Vulnerability index

Browse CVEs

292 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Dynamips HIGH 7.5
CVE-2022-47012

Use of uninitialized variable in function gen_eth_recv in GNS3 dynamips 0.2.21.

No fix yet
Fix from $1,950 2023-01-20
Database Performance Analyzer HIGH 7.5
CVE-2022-38112

In DPA 2022.4 and older releases, generated heap memory dumps contain sensitive information in cleartext.

Fix: after 2022.4
Fix from $1,950 2023-01-20
Database Performance Analyzer MEDIUM 5.4
CVE-2022-38110

In Database Performance Analyzer (DPA) 2022.4 and older releases, certain URL vectors are susceptible to authenticated reflected cross-site scripting.

Fix: after 2022.4
Fix from $1,600 2023-01-20
Solarwinds Platform MEDIUM 5.5
CVE-2022-47512

Sensitive information was stored in plain text in a file that is accessible by a user with a local account in Hybrid Cloud Observability (HCO)/ Solar…

Mitigation only
Fix from $1,600 2022-12-19
Serv U MEDIUM 5.4
CVE-2022-38106

This vulnerability happens in the web client versions 15.3.0 to Serv-U 15.3.1. This vulnerability affects the directory creation function.

No fix yet
Fix from $1,600 2022-12-16
Serv U HIGH 7.5
CVE-2021-35252

Common encryption key appears to be used across all deployed instances of Serv-U FTP Server. Because of this an encrypted value that is exposed to an…

Fix: 15.3.2+
Fix from $1,950 2022-12-16
Orion Platform HIGH 8.8
CVE-2022-36960

SolarWinds Platform was susceptible to Improper Input Validation. This vulnerability allows a remote adversary with valid access to SolarWinds Web Co…

Fix: 2020.2.6+
Fix from $1,950 2022-11-29
Orion Platform HIGH 8.8
CVE-2022-36964EPSS 17%

SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with valid access to Solar…

Fix: 2020.2.6+
Fix from $1,950 2022-11-29
Orion Platform HIGH 7.2
CVE-2022-36962EPSS 9%

SolarWinds Platform was susceptible to Command Injection. This vulnerability allows a remote adversary with complete control over the SolarWinds data…

Fix: 2020.2.6+
Fix from $1,950 2022-11-29
Security Event Manager MEDIUM 6.1
CVE-2022-38114

This vulnerability occurs when a web server fails to correctly process the Content-Length of POST requests. This can lead to HTTP request smuggling o…

Fix: 2022.4+
Fix from $1,600 2022-11-23
Security Event Manager MEDIUM 5.3
CVE-2022-38113

This vulnerability discloses build and services versions in the server response header.

Mitigation only
Fix from $1,600 2022-11-23
Security Event Manager MEDIUM 5.3
CVE-2022-38115

Insecure method vulnerability in which allowed HTTP methods are disclosed. E.g., OPTIONS, DELETE, TRACE, and PUT

Fix: 2022.2+
Fix from $1,600 2022-11-23
Engineer\'s Toolset MEDIUM 5.3
CVE-2021-35246

The application fails to prevent users from connecting to it over unencrypted connections. An attacker able to modify a legitimate user's network tra…

Patch available
Fix from $1,600 2022-11-23
Orion Platform HIGH 7.2
CVE-2022-38108EPSS 68%

SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level acc…

Fix: 2020.2.6+
Fix from $1,950 2022-10-20
Orion Platform MEDIUM 5.4
CVE-2022-36966

Users with Node Management rights were able to view and edit all nodes due to Insufficient control on URL parameter causing insecure direct object re…

Fix: 2020.2.6+
Fix from $1,600 2022-10-20
Orion Platform HIGH 8.8
CVE-2022-36958EPSS 83%

SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with valid access to Solar…

Fix: 2020.2.6+
Fix from $1,950 2022-10-20
Orion Platform HIGH 7.2
CVE-2022-36957EPSS 12%

SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level acc…

Fix: 2020.2.6+
Fix from $1,950 2022-10-20
Sql Sentry MEDIUM 5.3
CVE-2022-38107

Sensitive information could be displayed when a detailed technical error message is posted. This information could disclose environmental details.

Fix: after 2021.18.10
Fix from $1,600 2022-10-19
Network Configuration Manager MEDIUM 6.5
CVE-2021-35226

An entity in Network Configuration Manager product is misconfigured and exposing password field to Solarwinds Information Service (SWIS). Exposed cre…

Fix: after 2020.2.5
Fix from $1,600 2022-10-10
Orion Platform HIGH 8.8
CVE-2022-36961EPSS 75%

A vulnerable component of Orion Platform was vulnerable to SQL Injection, an authenticated attacker could leverage this for privilege escalation or r…

Fix: after 2022.2.0
Fix from $1,950 2022-09-30
Solarwinds Platform MEDIUM 6.1
CVE-2022-36965

Insufficient sanitization of inputs in QoE application input field could lead to stored and Dom based XSS attack. This issue is fixed and released in…

Fix: 2022.3.0+
Fix from $1,600 2022-09-30
Serv U HIGH 7.5
CVE-2021-35250EPSS 13%

A researcher reported a Directory Transversal Vulnerability in Serv-U 15.3. This may allow access to files relating to the Serv-U installation and se…

Mitigation only
Fix from $1,950 2022-04-25
Database Performance Analyzer MEDIUM 6.1
CVE-2021-35229

Cross-site scripting vulnerability is present in Database Performance Monitor 2022.1.7779 and previous versions when using a complex SQL query

Fix: 2022.2+
Fix from $1,600 2022-04-21
Webhelpdesk HIGH 8.8
CVE-2021-35254

SolarWinds received a report of a vulnerability related to an input that was not sanitized in WebHelpDesk. SolarWinds has removed this input field to…

Fix: 12.7.8+
Fix from $1,950 2022-03-25
Web Help Desk MEDIUM 5.3
CVE-2021-35251

Sensitive information could be displayed when a detailed technical error message is posted. This information could disclose environmental details abo…

Fix: 12.7.8+
Fix from $1,600 2022-03-10
Serv U MEDIUM 5.3
CVE-2021-35247 KEV

Serv-U web login screen to LDAP authentication was allowing characters that were not sufficiently sanitized. SolarWinds has updated the input mechani…

Fix: 15.3+
Fix from $1,600 2022-01-10
Webhelpdesk MEDIUM 6.1
CVE-2021-35232

Hard coded credentials discovered in SolarWinds Web Help Desk product. Through these credentials, the attacker with local access to the Web Help Desk…

Fix: after 12.7.6
Fix from $1,600 2021-12-27
Web Help Desk HIGH 7.5
CVE-2021-35243

The HTTP PUT and DELETE methods were enabled in the Web Help Desk web server (12.7.7 and earlier), allowing users to execute dangerous HTTP requests.…

Fix: after 12.7.7
Fix from $1,950 2021-12-23
Orion Platform HIGH 8.8
CVE-2021-35234

Numerous exposed dangerous functions within Orion Core has allows for read-only SQL injection leading to privileged escalation. An attacker with low-…

Fix: after 2020.2.5
Fix from $1,950 2021-12-20
Orion Platform HIGH 7.2
CVE-2021-35244EPSS 6%

The "Log alert to a file" action within action management enables any Orion Platform user with Orion alert management rights to write to any file. An…

Fix: 2020.2.6+
Fix from $1,950 2021-12-20