Vulnerability index

Browse CVEs

292 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Orion Platform CRITICAL 9.8
CVE-2019-9546

SolarWinds Orion Platform before 2018.4 Hotfix 2 allows privilege escalation through the RabbitMQ service.

Fix: 2018.4+
Fix from $2,300 2019-03-01
Orion Network Performance Monitor CRITICAL 9.8
CVE-2019-8917EPSS 36%

SolarWinds Orion NPM before 12.4 suffers from a SYSTEM remote code execution vulnerability in the OrionModuleEngine service. This service establishes…

Fix: 12.4+
Fix from $2,300 2019-02-18
Sftp\/scp Server CRITICAL 9.8
CVE-2018-16791

In SolarWinds SFTP/SCP Server through 2018-09-10, the configuration file is world readable and writable, and stores user passwords in an insecure man…

Fix: after 20180910
Fix from $2,300 2018-12-05
Sftp\/scp Server CRITICAL 9.1
CVE-2018-16792

SolarWinds SFTP/SCP server through 2018-09-10 is vulnerable to XXE via a world readable and writable configuration file that allows an attacker to ex…

Fix: after 2018-09-10
Fix from $2,300 2018-12-05
Dameware Mini Remote Control HIGH 7.8
CVE-2018-12897

SolarWinds DameWare Mini Remote Control before 12.1 has a Buffer Overflow.

Fix: 12.1+
Fix from $1,950 2018-09-07
Serv U HIGH 7.3
CVE-2018-10240

SolarWinds Serv-U MFT before 15.1.6 HFv1 assigns authenticated users a low-entropy session token that can be included in requests to the application …

Fix: after 15.1.6
Fix from $1,950 2018-05-16
Serv U MEDIUM 6.5
CVE-2018-10241

A denial of service vulnerability in SolarWinds Serv-U before 15.1.6 HFv1 allows an authenticated user to crash the application (with a NULL pointer …

Fix: after 15.1.6
Fix from $1,600 2018-05-16
Backup Profiler CRITICAL 9.8
CVE-2012-2576EPSS 59%

SQL injection vulnerability in the LoginServlet page in SolarWinds Storage Manager before 5.1.2, SolarWinds Storage Profiler before 5.1.2, and SolarW…

Fix: 5.1.2+
Fix from $2,300 2017-12-20
Log \& Event Manager CRITICAL 10.0
CVE-2017-7722EPSS 13%

In SolarWinds Log & Event Manager (LEM) before 6.3.1 Hotfix 4, a menu system is encountered when the SSH service is accessed with "cmc" and "password…

Patch available
Fix from $2,300 2017-04-12
Log \& Event Manager HIGH 8.8
CVE-2017-7647

SolarWinds Log & Event Manager (LEM) before 6.3.1 Hotfix 4 allows an authenticated user to execute arbitrary commands.

Fix: after 6.3.1
Fix from $1,950 2017-04-10
Log \& Event Manager MEDIUM 6.5
CVE-2017-7646

SolarWinds Log & Event Manager (LEM) before 6.3.1 Hotfix 4 allows an authenticated user to browse the server's filesystem and read the contents of ar…

Fix: after 6.3.1
Fix from $1,600 2017-04-10
Log And Event Manager HIGH 8.8
CVE-2017-5198

SolarWinds LEM (aka SIEM) before 6.3.1 has an incorrect sudo configuration, which allows local users to obtain root access by editing /usr/local/cont…

Fix: 6.3.1+
Fix from $1,950 2017-03-24
Log And Event Manager HIGH 8.8
CVE-2017-5199

The editbanner feature in SolarWinds LEM (aka SIEM) through 6.3.1 allows remote authenticated users to execute arbitrary code by editing /usr/local/c…

Fix: after 6.3.1
Fix from $1,950 2017-03-24
Ftp Voyager HIGH 8.8
CVE-2017-6803

Multiple cross-site request forgery (CSRF) vulnerabilities in the web interface in the Scheduler in SolarWinds (formerly Serv-U) FTP Voyager 16.2.0 a…

No fix yet
Fix from $1,950 2017-03-20
Virtualization Manager HIGH 7.8
CVE-2016-3643 KEV

SolarWinds Virtualization Manager 6.3.1 and earlier allow local users to gain privileges by leveraging a misconfiguration of sudo, as demonstrated by…

Fix: after 6.3.1
Fix from $1,950 2016-06-17
Virtualization Manager CRITICAL 9.8
CVE-2016-3642EPSS 13%

