Vulnerability index

Browse CVEs

67 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Webhelpdesk MEDIUM 5.4
CVE-2019-16957

SolarWinds Web Help Desk 12.7.0 allows XSS via the First Name field of a User Account.

No fix yet
Fix from $1,600 2020-12-18
N Central HIGH 8.8
CVE-2020-25622

An issue was discovered in SolarWinds N-Central 12.3.0.670. The AdvancedScripts HTTP endpoint allows CSRF.

Mitigation only
Fix from $1,950 2020-12-16
N Central HIGH 8.4
CVE-2020-25621

An issue was discovered in SolarWinds N-Central 12.3.0.670. The local database does not require authentication: security is only based on ability to …

Mitigation only
Fix from $1,950 2020-12-16
N Central HIGH 7.8
CVE-2020-25620

An issue was discovered in SolarWinds N-Central 12.3.0.670. Hard-coded Credentials exist by default for local user accounts named [email protected]

Mitigation only
Fix from $1,950 2020-12-16
N Central HIGH 8.8
CVE-2020-25617

An issue was discovered in SolarWinds N-Central 12.3.0.670. The AdvancedScripts HTTP endpoint allows Relative Path Traversal by an authenticated user…

Mitigation only
Fix from $1,950 2020-12-16
N Central HIGH 8.8
CVE-2020-25618

An issue was discovered in SolarWinds N-Central 12.3.0.670. The sudo configuration has incorrect access control because the nable web user account is…

Mitigation only
Fix from $1,950 2020-12-16
Database Performance Analyzer MEDIUM 5.4
CVE-2018-16243

SolarWinds Database Performance Analyzer (DPA) 11.1.468 and 12.0.3074 have several persistent XSS vulnerabilities, related to logViewer.iwc, centralM…

Mitigation only
Fix from $1,600 2020-12-15
Help Desk MEDIUM 5.4
CVE-2019-16958

Cross-site Scripting (XSS) vulnerability in SolarWinds Web Help Desk 12.7.0 allows attacker to inject arbitrary web script or HTML via Location Name.

No fix yet
Fix from $1,600 2020-12-01
Orion Network Performance Monitor HIGH 8.8
CVE-2020-14005EPSS 14%

Solarwinds Orion (with Web Console WPM 2019.4.1, and Orion Platform HF4 or NPM HF2 2019.4) allows remote attackers to execute arbitrary code via a de…

Mitigation only
Fix from $1,950 2020-06-24
Orion Network Performance Monitor MEDIUM 5.4
CVE-2020-14006

Solarwinds Orion (with Web Console WPM 2019.4.1, and Orion Platform HF4 or NPM HF2 2019.4) allows XSS via a Responsible Team.

No fix yet
Fix from $1,600 2020-06-24
Orion Network Performance Monitor MEDIUM 5.4
CVE-2020-14007

Solarwinds Orion (with Web Console WPM 2019.4.1, and Orion Platform HF4 or NPM HF2 2019.4) allows XSS via a name of an alert definition.

No fix yet
Fix from $1,600 2020-06-24
Netpath MEDIUM 5.5
CVE-2019-12864

SolarWinds Orion Platform 2018.4 HF3 (NPM 12.4, NetPath 1.1.4) is vulnerable to Information Leakage, because of improper error handling with stack tr…

No fix yet
Fix from $1,600 2020-05-04
Webhelpdesk HIGH 7.8
CVE-2019-20002

Formula Injection exists in the export feature in SolarWinds WebHelpDesk 12.7.1 via a value (provided by a low-privileged user in the Subject field o…

Mitigation only
Fix from $1,950 2020-04-27
Dameware HIGH 7.5
CVE-2020-5734EPSS 25%

Classic buffer overflow in SolarWinds Dameware allows a remote, unauthenticated attacker to cause a denial of service by sending a large 'SigPubkeyLe…

No fix yet
Fix from $1,950 2020-04-07
Network Performance Monitor Orion Platform 2018 Netpath MEDIUM 5.4
CVE-2019-12954

SolarWinds Network Performance Monitor (Orion Platform 2018, NPM 12.3, NetPath 1.1.3) allows XSS by authenticated users via a crafted onerror attribu…

