Vulnerability index

Browse CVEs

292 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Web Help Desk CRITICAL 9.8
CVE-2025-40536 KEVEPSS 72%

SolarWinds Web Help Desk was found to be susceptible to a security control bypass vulnerability that if exploited, could allow an unauthenticated att…

Fix: 2026.1+
Fix from $2,300 2026-01-28
Serv U CRITICAL 9.1
CVE-2025-40548

A missing validation process exists in Serv U when abused, could give a malicious actor with access to admin privileges the ability to execute code. …

Fix: 15.5.3+
Fix from $2,300 2025-11-18
Serv U CRITICAL 9.1
CVE-2025-40549

A Path Restriction Bypass vulnerability exists in Serv-U that when abused, could give a malicious actor with access to admin privileges the ability t…

Fix: 15.5.3+
Fix from $2,300 2025-11-18
Serv U CRITICAL 9.1
CVE-2025-40547

A logic error vulnerability exists in Serv-U which when abused could give a malicious actor with access to admin privileges the ability to execute co…

Fix: 15.5.3+
Fix from $2,300 2025-11-18
Observability Self Hosted MEDIUM 5.4
CVE-2025-26391

SolarWinds Observability Self-Hosted XSS Vulnerability. The SolarWinds Platform was susceptible to a XSS vulnerability that affects user-created URL …

Fix: 2025.4.1+
Fix from $1,600 2025-11-18
Web Help Desk CRITICAL 9.8
CVE-2025-26399 KEVEPSS 88%

SolarWinds Web Help Desk was found to be susceptible to an unauthenticated AjaxProxy deserialization remote code execution vulnerability that, if exp…

Fix: after 12.8.6
Fix from $2,300 2025-09-23
Web Help Desk CRITICAL 9.8
CVE-2024-28988EPSS 39%

SolarWinds Web Help Desk was found to be susceptible to a Java Deserialization Remote Code Execution vulnerability that, if exploited, would allow an…

Fix: after 12.8.2
Fix from $2,300 2025-09-01
Database Performance Analyzer MEDIUM 6.4
CVE-2025-26398

SolarWinds Database Performance Analyzer was found to contain a hard-coded cryptographic key. If exploited, this vulnerability could lead to a machin…

Fix: 2025.3+
Fix from $1,600 2025-08-12
Web Help Desk MEDIUM 6.5
CVE-2025-26400

SolarWinds Web Help Desk was reported to be affected by an XML External Entity Injection (XXE) vulnerability that could lead to information disclosur…

Fix: 12.8.7+
Fix from $1,600 2025-07-29
Observability Self Hosted HIGH 7.8
CVE-2025-26397

SolarWinds Observability Self-Hosted is susceptible to Deserialization of Untrusted Data Local Privilege Escalation vulnerability. An attacker with l…

Fix: 2025.2.1+
Fix from $1,950 2025-07-24
Serv U MEDIUM 5.4
CVE-2024-45712

SolarWinds Serv-U is vulnerable to a client-side cross-site scripting (XSS) vulnerability. The vulnerability can only be performed by an authenticate…

Fix: 15.5.1+
Fix from $1,600 2025-04-15
Solarwinds Platform CRITICAL 9.8
CVE-2024-52606

SolarWinds Platform is affected by server-side request forgery vulnerability. Proper input sanitation was not applied allowing for the possibility of…

Fix: 2025.1+
Fix from $2,300 2025-02-11
Web Help Desk MEDIUM 5.5
CVE-2024-28989

SolarWinds Web Help Desk was found to have a hardcoded cryptographic key that could allow the disclosure of sensitive information from the software.

Fix: 12.8.5+
Fix from $1,600 2025-02-11
Web Help Desk MEDIUM 5.5
CVE-2024-45709

SolarWinds Web Help Desk was susceptible to a local file read vulnerability. This vulnerability requires the software be installed on Linux and conf…

Fix: 12.8.4+
Fix from $1,600 2024-12-10
Solarwinds Platform MEDIUM 5.2
CVE-2024-45715

The SolarWinds Platform was susceptible to a Cross-Site Scripting vulnerability when performing an edit function to existing elements.