The RMI service in SolarWinds Virtualization Manager 6.3.1 and earlier allows remote attackers to execute arbitrary commands via a crafted serialized…

Fix: after 6.3.1
Fix from $2,300 2016-06-17
Storage Resource Monitor CRITICAL 9.8
CVE-2016-4350EPSS 70%

Multiple SQL injection vulnerabilities in the Web Services web server in SolarWinds Storage Resource Monitor (SRM) Profiler (formerly Storage Manager…

Fix: after 6.2.1
Fix from $2,300 2016-05-09
Dameware Mini Remote Control HIGH 7.5
CVE-2015-8220

Stack-based buffer overflow in the URI handler in DWRCC.exe in SolarWinds DameWare Mini Remote Control before 12.0 HotFix 1 allows remote attackers t…

Fix: after 12.0
Fix from $1,950 2015-11-17
Log And Event Manager HIGH 7.5
CVE-2015-7840

The command line management console (CMC) in SolarWinds Log and Event Manager (LEM) before 6.2.0 allows remote attackers to execute arbitrary code vi…

Fix: after 6.1
Fix from $1,950 2015-10-15
Log And Event Manager HIGH 7.5
CVE-2015-7839EPSS 7%

SolarWinds Log and Event Manager (LEM) allows remote attackers to execute arbitrary commands on managed computers via a request to services/messagebr…

Mitigation only
Fix from $1,950 2015-10-15
Storage Manager HIGH 10.0
CVE-2015-7838

ProcessFileUpload.jsp in SolarWinds Storage Manager before 6.2 allows remote attackers to upload and execute arbitrary files via unspecified vectors.

Fix: after 6.1
Fix from $1,950 2015-10-15
Storage Manager HIGH 10.0
CVE-2015-5371EPSS 93%

The AuthenticationFilter class in SolarWinds Storage Manager allows remote attackers to upload and execute arbitrary scripts via unspecified vectors.

Mitigation only
Fix from $1,950 2015-07-06
Firewall Security Manager HIGH 10.0
CVE-2015-2284EPSS 73%

userlogin.jsp in SolarWinds Firewall Security Manager (FSM) before 6.6.5 HotFix1 allows remote attackers to gain privileges and execute arbitrary cod…

Fix: after 6.6.5
Fix from $1,950 2015-03-24
Orion Ip Address Manager HIGH 7.5
CVE-2014-9566EPSS 48%

Multiple SQL injection vulnerabilities in the Manage Accounts page in the AccountManagement.asmx service in the Solarwinds Orion Platform 2015.1, as …

Fix: after 11.4
Fix from $1,950 2015-03-10
Server And Application Monitor MEDIUM 6.8
CVE-2015-1501EPSS 7%

The factory.loadExtensionFactory function in TSUnicodeGraphEditorControl in SolarWinds Server and Application Monitor (SAM) allow remote attackers to…

Mitigation only
Fix from $1,600 2015-02-16
Server And Application Monitor MEDIUM 6.8
CVE-2015-1500EPSS 8%

Multiple stack-based buffer overflows in the TSUnicodeGraphEditorControl in SolarWinds Server and Application Monitor (SAM) allow remote attackers to…

Patch available
Fix from $1,600 2015-02-16
Log And Event Manager HIGH 7.5
CVE-2014-5504EPSS 5%

SolarWinds Log and Event Manager before 6.0 uses "static" credentials, which makes it easier for remote attackers to obtain access to the database an…

Fix: after 5.7.0
Fix from $1,950 2014-09-04
Network Configuration Manager MEDIUM 6.8
CVE-2014-3459EPSS 12%

Heap-based buffer overflow in SolarWinds Network Configuration Manager (NCM) before 7.3 allows remote attackers to execute arbitrary code via the PEs…

Fix: after 7.2.2
Fix from $1,600 2014-08-07
Dameware Remote Support HIGH 9.3
CVE-2013-3249EPSS 6%

Stack-based buffer overflow in the "Add from text file" feature in the DameWare Exporter tool (DWExporter.exe) in DameWare Remote Support 10.0.0.372,…

Fix: after 10.0.0.372
Fix from $1,950 2014-03-20
Orion Network Performance Monitor MEDIUM 6.8
CVE-2012-2602EPSS 6%

Multiple cross-site request forgery (CSRF) vulnerabilities in SolarWinds Orion Network Performance Monitor (NPM) before 10.3.1 allow remote attackers…

Fix: after 10.2.2
Fix from $1,600 2012-08-12