Vulnerability index

Browse CVEs

292 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Orion Platform CRITICAL 9.8
CVE-2021-27258

This vulnerability allows remote attackers to execute escalate privileges on affected installations of SolarWinds Orion Platform 2020.2. Authenticati…

Mitigation only
Fix from $2,300 2021-04-14
Patch Manager HIGH 7.8
CVE-2021-27240

This vulnerability allows local attackers to escalate privileges on affected installations of SolarWinds Patch Manager 2020.2.1. An attacker must fir…

Mitigation only
Fix from $1,950 2021-03-29
Network Performance Monitor HIGH 8.8
CVE-2020-27869EPSS 5%

This vulnerability allows remote attackers to escalate privileges on affected installations of SolarWinds Network Performance Monitor 2020 HF1, NPM: …

Mitigation only
Fix from $1,950 2021-02-12
Orion Platform HIGH 7.2
CVE-2020-27871EPSS 90%

This vulnerability allows remote attackers to create arbitrary files on affected installations of SolarWinds Orion Platform 2020.2.1. Although authen…

Mitigation only
Fix from $1,950 2021-02-10
Orion Platform MEDIUM 6.5
CVE-2020-27870

This vulnerability allows remote attackers to disclose sensitive information on affected installations of SolarWinds Orion Platform 2020.2.1. Authent…

Mitigation only
Fix from $1,600 2021-02-10
Orion Platform CRITICAL 9.8
CVE-2021-25274EPSS 36%

The Collector Service in SolarWinds Orion Platform before 2020.2.4 uses MSMQ (Microsoft Message Queue) and doesn't set permissions on its private que…

Fix: 2020.2.4+
Fix from $2,300 2021-02-03
Orion Platform HIGH 7.8
CVE-2021-25275

SolarWinds Orion Platform before 2020.2.4, as used by various SolarWinds products, installs and uses a SQL Server backend, and stores database creden…

Fix: 2020.2.4+
Fix from $1,950 2021-02-03
Serv U HIGH 7.1
CVE-2021-25276

In SolarWinds Serv-U before 15.2.2 Hotfix 1, there is a directory containing user profile files (that include users' password hashes) that is world r…

Fix: 15.2.2+
Fix from $1,950 2021-02-03
Serv U CRITICAL 9.8
CVE-2020-35481

SolarWinds Serv-U before 15.2.2 allows Unauthenticated Macro Injection.

Fix: 15.2.2+
Fix from $2,300 2021-02-03
Serv U MEDIUM 5.4
CVE-2020-35482

SolarWinds Serv-U before 15.2.2 allows authenticated reflected XSS.

Fix: 15.2.2+
Fix from $1,600 2021-02-03
Serv U MEDIUM 6.5
CVE-2020-27994

SolarWinds Serv-U before 15.2.2 allows Authenticated Directory Traversal.

Fix: 15.2.2+
Fix from $1,600 2021-02-03
Serv U MEDIUM 5.4
CVE-2020-28001

SolarWinds Serv-U before 15.2.2 allows Authenticated Stored XSS.

Fix: 15.2.2+
Fix from $1,600 2021-02-03
Web Help Desk MEDIUM 5.4
CVE-2019-16961

SolarWinds Web Help Desk 12.7.0 allows XSS via a Schedule Name.

No fix yet
Fix from $1,600 2021-01-15
Web Help Desk MEDIUM 5.4
CVE-2019-16954

SolarWinds Web Help Desk 12.7.0 allows HTML injection via a Comment in a Help Request ticket.

No fix yet
Fix from $1,600 2021-01-06
Web Help Desk MEDIUM 5.4
CVE-2019-16956

SolarWinds Web Help Desk 12.7.0 allows XSS via the Request Type parameter of a ticket.

No fix yet
Fix from $1,600 2021-01-04
Web Help Desk MEDIUM 5.4
CVE-2019-16960

SolarWinds Web Help Desk 12.7.0 allows XSS via a CSV template file with a crafted Location Name field.

No fix yet
Fix from $1,600 2021-01-04
Orion Platform CRITICAL 9.8
CVE-2020-10148 KEVEPSS 92%

The SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands. This vulnerability cou…

Mitigation only
Fix from $2,300 2020-12-29
Webhelpdesk MEDIUM 6.5
CVE-2019-16959

SolarWinds Web Help Desk 12.7.0 allows CSV Injection, also known as Formula Injection, via a file attached to a ticket.

No fix yet
Fix from $1,600 2020-12-21
Webhelpdesk MEDIUM 5.4
CVE-2019-16955

SolarWinds Web Help Desk 12.7.0 allows XSS via an uploaded SVG document in a request.

No fix yet
Fix from $1,600 2020-12-18
Webhelpdesk MEDIUM 5.4
CVE-2019-16957

SolarWinds Web Help Desk 12.7.0 allows XSS via the First Name field of a User Account.

No fix yet
Fix from $1,600 2020-12-18
N Central HIGH 8.8
CVE-2020-25622

An issue was discovered in SolarWinds N-Central 12.3.0.670. The AdvancedScripts HTTP endpoint allows CSRF.

Mitigation only
Fix from $1,950 2020-12-16
N Central HIGH 8.4
CVE-2020-25621

An issue was discovered in SolarWinds N-Central 12.3.0.670. The local database does not require authentication: security is only based on ability to …

Mitigation only
Fix from $1,950 2020-12-16
N Central HIGH 7.8
CVE-2020-25620

An issue was discovered in SolarWinds N-Central 12.3.0.670. Hard-coded Credentials exist by default for local user accounts named [email protected]

Mitigation only
Fix from $1,950 2020-12-16
N Central HIGH 8.8
CVE-2020-25617

An issue was discovered in SolarWinds N-Central 12.3.0.670. The AdvancedScripts HTTP endpoint allows Relative Path Traversal by an authenticated user…

Mitigation only
Fix from $1,950 2020-12-16
N Central HIGH 8.8
CVE-2020-25618

An issue was discovered in SolarWinds N-Central 12.3.0.670. The sudo configuration has incorrect access control because the nable web user account is…

Mitigation only
Fix from $1,950 2020-12-16
Database Performance Analyzer MEDIUM 5.4
CVE-2018-16243

SolarWinds Database Performance Analyzer (DPA) 11.1.468 and 12.0.3074 have several persistent XSS vulnerabilities, related to logViewer.iwc, centralM…

Mitigation only
Fix from $1,600 2020-12-15
Help Desk MEDIUM 5.4
CVE-2019-16958

Cross-site Scripting (XSS) vulnerability in SolarWinds Web Help Desk 12.7.0 allows attacker to inject arbitrary web script or HTML via Location Name.

No fix yet
Fix from $1,600 2020-12-01
N Central HIGH 8.8
CVE-2020-15909

SolarWinds N-central through 2020.1 allows session hijacking and requires user interaction or physical access. The N-Central JSESSIONID cookie attrib…

Fix: after 2020.1
Fix from $1,950 2020-10-19
Orion Platform CRITICAL 9.0
CVE-2020-13169

Stored XSS (Cross-Site Scripting) exists in the SolarWinds Orion Platform before before 2020.2.1 on multiple forms and pages. This vulnerability may …

Fix: 2020.2.1+
Fix from $2,300 2020-09-17
Serv U HIGH 7.5
CVE-2020-15574

SolarWinds Serv-U File Server before 15.2.1 mishandles the Same-Site cookie attribute, aka Case Number 00331893.

Fix: 15.2.1+
Fix from $1,950 2020-07-07