No fix yet
Fix from $1,600 2020-02-17
Orion Platform MEDIUM 6.1
CVE-2019-17125

A Reflected Client Side Template Injection (CSTI) with Angular was discovered in the SolarWinds Orion Platform 2019.2 HF1 in many forms. An attacker …

Mitigation only
Fix from $1,600 2020-01-17
Orion Platform MEDIUM 6.1
CVE-2019-17127

A Stored Client Side Template Injection (CSTI) with Angular was discovered in the SolarWinds Orion Platform 2019.2 HF1 in many application forms. An …

Mitigation only
Fix from $1,600 2020-01-17
Serv U Ftp Server MEDIUM 5.4
CVE-2019-19829

A cross-site scripting (XSS) vulnerability exists in SolarWinds Serv-U FTP Server 15.1.7 in the email parameter, a different vulnerability than CVE-2…

No fix yet
Fix from $1,600 2019-12-18
Serv U Ftp Server MEDIUM 6.5
CVE-2019-13181

A CSV injection vulnerability exists in the web UI of SolarWinds Serv-U FTP Server v15.1.7.

No fix yet
Fix from $1,600 2019-12-16
Serv U Ftp Server MEDIUM 5.4
CVE-2019-13182EPSS 6%

A stored cross-site scripting (XSS) vulnerability exists in the web UI of SolarWinds Serv-U FTP Server 15.1.7.

No fix yet
Fix from $1,600 2019-12-16
Dameware Mini Remote Control CRITICAL 9.8
CVE-2019-3980EPSS 5%

The Solarwinds Dameware Mini Remote Client agent v12.1.0.89 supports smart card authentication which can allow a user to upload an executable to be e…

No fix yet
Fix from $2,300 2019-10-08
Database Performance Analyzer MEDIUM 6.1
CVE-2018-19386EPSS 9%

SolarWinds Database Performance Analyzer 11.1.457 contains an instance of Reflected XSS in its idcStateError component, where the page parameter is r…

No fix yet
Fix from $1,600 2019-08-14
Serv U Ftp Server HIGH 7.8
CVE-2018-19999

The local management interface in SolarWinds Serv-U FTP Server 15.1.6.25 has incorrect access controls that permit local users to bypass authenticati…

Mitigation only
Fix from $1,950 2019-06-07
Dameware Mini Remote Control HIGH 7.5
CVE-2019-9017EPSS 21%

DWRCC in SolarWinds DameWare Mini Remote Control 10.0 x64 has a Buffer Overflow associated with the size field for the machine name.

No fix yet
Fix from $1,950 2019-05-02
Serv U Ftp Server HIGH 7.2
CVE-2018-15906EPSS 8%

SolarWinds Serv-U FTP Server 15.1.6 allows remote authenticated users to execute arbitrary code by leveraging the Import feature and modifying a CSV …

No fix yet
Fix from $1,950 2019-03-21
Ftp Voyager HIGH 8.8
CVE-2017-6803

Multiple cross-site request forgery (CSRF) vulnerabilities in the web interface in the Scheduler in SolarWinds (formerly Serv-U) FTP Voyager 16.2.0 a…

No fix yet
Fix from $1,950 2017-03-20
Log And Event Manager HIGH 7.5
CVE-2015-7839EPSS 7%

SolarWinds Log and Event Manager (LEM) allows remote attackers to execute arbitrary commands on managed computers via a request to services/messagebr…

Mitigation only
Fix from $1,950 2015-10-15
Storage Manager HIGH 10.0
CVE-2015-5371EPSS 93%

The AuthenticationFilter class in SolarWinds Storage Manager allows remote attackers to upload and execute arbitrary scripts via unspecified vectors.

Mitigation only
Fix from $1,950 2015-07-06
Server And Application Monitor MEDIUM 6.8
CVE-2015-1501EPSS 7%

The factory.loadExtensionFactory function in TSUnicodeGraphEditorControl in SolarWinds Server and Application Monitor (SAM) allow remote attackers to…

Mitigation only
Fix from $1,600 2015-02-16
Tftp Server MEDIUM 5.0
CVE-2010-2310EPSS 11%

SolarWinds TFTP Server 10.4.0.13 allows remote attackers to cause a denial of service (crash) via a long write request.

No fix yet
Fix from $1,600 2010-06-16