Email Security
Vendor:
First CVE: May 12, 2008 · Active for 18 years
13
Total CVEs
More Total CVEs than 90% of tracked products
2.6
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
6.2
Avg CVSS
Higher Avg CVSS than 27% of tracked products
38.5%
KEV Rate
Higher KEV Rate than 98% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Email Security over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 12, 2008
18 years ago
Most Recent CVE
Mar 31, 2026
117 days ago
CVE Severity & Scoring
Email Security13 CVEs
15%
46%
15%
23%
All CVEs352,719 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (7.7%)
Network11 (84.6%)
Unknown1 (7.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (69.2%)
High3 (23.1%)
Unknown1 (7.7%)
User Interaction
None11 (84.6%)
Unknown1 (7.7%)
Required1 (7.7%)
Privileges Required
Low1 (7.7%)
High5 (38.5%)
None6 (46.2%)
Unknown1 (7.7%)
Top CVEs
Signals from CVEs in this product scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-44228CRITICAL Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect agai | Dec 10, 2021 | 10.0 | 99 | YES | YES |
CVE-2021-45046CRITICAL It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Threa | Dec 14, 2021 | 9.0 | 98 | YES | YES |
CVE-2021-20021CRITICAL A vulnerability in the SonicWall Email Security version 10.0.9.x allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host. | Apr 9, 2021 | 9.8 | 96 | YES | YES |
CVE-2021-20023MEDIUM SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to read an arbitrary file on the remote host. | Apr 20, 2021 | 4.9 | 80 | YES | NO |
CVE-2021-45105MEDIUM Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker wit | Dec 18, 2021 | 5.9 | 76 | NO | NO |
CVE-2018-3639MEDIUM Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthori | May 22, 2018 | 5.5 | 65 | NO | YES |
CVE-2021-20022HIGH SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to the remote host. | Apr 9, 2021 | 7.2 | 64 | YES | NO |
CVE-2021-3450HIGH The X509_V_FLAG_X509_STRICT flag enables additional security checks of the certificates present in a certificate chain. It is not set by default. Starting from OpenSSL version 1.1. | Mar 25, 2021 | 7.4 | 34 | NO | NO |
CVE-2026-3468MEDIUM A stored Cross-Site Scripting (XSS) vulnerability has been identified in the SonicWall Email Security appliance due to improper neutralization of user-supplied input during web pag | Mar 31, 2026 | 4.8 | 22 | NO | NO |
CVE-2008-2162MEDIUM Cross-site scripting (XSS) vulnerability in SonicWall Email Security 6.1.1 allows remote attackers to inject arbitrary web script or HTML via the Host header in a request to a non- | May 12, 2008 | 4.3 | 22 | NO | YES |
Exploit Exposure
Signals from CVEs in this product scope (13 CVEs).
CISA KEV
5 CVEs
38.5% of CVEs· 98th percentile
Metasploit
2 CVEs
15.4% of CVEs· 97th percentile
Nuclei
3 CVEs
23.1% of CVEs· 98th percentile
ExploitDB
3 CVEs
23.1% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (13 CVEs).
Media Mentions
Signals from CVEs in this product scope (13 CVEs).
Top CNAs Publishing CVEs For Email Security
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 6.1.1 | 1 | 4.3 | 1.5% | 0 | 1 |