Vulnerability index

Browse CVEs

292 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Serv U HIGH 8.8
CVE-2021-35242

Serv-U server responds with valid CSRFToken when the request contains only Session.

Fix: 15.2.5+
Fix from $1,950 2021-12-06
Serv U MEDIUM 6.8
CVE-2021-35245

When a user has admin rights in Serv-U Console, the user can move, create and delete any files are able to be accessed on the Serv-U host machine.

Fix: 15.2.4+
Fix from $1,600 2021-12-06
Kiwi Syslog Server MEDIUM 5.3
CVE-2021-35233

The HTTP TRACK & TRACE methods were enabled in Kiwi Syslog Server 9.7.1 and earlier. These methods are intended for diagnostic purposes only. If enab…

Fix: after 9.7.2
Fix from $1,600 2021-10-27
Kiwi Syslog Server MEDIUM 5.3
CVE-2021-35235

The ASP.NET debug feature is enabled by default in Kiwi Syslog Server 9.7.2 and previous versions. ASP.NET allows remote debugging of web application…

Fix: after 9.7.2
Fix from $1,600 2021-10-27
Kiwi Syslog Server MEDIUM 5.3
CVE-2021-35236

The Secure flag is not set in the SSL Cookie of Kiwi Syslog Server 9.7.2 and previous versions. The Secure attribute tells the browser to only send t…

Fix: after 9.7.2
Fix from $1,600 2021-10-27
Kiwi Syslog Server MEDIUM 6.7
CVE-2021-35231

As a result of an unquoted service path vulnerability present in the Kiwi Syslog Server Installation Wizard, a local attacker could gain escalated pr…

Fix: 9.8+
Fix from $1,600 2021-10-25
Kiwi Cattools MEDIUM 6.7
CVE-2021-35230

As a result of an unquoted service path vulnerability present in the Kiwi CatTools Installation Wizard, a local attacker could gain escalated privile…

Fix: 3.11.9+
Fix from $1,600 2021-10-22
Access Rights Manager HIGH 7.8
CVE-2021-35227

The HTTP interface was enabled for RabbitMQ Plugin in ARM 2020.2.6 and the ability to configure HTTPS was not available.

Fix: after 2020.2.6
Fix from $1,950 2021-10-21
Network Performance Monitor MEDIUM 6.4
CVE-2021-35225

Each authenticated Orion Platform user in a MSP (Managed Service Provider) environment can view and browse all NetPath Services from all that MSP's c…

Fix: after 2020.2.6
Fix from $1,600 2021-10-21
Patch Manager HIGH 8.8
CVE-2021-35217EPSS 73%

Insecure Deseralization of untrusted data remote code execution vulnerability was discovered in Patch Manager Orion Platform Integration module and r…

Fix: after 2020.2.5
Fix from $1,950 2021-09-08
Orion Platform HIGH 8.8
CVE-2021-35215EPSS 70%

Insecure deserialization leading to Remote Code Execution was detected in the Orion Platform version 2020.2.5. Authentication is required to exploit …

Fix: after 2020.2.5
Fix from $1,950 2021-09-01
Patch Manager HIGH 8.8
CVE-2021-35216EPSS 81%

Insecure Deserialization of untrusted data remote code execution vulnerability was discovered in Patch Manager Orion Platform Integration module. An …

Fix: 2020.2.6+
Fix from $1,950 2021-09-01
Orion Platform HIGH 8.8
CVE-2021-35218EPSS 76%

Deserialization of Untrusted Data in the Web Console Chart Endpoint can lead to remote code execution. An unauthorized attacker who has network acces…

Fix: 2020.2.6+
Fix from $1,950 2021-09-01
Orion Platform HIGH 8.8
CVE-2021-35212

An SQL injection Privilege Escalation Vulnerability was discovered in the Orion Platform reported by the ZDI Team. A blind Boolean SQL injection whic…

Patch available
Fix from $1,950 2021-08-31
Orion Platform HIGH 8.8
CVE-2021-35213

An Improper Access Control Privilege Escalation Vulnerability was discovered in the User Setting of Orion Platform version 2020.2.5. It allows a gues…

Fix: after 2020.2.5
Fix from $1,950 2021-08-31
Serv U HIGH 8.8
CVE-2021-35223

The Serv-U File Server allows for events such as user login failures to be audited by executing a command. This command can be supplied with paramete…

Fix: 15.2.4+
Fix from $1,950 2021-08-31
Orion Platform MEDIUM 5.4
CVE-2021-35239

A security researcher found a user with Orion map manage rights could store XSS through via text box hyperlink.

