Vulnerability index

Browse CVEs

292 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Serv U HIGH 7.5
CVE-2020-15576

SolarWinds Serv-U File Server before 15.2.1 allows information disclosure via an HTTP response.

Fix: 15.2.1+
Fix from $1,950 2020-07-07
Serv U MEDIUM 6.1
CVE-2020-15573

SolarWinds Serv-U File Server before 15.2.1 has a "Cross-script vulnerability," aka Case Numbers 00041778 and 00306421.

Fix: 15.2.1+
Fix from $1,600 2020-07-07
Serv U MEDIUM 6.1
CVE-2020-15575

SolarWinds Serv-U File Server before 15.2.1 allows XSS as demonstrated by Tenable Scan, aka Case Number 00484194.

Fix: 15.2.1+
Fix from $1,600 2020-07-07
Serv U Ftp Server CRITICAL 9.8
CVE-2020-15541EPSS 7%

SolarWinds Serv-U FTP server before 15.2.1 allows remote command execution.

Fix: 15.2.1+
Fix from $2,300 2020-07-05
Serv U Ftp Server CRITICAL 9.8
CVE-2020-15542

SolarWinds Serv-U FTP server before 15.2.1 mishandles the CHMOD command.

Fix: 15.2.1+
Fix from $2,300 2020-07-05
Serv U Ftp Server CRITICAL 9.8
CVE-2020-15543

SolarWinds Serv-U FTP server before 15.2.1 does not validate an argument path.

Fix: 15.2.1+
Fix from $2,300 2020-07-05
Orion Network Performance Monitor HIGH 8.8
CVE-2020-14005EPSS 14%

Solarwinds Orion (with Web Console WPM 2019.4.1, and Orion Platform HF4 or NPM HF2 2019.4) allows remote attackers to execute arbitrary code via a de…

Mitigation only
Fix from $1,950 2020-06-24
Orion Network Performance Monitor MEDIUM 5.4
CVE-2020-14006

Solarwinds Orion (with Web Console WPM 2019.4.1, and Orion Platform HF4 or NPM HF2 2019.4) allows XSS via a Responsible Team.

No fix yet
Fix from $1,600 2020-06-24
Orion Network Performance Monitor MEDIUM 5.4
CVE-2020-14007

Solarwinds Orion (with Web Console WPM 2019.4.1, and Orion Platform HF4 or NPM HF2 2019.4) allows XSS via a name of an alert definition.

No fix yet
Fix from $1,600 2020-06-24
Advanced Monitoring Agent HIGH 7.3
CVE-2020-13912

SolarWinds Advanced Monitoring Agent before 10.8.9 allows local users to gain privileges via a Trojan horse .exe file, because everyone can write to …

Fix: 10.8.9+
Fix from $1,950 2020-06-07
Managed Service Provider Patch Management Engine HIGH 7.8
CVE-2020-12608EPSS 22%

An issue was discovered in SolarWinds MSP PME (Patch Management Engine) Cache Service before 1.1.15 in the Advanced Monitoring Agent. There are insec…

Fix: 1.1.15+
Fix from $1,950 2020-05-07
Netpath MEDIUM 5.5
CVE-2019-12864

SolarWinds Orion Platform 2018.4 HF3 (NPM 12.4, NetPath 1.1.4) is vulnerable to Information Leakage, because of improper error handling with stack tr…

No fix yet
Fix from $1,600 2020-05-04
Webhelpdesk HIGH 7.8
CVE-2019-20002

Formula Injection exists in the export feature in SolarWinds WebHelpDesk 12.7.1 via a value (provided by a low-privileged user in the Subject field o…

Mitigation only
Fix from $1,950 2020-04-27
Dameware HIGH 7.5
CVE-2020-5734EPSS 25%

Classic buffer overflow in SolarWinds Dameware allows a remote, unauthenticated attacker to cause a denial of service by sending a large 'SigPubkeyLe…

No fix yet
Fix from $1,950 2020-04-07
Serv U Managed File Transfer HIGH 8.8
CVE-2019-12769

SolarWinds Serv-U Managed File Transfer (MFT) Web client before 15.1.6 Hotfix 2 is vulnerable to Cross-Site Request Forgery in the file upload functi…

Fix: after 15.1.5
Fix from $1,950 2020-03-18
Network Performance Monitor Orion Platform 2018 Netpath MEDIUM 5.4
CVE-2019-12954

