Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.5
CVE-2022-47012
Use of uninitialized variable in function gen_eth_recv in GNS3 dynamips 0.2.21.
Dynamips
No fix yet
HIGH 7.5
CVE-2022-38112
In DPA 2022.4 and older releases, generated heap memory dumps contain sensitive information in cleartext.
Database Performance Analyzer
after 2022.4
MEDIUM 5.4
CVE-2022-38110
In Database Performance Analyzer (DPA) 2022.4 and older releases, certain URL vectors are susceptible to authenticated reflected cross-site scripting.
Database Performance Analyzer
after 2022.4
MEDIUM 5.5
CVE-2022-47512
Sensitive information was stored in plain text in a file that is accessible by a user with a local account in Hybrid Cloud Observability (HCO)/ Solar…
Solarwinds Platform
Mitigation only
MEDIUM 5.4
CVE-2022-38106
This vulnerability happens in the web client versions 15.3.0 to Serv-U 15.3.1. This vulnerability affects the directory creation function.
Serv U
No fix yet
HIGH 7.5
CVE-2021-35252
Common encryption key appears to be used across all deployed instances of Serv-U FTP Server. Because of this an encrypted value that is exposed to an…
Serv U
15.3.2+
HIGH 8.8
CVE-2022-36960
SolarWinds Platform was susceptible to Improper Input Validation. This vulnerability allows a remote adversary with valid access to SolarWinds Web Co…
Orion Platform
2020.2.6+
HIGH 8.8
CVE-2022-36964EPSS 17%
SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with valid access to Solar…
Orion Platform
2020.2.6+
HIGH 7.2
CVE-2022-36962EPSS 9%
SolarWinds Platform was susceptible to Command Injection. This vulnerability allows a remote adversary with complete control over the SolarWinds data…
Orion Platform
2020.2.6+
MEDIUM 6.1
CVE-2022-38114
This vulnerability occurs when a web server fails to correctly process the Content-Length of POST requests. This can lead to HTTP request smuggling o…
Security Event Manager
2022.4+
MEDIUM 5.3
CVE-2022-38113
This vulnerability discloses build and services versions in the server response header.
Security Event Manager
Mitigation only
MEDIUM 5.3
CVE-2022-38115
Insecure method vulnerability in which allowed HTTP methods are disclosed. E.g., OPTIONS, DELETE, TRACE, and PUT
Security Event Manager
2022.2+
MEDIUM 5.3
CVE-2021-35246
The application fails to prevent users from connecting to it over unencrypted connections. An attacker able to modify a legitimate user's network tra…
Engineer\'s Toolset
Patch available
HIGH 7.2
CVE-2022-38108EPSS 68%
SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level acc…
Orion Platform
2020.2.6+
MEDIUM 5.4
CVE-2022-36966
Users with Node Management rights were able to view and edit all nodes due to Insufficient control on URL parameter causing insecure direct object re…
Orion Platform
2020.2.6+
HIGH 8.8
CVE-2022-36958EPSS 83%
SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with valid access to Solar…
Orion Platform
2020.2.6+
HIGH 7.2
CVE-2022-36957EPSS 12%
SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level acc…
Orion Platform
2020.2.6+
MEDIUM 5.3
CVE-2022-38107
Sensitive information could be displayed when a detailed technical error message is posted. This information could disclose environmental details.
Sql Sentry
after 2021.18.10
MEDIUM 6.5
CVE-2021-35226
An entity in Network Configuration Manager product is misconfigured and exposing password field to Solarwinds Information Service (SWIS). Exposed cre…
Network Configuration Manager
after 2020.2.5
HIGH 8.8
CVE-2022-36961EPSS 75%
A vulnerable component of Orion Platform was vulnerable to SQL Injection, an authenticated attacker could leverage this for privilege escalation or r…
Orion Platform
after 2022.2.0
MEDIUM 6.1
CVE-2022-36965
Insufficient sanitization of inputs in QoE application input field could lead to stored and Dom based XSS attack. This issue is fixed and released in…
Solarwinds Platform
2022.3.0+
HIGH 7.5
CVE-2021-35250EPSS 13%
A researcher reported a Directory Transversal Vulnerability in Serv-U 15.3. This may allow access to files relating to the Serv-U installation and se…
Serv U
Mitigation only
MEDIUM 6.1
CVE-2021-35229
Cross-site scripting vulnerability is present in Database Performance Monitor 2022.1.7779 and previous versions when using a complex SQL query
Database Performance Analyzer
2022.2+
HIGH 8.8
CVE-2021-35254
SolarWinds received a report of a vulnerability related to an input that was not sanitized in WebHelpDesk. SolarWinds has removed this input field to…
Webhelpdesk
12.7.8+
MEDIUM 5.3
CVE-2021-35251
Sensitive information could be displayed when a detailed technical error message is posted. This information could disclose environmental details abo…
Web Help Desk
12.7.8+
MEDIUM 5.3
CVE-2021-35247 KEV
Serv-U web login screen to LDAP authentication was allowing characters that were not sufficiently sanitized. SolarWinds has updated the input mechani…
Serv U
15.3+
MEDIUM 6.1
CVE-2021-35232
Hard coded credentials discovered in SolarWinds Web Help Desk product. Through these credentials, the attacker with local access to the Web Help Desk…
Webhelpdesk
after 12.7.6
HIGH 7.5
CVE-2021-35243
The HTTP PUT and DELETE methods were enabled in the Web Help Desk web server (12.7.7 and earlier), allowing users to execute dangerous HTTP requests.…
Web Help Desk
after 12.7.7
HIGH 8.8
CVE-2021-35234
Numerous exposed dangerous functions within Orion Core has allows for read-only SQL injection leading to privileged escalation. An attacker with low-…
Orion Platform
after 2020.2.5
HIGH 7.2
CVE-2021-35244EPSS 6%
The "Log alert to a file" action within action management enables any Orion Platform user with Orion alert management rights to write to any file. An…
Orion Platform
2020.2.6+