEs· Bottom 1%
Nuclei
3 CVEs
23.1% of CVEs· Bottom 1%
ExploitDB
3 CVEs
23.1% of CVEs· 93rd percentile
Social Chatter
Signals from CVEs in this product scope (13 CVEs).
Media Mentions
Signals from CVEs in this product scope (13 CVEs).
Top CNAs Publishing CVEs For E Mail Security
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 6.1.1 | 1 | 4.3 | 1.5% | 0 | 1 |