Vulnerability index

Browse CVEs

292 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2025-40536 KEVEPSS 72% SolarWinds Web Help Desk was found to be susceptible to a security control bypass vulnerability that if exploited, could allow an unauthenticated att… Web Help Desk 2026.1+ Fix from $2,3002026-01-28 CRITICAL 9.1 CVE-2025-40548 A missing validation process exists in Serv U when abused, could give a malicious actor with access to admin privileges the ability to execute code. … Serv U 15.5.3+ Fix from $2,3002025-11-18 CRITICAL 9.1 CVE-2025-40549 A Path Restriction Bypass vulnerability exists in Serv-U that when abused, could give a malicious actor with access to admin privileges the ability t… Serv U 15.5.3+ Fix from $2,3002025-11-18 CRITICAL 9.1 CVE-2025-40547 A logic error vulnerability exists in Serv-U which when abused could give a malicious actor with access to admin privileges the ability to execute co… Serv U 15.5.3+ Fix from $2,3002025-11-18 MEDIUM 5.4 CVE-2025-26391 SolarWinds Observability Self-Hosted XSS Vulnerability. The SolarWinds Platform was susceptible to a XSS vulnerability that affects user-created URL … Observability Self Hosted 2025.4.1+ Fix from $1,6002025-11-18 CRITICAL 9.8 CVE-2025-26399 KEVEPSS 88% SolarWinds Web Help Desk was found to be susceptible to an unauthenticated AjaxProxy deserialization remote code execution vulnerability that, if exp… Web Help Desk after 12.8.6 Fix from $2,3002025-09-23 CRITICAL 9.8 CVE-2024-28988EPSS 39% SolarWinds Web Help Desk was found to be susceptible to a Java Deserialization Remote Code Execution vulnerability that, if exploited, would allow an… Web Help Desk after 12.8.2 Fix from $2,3002025-09-01 MEDIUM 6.4 CVE-2025-26398 SolarWinds Database Performance Analyzer was found to contain a hard-coded cryptographic key. If exploited, this vulnerability could lead to a machin… Database Performance Analyzer 2025.3+ Fix from $1,6002025-08-12 MEDIUM 6.5 CVE-2025-26400 SolarWinds Web Help Desk was reported to be affected by an XML External Entity Injection (XXE) vulnerability that could lead to information disclosur… Web Help Desk 12.8.7+ Fix from $1,6002025-07-29 HIGH 7.8 CVE-2025-26397 SolarWinds Observability Self-Hosted is susceptible to Deserialization of Untrusted Data Local Privilege Escalation vulnerability. An attacker with l… Observability Self Hosted 2025.2.1+ Fix from $1,9502025-07-24 MEDIUM 5.4 CVE-2024-45712 SolarWinds Serv-U is vulnerable to a client-side cross-site scripting (XSS) vulnerability. The vulnerability can only be performed by an authenticate… Serv U 15.5.1+ Fix from $1,6002025-04-15 CRITICAL 9.8 CVE-2024-52606 SolarWinds Platform is affected by server-side request forgery vulnerability. Proper input sanitation was not applied allowing for the possibility of… Solarwinds Platform 2025.1+ Fix from $2,3002025-02-11 MEDIUM 5.5 CVE-2024-28989 SolarWinds Web Help Desk was found to have a hardcoded cryptographic key that could allow the disclosure of sensitive information from the software. Web Help Desk 12.8.5+ Fix from $1,6002025-02-11 MEDIUM 5.5 CVE-2024-45709 SolarWinds Web Help Desk was susceptible to a local file read vulnerability. This vulnerability requires the software be installed on Linux and conf… Web Help Desk 12.8.4+ Fix from $1,6002024-12-10 MEDIUM 5.2 CVE-2024-45715 The SolarWinds Platform was susceptible to a Cross-Site Scripting vulnerability when performing an edit function to existing elements. Solarwinds Platform 2024.4+ Fix from $1,6002024-10-16 HIGH 8.8 