E Mail Security

Vendor:

First CVE: May 12, 2008 · Active for 18 years

13
Total CVEs
Bottom 1%
2.6
Avg CVEs / Year
Bottom 1%
6.2
Avg CVSS
Higher Avg CVSS than 2% of tracked products
38.5%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact E Mail Security over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 12, 2008
18 years ago
Most Recent CVE
Mar 31, 2026
116 days ago

CVE Severity & Scoring

E Mail Security13 CVEs
All CVEs352,708 CVEs
LowMediumHighCritical
Attack Vector
Local1 (7.7%)
Network11 (84.6%)
Unknown1 (7.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (69.2%)
High3 (23.1%)
Unknown1 (7.7%)
User Interaction
None11 (84.6%)
Unknown1 (7.7%)
Required1 (7.7%)
Privileges Required
Low1 (7.7%)
High5 (38.5%)
None6 (46.2%)
Unknown1 (7.7%)

Top CVEs

Signals from CVEs in this product scope (13 CVEs).

13 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect agai
Dec 10, 202110.099YESYES
It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Threa
Dec 14, 20219.098YESYES
A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host.
Apr 9, 20219.896YESYES
SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to read an arbitrary file on the remote host.
Apr 20, 20214.980YESNO
Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker wit
Dec 18, 20215.976NONO
Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthori
May 22, 20185.565NOYES
SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to the remote host.
Apr 9, 20217.264YESNO
The X509_V_FLAG_X509_STRICT flag enables additional security checks of the certificates present in a certificate chain. It is not set by default. Starting from OpenSSL version 1.1.
Mar 25, 20217.434NONO
A stored Cross-Site Scripting (XSS) vulnerability has been identified in the SonicWall Email Security appliance due to improper neutralization of user-supplied input during web pag
Mar 31, 20264.822NONO
Cross-site scripting (XSS) vulnerability in SonicWall Email Security 6.1.1 allows remote attackers to inject arbitrary web script or HTML via the Host header in a request to a non-
May 12, 20084.322NOYES

Exploit Exposure

Signals from CVEs in this product scope (13 CVEs).

CISA KEV
5 CVEs
38.5% of CVEs· Bottom 1%
Metasploit
2 CVEs
15.4% of CVEs· Bottom 1%
Nuclei
3 CVEs
23.1% of CVEs· Bottom 1%
ExploitDB
3 CVEs
23.1% of CVEs· 93rd percentile

Social Chatter

Signals from CVEs in this product scope (13 CVEs).

Media Mentions

Signals from CVEs in this product scope (13 CVEs).

Top CNAs Publishing CVEs For E Mail Security

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
6.1.114.31.5%01