SolarWinds Network Performance Monitor (Orion Platform 2018, NPM 12.3, NetPath 1.1.3) allows XSS by authenticated users via a crafted onerror attribu…

No fix yet
Fix from $1,600 2020-02-17
N Central HIGH 7.5
CVE-2020-7984

SolarWinds N-central before 12.1 SP1 HF5 and 12.2 before SP1 HF2 allows remote attackers to retrieve cleartext domain admin credentials from the Agen…

Fix: 12.1.1.404 / 12.2.1.280+
Fix from $1,950 2020-01-26
Orion Platform MEDIUM 6.1
CVE-2019-17125

A Reflected Client Side Template Injection (CSTI) with Angular was discovered in the SolarWinds Orion Platform 2019.2 HF1 in many forms. An attacker …

Mitigation only
Fix from $1,600 2020-01-17
Orion Platform MEDIUM 6.1
CVE-2019-17127

A Stored Client Side Template Injection (CSTI) with Angular was discovered in the SolarWinds Orion Platform 2019.2 HF1 in many application forms. An …

Mitigation only
Fix from $1,600 2020-01-17
Serv U Ftp Server MEDIUM 5.4
CVE-2019-19829

A cross-site scripting (XSS) vulnerability exists in SolarWinds Serv-U FTP Server 15.1.7 in the email parameter, a different vulnerability than CVE-2…

No fix yet
Fix from $1,600 2019-12-18
Serv U Ftp Server MEDIUM 6.5
CVE-2019-13181

A CSV injection vulnerability exists in the web UI of SolarWinds Serv-U FTP Server v15.1.7.

No fix yet
Fix from $1,600 2019-12-16
Serv U Ftp Server MEDIUM 5.4
CVE-2019-13182EPSS 6%

A stored cross-site scripting (XSS) vulnerability exists in the web UI of SolarWinds Serv-U FTP Server 15.1.7.

No fix yet
Fix from $1,600 2019-12-16
Dameware Mini Remote Control CRITICAL 9.8
CVE-2019-3980EPSS 5%

The Solarwinds Dameware Mini Remote Client agent v12.1.0.89 supports smart card authentication which can allow a user to upload an executable to be e…

No fix yet
Fix from $2,300 2019-10-08
Database Performance Analyzer MEDIUM 6.1
CVE-2018-19386EPSS 9%

SolarWinds Database Performance Analyzer 11.1.457 contains an instance of Reflected XSS in its idcStateError component, where the page parameter is r…

No fix yet
Fix from $1,600 2019-08-14
Network Performance Monitor HIGH 8.8
CVE-2018-13442

SolarWinds Network Performance Monitor 12.3 allows SQL Injection via the /api/ActiveAlertsOnThisEntity/GetActiveAlerts TriggeringObjectEntityNames pa…

Fix: after 12.3
Fix from $1,950 2019-07-16
Serv U Ftp Server HIGH 8.8
CVE-2019-12181EPSS 66%

A privilege escalation vulnerability exists in SolarWinds Serv-U before 15.1.7 for Linux.

Fix: 15.1.7+
Fix from $1,950 2019-06-17
Dameware Mini Remote Control HIGH 7.4
CVE-2019-3957EPSS 26%

Dameware Remote Mini Control version 12.1.0.34 and prior contains an unauthenticated remote buffer over-read due to the server not properly validatin…

Fix: after 12.1.0.34
Fix from $1,950 2019-06-07
Serv U Ftp Server HIGH 7.8
CVE-2018-19999

The local management interface in SolarWinds Serv-U FTP Server 15.1.6.25 has incorrect access controls that permit local users to bypass authenticati…

Mitigation only
Fix from $1,950 2019-06-07
Dameware Mini Remote Control HIGH 7.5
CVE-2019-9017EPSS 21%

DWRCC in SolarWinds DameWare Mini Remote Control 10.0 x64 has a Buffer Overflow associated with the size field for the machine name.

No fix yet
Fix from $1,950 2019-05-02
Serv U Ftp Server HIGH 7.2
CVE-2018-15906EPSS 8%

SolarWinds Serv-U FTP Server 15.1.6 allows remote authenticated users to execute arbitrary code by leveraging the Import feature and modifying a CSV …

No fix yet
Fix from $1,950 2019-03-21