Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.0
CVE-2023-40053
A vulnerability has been identified within Serv-U 15.4 that allows an authenticated actor to insert content on the file share function feature of Ser…
Serv U
Mitigation only
HIGH 7.2
CVE-2023-40060
A vulnerability has been identified within Serv-U 15.4 and 15.4 Hotfix 1 that, if exploited, allows an actor to bypass multi-factor/two-factor authen…
Serv U
Mitigation only
HIGH 7.2
CVE-2023-35179
A vulnerability has been identified within Serv-U 15.4 that, if exploited, allows an actor to bypass multi-factor/two-factor authentication. The acto…
Serv U
Mitigation only
HIGH 7.2
CVE-2023-23836EPSS 80%
SolarWinds Platform version 2022.4.1 was found to be susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversa…
Orion Platform
Mitigation only
HIGH 7.8
CVE-2022-47506
SolarWinds Platform was susceptible to the Directory Traversal Vulnerability. This vulnerability allows a local adversary with authenticated account …
Orion Platform
Mitigation only
HIGH 7.5
CVE-2022-47508
Customers who had configured their polling to occur via Kerberos did not expect NTLM Traffic on their environment, but since we were querying for dat…
Server And Application Monitor
Mitigation only
HIGH 7.2
CVE-2022-47507EPSS 7%
SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level acc…
Orion Platform
Mitigation only
HIGH 7.2
CVE-2022-38111EPSS 85%
SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level acc…
Orion Platform
Mitigation only
HIGH 7.2
CVE-2022-47503EPSS 24%
SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level acc…
Orion Platform
Mitigation only
HIGH 7.2
CVE-2022-47504EPSS 25%
SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level acc…
Orion Platform
Mitigation only
HIGH 7.5
CVE-2022-47012
Use of uninitialized variable in function gen_eth_recv in GNS3 dynamips 0.2.21.
Dynamips
No fix yet
MEDIUM 5.5
CVE-2022-47512
Sensitive information was stored in plain text in a file that is accessible by a user with a local account in Hybrid Cloud Observability (HCO)/ Solar…
Solarwinds Platform
Mitigation only
MEDIUM 5.4
CVE-2022-38106
This vulnerability happens in the web client versions 15.3.0 to Serv-U 15.3.1. This vulnerability affects the directory creation function.
Serv U
No fix yet
MEDIUM 5.3
CVE-2022-38113
This vulnerability discloses build and services versions in the server response header.
Security Event Manager
Mitigation only
HIGH 7.5
CVE-2021-35250EPSS 13%
A researcher reported a Directory Transversal Vulnerability in Serv-U 15.3. This may allow access to files relating to the Serv-U installation and se…
Serv U
Mitigation only
CRITICAL 9.1
CVE-2021-31217
In SolarWinds DameWare Mini Remote Control Server 12.0.1.200, insecure file permissions allow file deletion as SYSTEM.
Dameware Mini Remote Control
Mitigation only
HIGH 8.8
CVE-2021-31475EPSS 6%
This vulnerability allows remote attackers to execute arbitrary code on affected installations of SolarWinds Orion Job Scheduler 2020.2.1 HF 2. Authe…
Orion Job Scheduler
Mitigation only
HIGH 7.8
CVE-2021-27277
This vulnerability allows local attackers to escalate privileges on affected installations of SolarWinds Orion Virtual Infrastructure Monitor 2020.2.…
Orion Platform
Mitigation only
CRITICAL 9.8
CVE-2021-27258
This vulnerability allows remote attackers to execute escalate privileges on affected installations of SolarWinds Orion Platform 2020.2. Authenticati…
Orion Platform
Mitigation only
HIGH 7.8
CVE-2021-27240
This vulnerability allows local attackers to escalate privileges on affected installations of SolarWinds Patch Manager 2020.2.1. An attacker must fir…
Patch Manager
Mitigation only
HIGH 8.8
CVE-2020-27869EPSS 5%
This vulnerability allows remote attackers to escalate privileges on affected installations of SolarWinds Network Performance Monitor 2020 HF1, NPM: …
Network Performance Monitor
Mitigation only
HIGH 7.2
CVE-2020-27871EPSS 90%
This vulnerability allows remote attackers to create arbitrary files on affected installations of SolarWinds Orion Platform 2020.2.1. Although authen…
Orion Platform
Mitigation only
MEDIUM 6.5
CVE-2020-27870
This vulnerability allows remote attackers to disclose sensitive information on affected installations of SolarWinds Orion Platform 2020.2.1. Authent…
Orion Platform
Mitigation only
MEDIUM 5.4
CVE-2019-16961
SolarWinds Web Help Desk 12.7.0 allows XSS via a Schedule Name.
Web Help Desk
No fix yet
MEDIUM 5.4
CVE-2019-16954
SolarWinds Web Help Desk 12.7.0 allows HTML injection via a Comment in a Help Request ticket.
Web Help Desk
No fix yet
MEDIUM 5.4
CVE-2019-16956
SolarWinds Web Help Desk 12.7.0 allows XSS via the Request Type parameter of a ticket.
Web Help Desk
No fix yet
MEDIUM 5.4
CVE-2019-16960
SolarWinds Web Help Desk 12.7.0 allows XSS via a CSV template file with a crafted Location Name field.
Web Help Desk
No fix yet
CRITICAL 9.8
CVE-2020-10148 KEVEPSS 92%
The SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands. This vulnerability cou…
Orion Platform
Mitigation only
MEDIUM 6.5
CVE-2019-16959
SolarWinds Web Help Desk 12.7.0 allows CSV Injection, also known as Formula Injection, via a file attached to a ticket.
Webhelpdesk
No fix yet
MEDIUM 5.4
CVE-2019-16955
SolarWinds Web Help Desk 12.7.0 allows XSS via an uploaded SVG document in a request.
Webhelpdesk
No fix yet