CVE-2024-45711EPSS 6% SolarWinds Serv-U is vulnerable to a directory traversal vulnerability where remote code execution is possible depending on privileges given to the… Serv U 15.5+ Fix from $1,9502024-10-16 HIGH 7.8 CVE-2024-45710 SolarWinds Platform is susceptible to an Uncontrolled Search Path Element Local Privilege Escalation vulnerability. This requires a low privilege acc… Solarwinds Platform 2024.4+ Fix from $1,9502024-10-16 HIGH 8.8 CVE-2024-28990 SolarWinds Access Rights Manager (ARM) was found to contain a hard-coded credential authentication bypass vulnerability. If exploited, this vulnerabi… Access Rights Manager 2024.3.1+ Fix from $1,9502024-09-12 HIGH 8.0 CVE-2024-28991 SolarWinds Access Rights Manager (ARM) was found to be susceptible to a remote code execution vulnerability. If exploited, this vulnerability would a… Access Rights Manager 2024.3.1+ Fix from $1,9502024-09-12 CRITICAL 9.1 CVE-2024-28987 KEVEPSS 93% The SolarWinds Web Help Desk (WHD) software is affected by a hardcoded credential vulnerability, allowing remote unauthenticated user to access inter… Web Help Desk 12.8.3+ Fix from $2,3002024-08-21 CRITICAL 9.8 CVE-2024-28986 KEVEPSS 85% SolarWinds Web Help Desk was found to be susceptible to a Java Deserialization Remote Code Execution vulnerability that, if exploited, would allow an… Web Help Desk after 12.8.2 Fix from $2,3002024-08-13 HIGH 8.8 CVE-2024-23475 The SolarWinds Access Rights Manager was susceptible to a Directory Traversal and Information Disclosure Vulnerability. This vulnerability allows an … Access Rights Manager after 2023.2.4 Fix from $1,9502024-07-17 HIGH 8.8 CVE-2024-28074EPSS 11% It was discovered that a previous vulnerability was not completely fixed with SolarWinds Access Rights Manager. While some controls were implemented … Access Rights Manager after 2023.2.4 Fix from $1,9502024-07-17 HIGH 8.3 CVE-2024-28992 The SolarWinds Access Rights Manager was susceptible to a Directory Traversal and Information Disclosure Vulnerability. This vulnerability allows an … Access Rights Manager after 2023.2.4 Fix from $1,9502024-07-17 HIGH 8.3 CVE-2024-28993 The SolarWinds Access Rights Manager was susceptible to a Directory Traversal and Information Disclosure Vulnerability. This vulnerability allows an … Access Rights Manager 2024.3+ Fix from $1,9502024-07-17 HIGH 8.8 CVE-2024-23470 The SolarWinds Access Rights Manager was found to be susceptible to a pre-authentication remote code execution vulnerability. If exploited, this vuln… Access Rights Manager after 2023.2.4 Fix from $1,9502024-07-17 HIGH 8.8 CVE-2024-23471 The SolarWinds Access Rights Manager was found to be susceptible to a Remote Code Execution Vulnerability. If exploited, this vulnerability allows an… Access Rights Manager after 2023.2.4 Fix from $1,9502024-07-17 HIGH 8.8 CVE-2024-23474 The SolarWinds Access Rights Manager was found to be susceptible to an Arbitrary File Deletion and Information Disclosure vulnerability. Access Rights Manager after 2023.2.4 Fix from $1,9502024-07-17 HIGH 8.0 CVE-2024-23472EPSS 19% SolarWinds Access Rights Manager (ARM) is susceptible to Directory Traversal vulnerability. This vulnerability allows an authenticated user to arbitr… Access Rights Manager after 2023.2.4 Fix from $1,9502024-07-17 HIGH 8.8 CVE-2024-23466 SolarWinds Access Rights Manager (ARM) is susceptible to a Directory Traversal Remote Code Execution vulnerability. If exploited, this vulnerability … Access Rights Manager after 2023.2.4 Fix from $1,9502024-07-17