Fix: after 2020.2.5
Fix from $1,600 2021-08-31
Orion Platform CRITICAL 9.6
CVE-2021-35222

This vulnerability allows attackers to impersonate users and perform arbitrary actions leading to a Remote Code Execution (RCE) from the Alerts Setti…

Fix: 2020.2.6+
Fix from $2,300 2021-08-31
Orion Platform HIGH 8.1
CVE-2021-35221

Improper Access Control Tampering Vulnerability using ImportAlert function which can lead to a Remote Code Execution (RCE) from the Alerts Settings p…

Fix: 2020.2.6+
Fix from $1,950 2021-08-31
Orion Platform HIGH 7.2
CVE-2021-35220

Command Injection vulnerability in EmailWebPage API which can lead to a Remote Code Execution (RCE) from the Alerts Settings page.

Fix: 2020.2.6+
Fix from $1,950 2021-08-31
Web Help Desk MEDIUM 5.3
CVE-2021-32076

Access Restriction Bypass via referrer spoof was discovered in SolarWinds Web Help Desk 12.7.2. An attacker can access the 'Web Help Desk Getting Sta…

Fix: after 12.7.2
Fix from $1,600 2021-08-26
Orion Platform MEDIUM 5.4
CVE-2021-28674

The node management page in SolarWinds Orion Platform before 2020.2.5 HF1 allows an attacker to create or delete a node (outside of the attacker's pe…

Fix: after 2020.2.5
Fix from $1,600 2021-07-30
Serv U CRITICAL 10.0
CVE-2021-35211 KEVEPSS 91%

Microsoft discovered a remote code execution (RCE) vulnerability in the SolarWinds Serv-U product utilizing a Remote Memory Escape Vulnerability. If …

Fix: 15.2.3+
Fix from $2,300 2021-07-14
Dameware Mini Remote Control CRITICAL 9.1
CVE-2021-31217

In SolarWinds DameWare Mini Remote Control Server 12.0.1.200, insecure file permissions allow file deletion as SYSTEM.

Mitigation only
Fix from $2,300 2021-07-13
Network Performance Monitor CRITICAL 9.8
CVE-2021-31474EPSS 94%

This vulnerability allows remote attackers to execute arbitrary code on affected installations of SolarWinds Network Performance Monitor 2020.2.1. Au…

Fix: 2020.2.5+
Fix from $2,300 2021-05-21
Orion Job Scheduler HIGH 8.8
CVE-2021-31475EPSS 6%

This vulnerability allows remote attackers to execute arbitrary code on affected installations of SolarWinds Orion Job Scheduler 2020.2.1 HF 2. Authe…

Mitigation only
Fix from $1,950 2021-05-21
Serv U MEDIUM 5.4
CVE-2021-32604

Share/IncomingWizard.htm in SolarWinds Serv-U before 15.2.3 mishandles the user-supplied SenderEmail parameter, aka "Share URL XSS."

Fix: 15.2.3+
Fix from $1,600 2021-05-11
Serv U File Server MEDIUM 6.1
CVE-2021-25179

SolarWinds Serv-U before 15.2 is affected by Cross Site Scripting (XSS) via the HTTP Host header.

Fix: 15.2+
Fix from $1,600 2021-05-05
Serv U HIGH 7.5
CVE-2021-3154

An issue was discovered in SolarWinds Serv-U before 15.2.2. Unauthenticated attackers can retrieve cleartext passwords via macro Injection. NOTE: thi…

Fix: 15.2.2+
Fix from $1,950 2021-05-04
Orion Platform HIGH 7.8
CVE-2021-27277

This vulnerability allows local attackers to escalate privileges on affected installations of SolarWinds Orion Virtual Infrastructure Monitor 2020.2.…

Mitigation only
Fix from $1,950 2021-04-22