Fix: 2024.4+
Fix from $1,600 2024-10-16
Serv U HIGH 8.8
CVE-2024-45711EPSS 6%

SolarWinds Serv-U is vulnerable to a directory traversal vulnerability where remote code execution is possible depending on privileges given to the…

Fix: 15.5+
Fix from $1,950 2024-10-16
Solarwinds Platform HIGH 7.8
CVE-2024-45710

SolarWinds Platform is susceptible to an Uncontrolled Search Path Element Local Privilege Escalation vulnerability. This requires a low privilege acc…

Fix: 2024.4+
Fix from $1,950 2024-10-16
Access Rights Manager HIGH 8.8
CVE-2024-28990

SolarWinds Access Rights Manager (ARM) was found to contain a hard-coded credential authentication bypass vulnerability. If exploited, this vulnerabi…

Fix: 2024.3.1+
Fix from $1,950 2024-09-12
Access Rights Manager HIGH 8.0
CVE-2024-28991

SolarWinds Access Rights Manager (ARM) was found to be susceptible to a remote code execution vulnerability. If exploited, this vulnerability would a…

Fix: 2024.3.1+
Fix from $1,950 2024-09-12
Web Help Desk CRITICAL 9.1
CVE-2024-28987 KEVEPSS 93%

The SolarWinds Web Help Desk (WHD) software is affected by a hardcoded credential vulnerability, allowing remote unauthenticated user to access inter…

Fix: 12.8.3+
Fix from $2,300 2024-08-21
Web Help Desk CRITICAL 9.8
CVE-2024-28986 KEVEPSS 85%

SolarWinds Web Help Desk was found to be susceptible to a Java Deserialization Remote Code Execution vulnerability that, if exploited, would allow an…

Fix: after 12.8.2
Fix from $2,300 2024-08-13
Access Rights Manager HIGH 8.8
CVE-2024-23475

The SolarWinds Access Rights Manager was susceptible to a Directory Traversal and Information Disclosure Vulnerability. This vulnerability allows an …

Fix: after 2023.2.4
Fix from $1,950 2024-07-17
Access Rights Manager HIGH 8.8
CVE-2024-28074EPSS 11%

It was discovered that a previous vulnerability was not completely fixed with SolarWinds Access Rights Manager. While some controls were implemented …

Fix: after 2023.2.4
Fix from $1,950 2024-07-17
Access Rights Manager HIGH 8.3
CVE-2024-28992

The SolarWinds Access Rights Manager was susceptible to a Directory Traversal and Information Disclosure Vulnerability. This vulnerability allows an …

Fix: after 2023.2.4
Fix from $1,950 2024-07-17
Access Rights Manager HIGH 8.3
CVE-2024-28993

The SolarWinds Access Rights Manager was susceptible to a Directory Traversal and Information Disclosure Vulnerability. This vulnerability allows an …

Fix: 2024.3+
Fix from $1,950 2024-07-17
Access Rights Manager HIGH 8.8
CVE-2024-23470

The SolarWinds Access Rights Manager was found to be susceptible to a pre-authentication remote code execution vulnerability. If exploited, this vuln…

Fix: after 2023.2.4
Fix from $1,950 2024-07-17
Access Rights Manager HIGH 8.8
CVE-2024-23471

The SolarWinds Access Rights Manager was found to be susceptible to a Remote Code Execution Vulnerability. If exploited, this vulnerability allows an…

Fix: after 2023.2.4
Fix from $1,950 2024-07-17
Access Rights Manager HIGH 8.8
CVE-2024-23474

The SolarWinds Access Rights Manager was found to be susceptible to an Arbitrary File Deletion and Information Disclosure vulnerability.

Fix: after 2023.2.4
Fix from $1,950 2024-07-17
Access Rights Manager HIGH 8.0
CVE-2024-23472EPSS 19%

SolarWinds Access Rights Manager (ARM) is susceptible to Directory Traversal vulnerability. This vulnerability allows an authenticated user to arbitr…

Fix: after 2023.2.4
Fix from $1,950 2024-07-17
Access Rights Manager HIGH 8.8
CVE-2024-23466

SolarWinds Access Rights Manager (ARM) is susceptible to a Directory Traversal Remote Code Execution vulnerability. If exploited, this vulnerability …

Fix: after 2023.2.4
Fix from $1,950 2024-07-17