Skip to main content

CVE-2021-20022

7.2
HIGHCVSS v3.1 Base Score
32.60%
MEDIUM RiskEPSS (97th percentile)
KEV

SonicWall Email Security version 10.0.9.x contains a vulnerability that allows a post-authenticated attacker to upload an arbitrary file to the remote host.

Published: 4/9/2021
Modified: 11/10/2025
Back to CVE Lookup

ACTIVELY EXPLOITED IN THE WILD

This vulnerability is listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Vulnerability Name:

SonicWall Email Security Unrestricted Upload of File Vulnerability

Vendor / Product:

SonicWall SonicWall Email Security

Required Action:

Apply updates per vendor instructions.

Due Date: 11/17/2021(OVERDUE)
Ransomware Campaign Use
Added to KEV:

11/3/2021

Notes:

https://nvd.nist.gov/vuln/detail/CVE-2021-20022

Vulnerability Summary

CVSS v3 Score

7.2HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CVSS v2 Score

7.5

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS Score (Exploitation Probability)

32.60%MEDIUM Exploitation Risk
97th percentile

This vulnerability has a 32.60% probability of being exploited in the next 30 days, ranking higher than 97% of all scored CVEs.

CWE Classification

Related Vulnerabilities

Same Weakness Type(CWE-434)

CVE-2025-13374CRITICAL 9.8

The Kalrav AI Agent plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the kalrav_upload_file AJAX action in all versions up to, and including, 2.3.3. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

1/24/2026
CVE-2026-1331CRITICAL 9.8

MeetingHub developed by HAMASTAR Technology has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.

1/22/2026
CVE-2025-55251LOW 3.1

HCL AION is affected by an Unrestricted File Upload vulnerability. This can allow malicious file uploads, potentially resulting in unauthorized code execution or system compromise.

1/19/2026
CVE-2025-14894CRITICAL 9.8

Livewire Filemanager, commonly used in Laravel applications, contains LivewireFilemanagerComponent.php, which does not perform file type and MIME validation, allowing for RCE through upload of a malicious php file that can then be executed via the /storage/ URL if a commonly performed setup process within Laravel applications has been completed.

1/16/2026
CVE-2022-50893CRITICAL 9.8

VIAVIWEB Wallpaper Admin 1.0 contains an unauthenticated remote code execution vulnerability in the image upload functionality. Attackers can upload a malicious PHP file through the add_gallery_image.php endpoint to execute arbitrary code on the server.

1/13/2026

Similar SeverityHIGH