Vulnerability index

Browse CVEs

67 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2019-16957 SolarWinds Web Help Desk 12.7.0 allows XSS via the First Name field of a User Account. Webhelpdesk No fix yet Fix from $1,6002020-12-18 HIGH 8.8 CVE-2020-25622 An issue was discovered in SolarWinds N-Central 12.3.0.670. The AdvancedScripts HTTP endpoint allows CSRF. N Central Mitigation only Fix from $1,9502020-12-16 HIGH 8.4 CVE-2020-25621 An issue was discovered in SolarWinds N-Central 12.3.0.670. The local database does not require authentication: security is only based on ability to … N Central Mitigation only Fix from $1,9502020-12-16 HIGH 7.8 CVE-2020-25620 An issue was discovered in SolarWinds N-Central 12.3.0.670. Hard-coded Credentials exist by default for local user accounts named [email protected] N Central Mitigation only Fix from $1,9502020-12-16 HIGH 8.8 CVE-2020-25617 An issue was discovered in SolarWinds N-Central 12.3.0.670. The AdvancedScripts HTTP endpoint allows Relative Path Traversal by an authenticated user… N Central Mitigation only Fix from $1,9502020-12-16 HIGH 8.8 CVE-2020-25618 An issue was discovered in SolarWinds N-Central 12.3.0.670. The sudo configuration has incorrect access control because the nable web user account is… N Central Mitigation only Fix from $1,9502020-12-16 MEDIUM 5.4 CVE-2018-16243 SolarWinds Database Performance Analyzer (DPA) 11.1.468 and 12.0.3074 have several persistent XSS vulnerabilities, related to logViewer.iwc, centralM… Database Performance Analyzer Mitigation only Fix from $1,6002020-12-15 MEDIUM 5.4 CVE-2019-16958 Cross-site Scripting (XSS) vulnerability in SolarWinds Web Help Desk 12.7.0 allows attacker to inject arbitrary web script or HTML via Location Name. Help Desk No fix yet Fix from $1,6002020-12-01 HIGH 8.8 CVE-2020-14005EPSS 14% Solarwinds Orion (with Web Console WPM 2019.4.1, and Orion Platform HF4 or NPM HF2 2019.4) allows remote attackers to execute arbitrary code via a de… Orion Network Performance Monitor Mitigation only Fix from $1,9502020-06-24 MEDIUM 5.4 CVE-2020-14006 Solarwinds Orion (with Web Console WPM 2019.4.1, and Orion Platform HF4 or NPM HF2 2019.4) allows XSS via a Responsible Team. Orion Network Performance Monitor No fix yet Fix from $1,6002020-06-24 MEDIUM 5.4 CVE-2020-14007 Solarwinds Orion (with Web Console WPM 2019.4.1, and Orion Platform HF4 or NPM HF2 2019.4) allows XSS via a name of an alert definition. Orion Network Performance Monitor No fix yet Fix from $1,6002020-06-24 MEDIUM 5.5 CVE-2019-12864 SolarWinds Orion Platform 2018.4 HF3 (NPM 12.4, NetPath 1.1.4) is vulnerable to Information Leakage, because of improper error handling with stack tr… Netpath No fix yet Fix from $1,6002020-05-04 HIGH 7.8 CVE-2019-20002 Formula Injection exists in the export feature in SolarWinds WebHelpDesk 12.7.1 via a value (provided by a low-privileged user in the Subject field o… Webhelpdesk Mitigation only Fix from $1,9502020-04-27 HIGH 7.5 CVE-2020-5734EPSS 25% Classic buffer overflow in SolarWinds Dameware allows a remote, unauthenticated attacker to cause a denial of service by sending a large 'SigPubkeyLe… Dameware No fix yet Fix from $1,9502020-04-07 MEDIUM 5.4 CVE-2019-12954 SolarWinds Network Performance Monitor (Orion Platform 2018, NPM 12.3, NetPath 1.1.3) allows XSS by authenticated users via a crafted onerror attribu… Network Performance Monitor Orion Platform 2018 Netpath No fix yet Fix from $1,6002020-02-17 MEDIUM 6.1 CVE-2019-17125 A Reflected Client Side Template Injection (CSTI) with Angular was discovered in the SolarWinds Orion Platform 2019.2 HF1 in many forms. An attacker … Orion Platform Mitigation only Fix from $1,6002020-01-17 MEDIUM 6.1 CVE-2019-17127 A Stored Client Side Template Injection (CSTI) with Angular was discovered in the SolarWinds Orion Platform 2019.2 HF1 in many application forms. An … Orion Platform Mitigation only Fix from $1,6002020-01-17 MEDIUM 5.4 CVE-2019-19829 A cross-site scripting (XSS) vulnerability exists in SolarWinds Serv-U FTP Server 15.1.7 in the email parameter, a different vulnerability than CVE-2… Serv U Ftp Server No fix yet Fix from $1,6002019-12-18 MEDIUM 6.5 CVE-2019-13181 A CSV injection vulnerability exists in the web UI of SolarWinds Serv-U FTP Server v15.1.7. Serv U Ftp Server No fix yet Fix from $1,6002019-12-16 MEDIUM 5.4 CVE-2019-13182EPSS 6% A stored cross-site scripting (XSS) vulnerability exists in the web UI of SolarWinds Serv-U FTP Server 15.1.7. Serv U Ftp Server No fix yet Fix from $1,6002019-12-16 CRITICAL 9.8 CVE-2019-3980EPSS 5% The Solarwinds Dameware Mini Remote Client agent v12.1.0.89 supports smart card authentication which can allow a user to upload an executable to be e… Dameware Mini Remote Control No fix yet Fix from $2,3002019-10-08 MEDIUM 6.1 CVE-2018-19386EPSS 9% SolarWinds Database Performance Analyzer 11.1.457 contains an instance of Reflected XSS in its idcStateError component, where the page parameter is r… Database Performance Analyzer No fix yet Fix from $1,6002019-08-14 HIGH 7.8 CVE-2018-19999 The local management interface in SolarWinds Serv-U FTP Server 15.1.6.25 has incorrect access controls that permit local users to bypass authenticati… Serv U Ftp Server Mitigation only Fix from $1,9502019-06-07 HIGH 7.5 CVE-2019-9017EPSS 21% DWRCC in SolarWinds DameWare Mini Remote Control 10.0 x64 has a Buffer Overflow associated with the size field for the machine name. Dameware Mini Remote Control No fix yet Fix from $1,9502019-05-02 HIGH 7.2 CVE-2018-15906EPSS 8% SolarWinds Serv-U FTP Server 15.1.6 allows remote authenticated users to execute arbitrary code by leveraging the Import feature and modifying a CSV … Serv U Ftp Server No fix yet Fix from $1,9502019-03-21 HIGH 8.8 CVE-2017-6803 Multiple cross-site request forgery (CSRF) vulnerabilities in the web interface in the Scheduler in SolarWinds (formerly Serv-U) FTP Voyager 16.2.0 a… Ftp Voyager No fix yet Fix from $1,9502017-03-20 HIGH 7.5 CVE-2015-7839EPSS 7% SolarWinds Log and Event Manager (LEM) allows remote attackers to execute arbitrary commands on managed computers via a request to services/messagebr… Log And Event Manager Mitigation only Fix from $1,9502015-10-15 HIGH 10.0 CVE-2015-5371EPSS 93% The AuthenticationFilter class in SolarWinds Storage Manager allows remote attackers to upload and execute arbitrary scripts via unspecified vectors. Storage Manager Mitigation only Fix from $1,9502015-07-06 MEDIUM 6.8 CVE-2015-1501EPSS 7% The factory.loadExtensionFactory function in TSUnicodeGraphEditorControl in SolarWinds Server and Application Monitor (SAM) allow remote attackers to… Server And Application Monitor Mitigation only Fix from $1,6002015-02-16 MEDIUM 5.0 CVE-2010-2310EPSS 11% SolarWinds TFTP Server 10.4.0.13 allows remote attackers to cause a denial of service (crash) via a long write request. Tftp Server No fix yet Fix from $1,6002010-06-16