Vulnerability index

Browse CVEs

292 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2022-47012 Use of uninitialized variable in function gen_eth_recv in GNS3 dynamips 0.2.21. Dynamips No fix yet Fix from $1,9502023-01-20 HIGH 7.5 CVE-2022-38112 In DPA 2022.4 and older releases, generated heap memory dumps contain sensitive information in cleartext. Database Performance Analyzer after 2022.4 Fix from $1,9502023-01-20 MEDIUM 5.4 CVE-2022-38110 In Database Performance Analyzer (DPA) 2022.4 and older releases, certain URL vectors are susceptible to authenticated reflected cross-site scripting. Database Performance Analyzer after 2022.4 Fix from $1,6002023-01-20 MEDIUM 5.5 CVE-2022-47512 Sensitive information was stored in plain text in a file that is accessible by a user with a local account in Hybrid Cloud Observability (HCO)/ Solar… Solarwinds Platform Mitigation only Fix from $1,6002022-12-19 MEDIUM 5.4 CVE-2022-38106 This vulnerability happens in the web client versions 15.3.0 to Serv-U 15.3.1. This vulnerability affects the directory creation function. Serv U No fix yet Fix from $1,6002022-12-16 HIGH 7.5 CVE-2021-35252 Common encryption key appears to be used across all deployed instances of Serv-U FTP Server. Because of this an encrypted value that is exposed to an… Serv U 15.3.2+ Fix from $1,9502022-12-16 HIGH 8.8 CVE-2022-36960 SolarWinds Platform was susceptible to Improper Input Validation. This vulnerability allows a remote adversary with valid access to SolarWinds Web Co… Orion Platform 2020.2.6+ Fix from $1,9502022-11-29 HIGH 8.8 CVE-2022-36964EPSS 17% SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with valid access to Solar… Orion Platform 2020.2.6+ Fix from $1,9502022-11-29 HIGH 7.2 CVE-2022-36962EPSS 9% SolarWinds Platform was susceptible to Command Injection. This vulnerability allows a remote adversary with complete control over the SolarWinds data… Orion Platform 2020.2.6+ Fix from $1,9502022-11-29 MEDIUM 6.1 CVE-2022-38114 This vulnerability occurs when a web server fails to correctly process the Content-Length of POST requests. This can lead to HTTP request smuggling o… Security Event Manager 2022.4+ Fix from $1,6002022-11-23 MEDIUM 5.3 CVE-2022-38113 This vulnerability discloses build and services versions in the server response header. Security Event Manager Mitigation only Fix from $1,6002022-11-23 MEDIUM 5.3 CVE-2022-38115 Insecure method vulnerability in which allowed HTTP methods are disclosed. E.g., OPTIONS, DELETE, TRACE, and PUT Security Event Manager 2022.2+ Fix from $1,6002022-11-23 MEDIUM 5.3 CVE-2021-35246 The application fails to prevent users from connecting to it over unencrypted connections. An attacker able to modify a legitimate user's network tra… Engineer\'s Toolset Patch available Fix from $1,6002022-11-23 HIGH 7.2 CVE-2022-38108EPSS 68% SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level acc… Orion Platform 2020.2.6+ Fix from $1,9502022-10-20 MEDIUM 5.4 CVE-2022-36966 Users with Node Management rights were able to view and edit all nodes due to Insufficient control on URL parameter causing insecure direct object re… Orion Platform 2020.2.6+ Fix from $1,6002022-10-20 HIGH 8.8 CVE-2022-36958EPSS 83% SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with valid access to Solar… Orion Platform 2020.2.6+ Fix from $1,9502022-10-20 HIGH 7.2 CVE-2022-36957EPSS 12% SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level acc… Orion Platform 2020.2.6+ Fix from $1,9502022-10-20 MEDIUM 5.3 CVE-2022-38107 Sensitive information could be displayed when a detailed technical error message is posted. This information could disclose environmental details. Sql Sentry after 2021.18.10 Fix from $1,6002022-10-19 MEDIUM 6.5 CVE-2021-35226 An entity in Network Configuration Manager product is misconfigured and exposing password field to Solarwinds Information Service (SWIS). Exposed cre… Network Configuration Manager after 2020.2.5 Fix from $1,6002022-10-10 HIGH 8.8 CVE-2022-36961EPSS 75% A vulnerable component of Orion Platform was vulnerable to SQL Injection, an authenticated attacker could leverage this for privilege escalation or r… Orion Platform after 2022.2.0 Fix from $1,9502022-09-30 MEDIUM 6.1 CVE-2022-36965 Insufficient sanitization of inputs in QoE application input field could lead to stored and Dom based XSS attack. This issue is fixed and released in… Solarwinds Platform 2022.3.0+ Fix from $1,6002022-09-30 HIGH 7.5 CVE-2021-35250EPSS 13% A researcher reported a Directory Transversal Vulnerability in Serv-U 15.3. This may allow access to files relating to the Serv-U installation and se… Serv U Mitigation only Fix from $1,9502022-04-25 MEDIUM 6.1 CVE-2021-35229 Cross-site scripting vulnerability is present in Database Performance Monitor 2022.1.7779 and previous versions when using a complex SQL query Database Performance Analyzer 2022.2+ Fix from $1,6002022-04-21 HIGH 8.8 CVE-2021-35254 SolarWinds received a report of a vulnerability related to an input that was not sanitized in WebHelpDesk. SolarWinds has removed this input field to… Webhelpdesk 12.7.8+ Fix from $1,9502022-03-25 MEDIUM 5.3 CVE-2021-35251 Sensitive information could be displayed when a detailed technical error message is posted. This information could disclose environmental details abo… Web Help Desk 12.7.8+ Fix from $1,6002022-03-10 MEDIUM 5.3 CVE-2021-35247 KEV Serv-U web login screen to LDAP authentication was allowing characters that were not sufficiently sanitized. SolarWinds has updated the input mechani… Serv U 15.3+ Fix from $1,6002022-01-10 MEDIUM 6.1 CVE-2021-35232 Hard coded credentials discovered in SolarWinds Web Help Desk product. Through these credentials, the attacker with local access to the Web Help Desk… Webhelpdesk after 12.7.6 Fix from $1,6002021-12-27 HIGH 7.5 CVE-2021-35243 The HTTP PUT and DELETE methods were enabled in the Web Help Desk web server (12.7.7 and earlier), allowing users to execute dangerous HTTP requests.… Web Help Desk after 12.7.7 Fix from $1,9502021-12-23 HIGH 8.8 CVE-2021-35234 Numerous exposed dangerous functions within Orion Core has allows for read-only SQL injection leading to privileged escalation. An attacker with low-… Orion Platform after 2020.2.5 Fix from $1,9502021-12-20 HIGH 7.2 CVE-2021-35244EPSS 6% The "Log alert to a file" action within action management enables any Orion Platform user with Orion alert management rights to write to any file. An… Orion Platform 2020.2.6+ Fix from $1,9502021-12-20