Vulnerability index

Browse CVEs

292 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2021-35242 Serv-U server responds with valid CSRFToken when the request contains only Session. Serv U 15.2.5+ Fix from $1,9502021-12-06 MEDIUM 6.8 CVE-2021-35245 When a user has admin rights in Serv-U Console, the user can move, create and delete any files are able to be accessed on the Serv-U host machine. Serv U 15.2.4+ Fix from $1,6002021-12-06 MEDIUM 5.3 CVE-2021-35233 The HTTP TRACK & TRACE methods were enabled in Kiwi Syslog Server 9.7.1 and earlier. These methods are intended for diagnostic purposes only. If enab… Kiwi Syslog Server after 9.7.2 Fix from $1,6002021-10-27 MEDIUM 5.3 CVE-2021-35235 The ASP.NET debug feature is enabled by default in Kiwi Syslog Server 9.7.2 and previous versions. ASP.NET allows remote debugging of web application… Kiwi Syslog Server after 9.7.2 Fix from $1,6002021-10-27 MEDIUM 5.3 CVE-2021-35236 The Secure flag is not set in the SSL Cookie of Kiwi Syslog Server 9.7.2 and previous versions. The Secure attribute tells the browser to only send t… Kiwi Syslog Server after 9.7.2 Fix from $1,6002021-10-27 MEDIUM 6.7 CVE-2021-35231 As a result of an unquoted service path vulnerability present in the Kiwi Syslog Server Installation Wizard, a local attacker could gain escalated pr… Kiwi Syslog Server 9.8+ Fix from $1,6002021-10-25 MEDIUM 6.7 CVE-2021-35230 As a result of an unquoted service path vulnerability present in the Kiwi CatTools Installation Wizard, a local attacker could gain escalated privile… Kiwi Cattools 3.11.9+ Fix from $1,6002021-10-22 HIGH 7.8 CVE-2021-35227 The HTTP interface was enabled for RabbitMQ Plugin in ARM 2020.2.6 and the ability to configure HTTPS was not available. Access Rights Manager after 2020.2.6 Fix from $1,9502021-10-21 MEDIUM 6.4 CVE-2021-35225 Each authenticated Orion Platform user in a MSP (Managed Service Provider) environment can view and browse all NetPath Services from all that MSP's c… Network Performance Monitor after 2020.2.6 Fix from $1,6002021-10-21 HIGH 8.8 CVE-2021-35217EPSS 73% Insecure Deseralization of untrusted data remote code execution vulnerability was discovered in Patch Manager Orion Platform Integration module and r… Patch Manager after 2020.2.5 Fix from $1,9502021-09-08 HIGH 8.8 CVE-2021-35215EPSS 70% Insecure deserialization leading to Remote Code Execution was detected in the Orion Platform version 2020.2.5. Authentication is required to exploit … Orion Platform after 2020.2.5 Fix from $1,9502021-09-01 HIGH 8.8 CVE-2021-35216EPSS 81% Insecure Deserialization of untrusted data remote code execution vulnerability was discovered in Patch Manager Orion Platform Integration module. An … Patch Manager 2020.2.6+ Fix from $1,9502021-09-01 HIGH 8.8 CVE-2021-35218EPSS 76% Deserialization of Untrusted Data in the Web Console Chart Endpoint can lead to remote code execution. An unauthorized attacker who has network acces… Orion Platform 2020.2.6+ Fix from $1,9502021-09-01 HIGH 8.8 CVE-2021-35212 An SQL injection Privilege Escalation Vulnerability was discovered in the Orion Platform reported by the ZDI Team. A blind Boolean SQL injection whic… Orion Platform Patch available Fix from $1,9502021-08-31 HIGH 8.8 CVE-2021-35213 An Improper Access Control Privilege Escalation Vulnerability was discovered in the User Setting of Orion Platform version 2020.2.5. It