Vulnerability index

Browse CVEs

67 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.0 CVE-2023-40053 A vulnerability has been identified within Serv-U 15.4 that allows an authenticated actor to insert content on the file share function feature of Ser… Serv U Mitigation only Fix from $1,6002023-12-06 HIGH 7.2 CVE-2023-40060 A vulnerability has been identified within Serv-U 15.4 and 15.4 Hotfix 1 that, if exploited, allows an actor to bypass multi-factor/two-factor authen… Serv U Mitigation only Fix from $1,9502023-09-07 HIGH 7.2 CVE-2023-35179 A vulnerability has been identified within Serv-U 15.4 that, if exploited, allows an actor to bypass multi-factor/two-factor authentication. The acto… Serv U Mitigation only Fix from $1,9502023-08-11 HIGH 7.2 CVE-2023-23836EPSS 80% SolarWinds Platform version 2022.4.1 was found to be susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversa… Orion Platform Mitigation only Fix from $1,9502023-02-15 HIGH 7.8 CVE-2022-47506 SolarWinds Platform was susceptible to the Directory Traversal Vulnerability. This vulnerability allows a local adversary with authenticated account … Orion Platform Mitigation only Fix from $1,9502023-02-15 HIGH 7.5 CVE-2022-47508 Customers who had configured their polling to occur via Kerberos did not expect NTLM Traffic on their environment, but since we were querying for dat… Server And Application Monitor Mitigation only Fix from $1,9502023-02-15 HIGH 7.2 CVE-2022-47507EPSS 7% SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level acc… Orion Platform Mitigation only Fix from $1,9502023-02-15 HIGH 7.2 CVE-2022-38111EPSS 85% SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level acc… Orion Platform Mitigation only Fix from $1,9502023-02-15 HIGH 7.2 CVE-2022-47503EPSS 24% SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level acc… Orion Platform Mitigation only Fix from $1,9502023-02-15 HIGH 7.2 CVE-2022-47504EPSS 25% SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level acc… Orion Platform Mitigation only Fix from $1,9502023-02-15 HIGH 7.5 CVE-2022-47012 Use of uninitialized variable in function gen_eth_recv in GNS3 dynamips 0.2.21. Dynamips No fix yet Fix from $1,9502023-01-20 MEDIUM 5.5 CVE-2022-47512 Sensitive information was stored in plain text in a file that is accessible by a user with a local account in Hybrid Cloud Observability (HCO)/ Solar… Solarwinds Platform Mitigation only Fix from $1,6002022-12-19 MEDIUM 5.4 CVE-2022-38106 This vulnerability happens in the web client versions 15.3.0 to Serv-U 15.3.1. This vulnerability affects the directory creation function. Serv U No fix yet Fix from $1,6002022-12-16 MEDIUM 5.3 CVE-2022-38113 This vulnerability discloses build and services versions in the server response header. Security Event Manager Mitigation only Fix from $1,6002022-11-23 HIGH 7.5 CVE-2021-35250EPSS 13% A researcher reported a Directory Transversal Vulnerability in Serv-U 15.3. This may allow access to files relating to the Serv-U installation and se… Serv U Mitigation only Fix from $1,9502022-04-25 CRITICAL 9.1 CVE-2021-31217 In SolarWinds DameWare Mini Remote Control Server 12.0.1.200, insecure file permissions allow file deletion as SYSTEM. Dameware Mini Remote Control Mitigation only Fix from $2,3002021-07-13 HIGH 8.8 CVE-2021-31475EPSS 6% This vulnerability allows remote attackers to execute arbitrary code on affected installations of SolarWinds Orion Job Scheduler 2020.2.1 HF 2. Authe… Orion Job Scheduler Mitigation only Fix from $1,9502021-05-21 HIGH 7.8 CVE-2021-27277 This vulnerability allows local attackers to escalate privileges on affected installations of SolarWinds Orion Virtual Infrastructure Monitor 2020.2.… Orion Platform Mitigation only Fix from $1,9502021-04-22 CRITICAL 9.8 CVE-2021-27258 This vulnerability allows remote attackers to execute escalate privileges on affected installations of SolarWinds Orion Platform 2020.2. Authenticati… Orion Platform Mitigation only Fix from $2,3002021-04-14 HIGH 7.8 CVE-2021-27240 This vulnerability allows local attackers to escalate privileges on affected installations of SolarWinds Patch Manager 2020.2.1. An attacker must fir… Patch Manager Mitigation only Fix from $1,9502021-03-29 HIGH 8.8 CVE-2020-27869EPSS 5% This vulnerability allows remote attackers to escalate privileges on affected installations of SolarWinds Network Performance Monitor 2020 HF1, NPM: … Network Performance Monitor Mitigation only Fix from $1,9502021-02-12 HIGH 7.2 CVE-2020-27871EPSS 90% This vulnerability allows remote attackers to create arbitrary files on affected installations of SolarWinds Orion Platform 2020.2.1. Although authen… Orion Platform Mitigation only Fix from $1,9502021-02-10 MEDIUM 6.5 CVE-2020-27870 This vulnerability allows remote attackers to disclose sensitive information on affected installations of SolarWinds Orion Platform 2020.2.1. Authent… Orion Platform Mitigation only Fix from $1,6002021-02-10 MEDIUM 5.4 CVE-2019-16961 SolarWinds Web Help Desk 12.7.0 allows XSS via a Schedule Name. Web Help Desk No fix yet Fix from $1,6002021-01-15 MEDIUM 5.4 CVE-2019-16954 SolarWinds Web Help Desk 12.7.0 allows HTML injection via a Comment in a Help Request ticket. Web Help Desk No fix yet Fix from $1,6002021-01-06 MEDIUM 5.4 CVE-2019-16956 SolarWinds Web Help Desk 12.7.0 allows XSS via the Request Type parameter of a ticket. Web Help Desk No fix yet Fix from $1,6002021-01-04 MEDIUM 5.4 CVE-2019-16960 SolarWinds Web Help Desk 12.7.0 allows XSS via a CSV template file with a crafted Location Name field. Web Help Desk No fix yet Fix from $1,6002021-01-04 CRITICAL 9.8 CVE-2020-10148 KEVEPSS 92% The SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands. This vulnerability cou… Orion Platform Mitigation only Fix from $2,3002020-12-29 MEDIUM 6.5 CVE-2019-16959 SolarWinds Web Help Desk 12.7.0 allows CSV Injection, also known as Formula Injection, via a file attached to a ticket. Webhelpdesk No fix yet Fix from $1,6002020-12-21 MEDIUM 5.4 CVE-2019-16955 SolarWinds Web Help Desk 12.7.0 allows XSS via an uploaded SVG document in a request. Webhelpdesk No fix yet Fix from $1,6002020-12-18