Vulnerability index

Browse CVEs

11 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Serv U HIGH 7.5
CVE-2026-28318 KEVEPSS 8%

SolarWinds Serv-U is susceptible to specially crafted POST requests that crash the Serv-U service without authentication using Content-Encoding: defl…

Fix: 15.5.4+
Fix from $1,950 2026-06-04
Web Help Desk CRITICAL 9.8
CVE-2025-40551 KEVEPSS 84%

SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, whi…

Fix: 2026.1+
Fix from $2,300 2026-01-28
Web Help Desk CRITICAL 9.8
CVE-2025-40536 KEVEPSS 72%

SolarWinds Web Help Desk was found to be susceptible to a security control bypass vulnerability that if exploited, could allow an unauthenticated att…

Fix: 2026.1+
Fix from $2,300 2026-01-28
Web Help Desk CRITICAL 9.8
CVE-2025-26399 KEVEPSS 88%

SolarWinds Web Help Desk was found to be susceptible to an unauthenticated AjaxProxy deserialization remote code execution vulnerability that, if exp…

Fix: after 12.8.6
Fix from $2,300 2025-09-23
Web Help Desk CRITICAL 9.1
CVE-2024-28987 KEVEPSS 93%

The SolarWinds Web Help Desk (WHD) software is affected by a hardcoded credential vulnerability, allowing remote unauthenticated user to access inter…

Fix: 12.8.3+
Fix from $2,300 2024-08-21
Web Help Desk CRITICAL 9.8
CVE-2024-28986 KEVEPSS 85%

SolarWinds Web Help Desk was found to be susceptible to a Java Deserialization Remote Code Execution vulnerability that, if exploited, would allow an…

Fix: after 12.8.2
Fix from $2,300 2024-08-13
Serv U HIGH 7.5
CVE-2024-28995 KEVEPSS 100%

SolarWinds Serv-U was susceptible to a directory transversal vulnerability that would allow access to read sensitive files on the host machine.

Fix: 15.4.2+
Fix from $1,950 2024-06-06
Serv U MEDIUM 5.3
CVE-2021-35247 KEV

Serv-U web login screen to LDAP authentication was allowing characters that were not sufficiently sanitized. SolarWinds has updated the input mechani…

Fix: 15.3+
Fix from $1,600 2022-01-10
Serv U CRITICAL 10.0
CVE-2021-35211 KEVEPSS 91%

Microsoft discovered a remote code execution (RCE) vulnerability in the SolarWinds Serv-U product utilizing a Remote Memory Escape Vulnerability. If …

Fix: 15.2.3+
Fix from $2,300 2021-07-14
Orion Platform CRITICAL 9.8
CVE-2020-10148 KEVEPSS 92%

The SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands. This vulnerability cou…

Mitigation only
Fix from $2,300 2020-12-29
Virtualization Manager HIGH 7.8
CVE-2016-3643 KEV

SolarWinds Virtualization Manager 6.3.1 and earlier allow local users to gain privileges by leveraging a misconfiguration of sudo, as demonstrated by…

Fix: after 6.3.1
Fix from $1,950 2016-06-17