allows a gues… Orion Platform after 2020.2.5 Fix from $1,9502021-08-31 HIGH 8.8 CVE-2021-35223 The Serv-U File Server allows for events such as user login failures to be audited by executing a command. This command can be supplied with paramete… Serv U 15.2.4+ Fix from $1,9502021-08-31 MEDIUM 5.4 CVE-2021-35239 A security researcher found a user with Orion map manage rights could store XSS through via text box hyperlink. Orion Platform after 2020.2.5 Fix from $1,6002021-08-31 CRITICAL 9.6 CVE-2021-35222 This vulnerability allows attackers to impersonate users and perform arbitrary actions leading to a Remote Code Execution (RCE) from the Alerts Setti… Orion Platform 2020.2.6+ Fix from $2,3002021-08-31 HIGH 8.1 CVE-2021-35221 Improper Access Control Tampering Vulnerability using ImportAlert function which can lead to a Remote Code Execution (RCE) from the Alerts Settings p… Orion Platform 2020.2.6+ Fix from $1,9502021-08-31 HIGH 7.2 CVE-2021-35220 Command Injection vulnerability in EmailWebPage API which can lead to a Remote Code Execution (RCE) from the Alerts Settings page. Orion Platform 2020.2.6+ Fix from $1,9502021-08-31 MEDIUM 5.3 CVE-2021-32076 Access Restriction Bypass via referrer spoof was discovered in SolarWinds Web Help Desk 12.7.2. An attacker can access the 'Web Help Desk Getting Sta… Web Help Desk after 12.7.2 Fix from $1,6002021-08-26 MEDIUM 5.4 CVE-2021-28674 The node management page in SolarWinds Orion Platform before 2020.2.5 HF1 allows an attacker to create or delete a node (outside of the attacker's pe… Orion Platform after 2020.2.5 Fix from $1,6002021-07-30 CRITICAL 10.0 CVE-2021-35211 KEVEPSS 91% Microsoft discovered a remote code execution (RCE) vulnerability in the SolarWinds Serv-U product utilizing a Remote Memory Escape Vulnerability. If … Serv U 15.2.3+ Fix from $2,3002021-07-14 CRITICAL 9.1 CVE-2021-31217 In SolarWinds DameWare Mini Remote Control Server 12.0.1.200, insecure file permissions allow file deletion as SYSTEM. Dameware Mini Remote Control Mitigation only Fix from $2,3002021-07-13 CRITICAL 9.8 CVE-2021-31474EPSS 94% This vulnerability allows remote attackers to execute arbitrary code on affected installations of SolarWinds Network Performance Monitor 2020.2.1. Au… Network Performance Monitor 2020.2.5+ Fix from $2,3002021-05-21 HIGH 8.8 CVE-2021-31475EPSS 6% This vulnerability allows remote attackers to execute arbitrary code on affected installations of SolarWinds Orion Job Scheduler 2020.2.1 HF 2. Authe… Orion Job Scheduler Mitigation only Fix from $1,9502021-05-21 MEDIUM 5.4 CVE-2021-32604 Share/IncomingWizard.htm in SolarWinds Serv-U before 15.2.3 mishandles the user-supplied SenderEmail parameter, aka "Share URL XSS." Serv U 15.2.3+ Fix from $1,6002021-05-11 MEDIUM 6.1 CVE-2021-25179 SolarWinds Serv-U before 15.2 is affected by Cross Site Scripting (XSS) via the HTTP Host header. Serv U File Server 15.2+ Fix from $1,6002021-05-05 HIGH 7.5 CVE-2021-3154 An issue was discovered in SolarWinds Serv-U before 15.2.2. Unauthenticated attackers can retrieve cleartext passwords via macro Injection. NOTE: thi… Serv U 15.2.2+ Fix from $1,9502021-05-04 HIGH 7.8 CVE-2021-27277 This vulnerability allows local attackers to escalate privileges on affected installations of SolarWinds Orion Virtual Infrastructure Monitor 2020.2.… Orion Platform Mitigation only Fix from $1,9502021-04-22