Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 8.8
CVE-2021-35242
Serv-U server responds with valid CSRFToken when the request contains only Session.
Serv U
15.2.5+
MEDIUM 6.8
CVE-2021-35245
When a user has admin rights in Serv-U Console, the user can move, create and delete any files are able to be accessed on the Serv-U host machine.
Serv U
15.2.4+
MEDIUM 5.3
CVE-2021-35233
The HTTP TRACK & TRACE methods were enabled in Kiwi Syslog Server 9.7.1 and earlier. These methods are intended for diagnostic purposes only. If enab…
Kiwi Syslog Server
after 9.7.2
MEDIUM 5.3
CVE-2021-35235
The ASP.NET debug feature is enabled by default in Kiwi Syslog Server 9.7.2 and previous versions. ASP.NET allows remote debugging of web application…
Kiwi Syslog Server
after 9.7.2
MEDIUM 5.3
CVE-2021-35236
The Secure flag is not set in the SSL Cookie of Kiwi Syslog Server 9.7.2 and previous versions. The Secure attribute tells the browser to only send t…
Kiwi Syslog Server
after 9.7.2
MEDIUM 6.7
CVE-2021-35231
As a result of an unquoted service path vulnerability present in the Kiwi Syslog Server Installation Wizard, a local attacker could gain escalated pr…
Kiwi Syslog Server
9.8+
MEDIUM 6.7
CVE-2021-35230
As a result of an unquoted service path vulnerability present in the Kiwi CatTools Installation Wizard, a local attacker could gain escalated privile…
Kiwi Cattools
3.11.9+
HIGH 7.8
CVE-2021-35227
The HTTP interface was enabled for RabbitMQ Plugin in ARM 2020.2.6 and the ability to configure HTTPS was not available.
Access Rights Manager
after 2020.2.6
MEDIUM 6.4
CVE-2021-35225
Each authenticated Orion Platform user in a MSP (Managed Service Provider) environment can view and browse all NetPath Services from all that MSP's c…
Network Performance Monitor
after 2020.2.6
HIGH 8.8
CVE-2021-35217EPSS 73%
Insecure Deseralization of untrusted data remote code execution vulnerability was discovered in Patch Manager Orion Platform Integration module and r…
Patch Manager
after 2020.2.5
HIGH 8.8
CVE-2021-35215EPSS 70%
Insecure deserialization leading to Remote Code Execution was detected in the Orion Platform version 2020.2.5. Authentication is required to exploit …
Orion Platform
after 2020.2.5
HIGH 8.8
CVE-2021-35216EPSS 81%
Insecure Deserialization of untrusted data remote code execution vulnerability was discovered in Patch Manager Orion Platform Integration module. An …
Patch Manager
2020.2.6+
HIGH 8.8
CVE-2021-35218EPSS 76%
Deserialization of Untrusted Data in the Web Console Chart Endpoint can lead to remote code execution. An unauthorized attacker who has network acces…
Orion Platform
2020.2.6+
HIGH 8.8
CVE-2021-35212
An SQL injection Privilege Escalation Vulnerability was discovered in the Orion Platform reported by the ZDI Team. A blind Boolean SQL injection whic…
Orion Platform
Patch available
HIGH 8.8
CVE-2021-35213
An Improper Access Control Privilege Escalation Vulnerability was discovered in the User Setting of Orion Platform version 2020.2.5. It allows a gues…
Orion Platform
after 2020.2.5
HIGH 8.8
CVE-2021-35223
The Serv-U File Server allows for events such as user login failures to be audited by executing a command. This command can be supplied with paramete…
Serv U
15.2.4+
MEDIUM 5.4
CVE-2021-35239
A security researcher found a user with Orion map manage rights could store XSS through via text box hyperlink.
Orion Platform
after 2020.2.5
CRITICAL 9.6
CVE-2021-35222
This vulnerability allows attackers to impersonate users and perform arbitrary actions leading to a Remote Code Execution (RCE) from the Alerts Setti…
Orion Platform
2020.2.6+
HIGH 8.1
CVE-2021-35221
Improper Access Control Tampering Vulnerability using ImportAlert function which can lead to a Remote Code Execution (RCE) from the Alerts Settings p…
Orion Platform
2020.2.6+
HIGH 7.2
CVE-2021-35220
Command Injection vulnerability in EmailWebPage API which can lead to a Remote Code Execution (RCE) from the Alerts Settings page.
Orion Platform
2020.2.6+
MEDIUM 5.3
CVE-2021-32076
Access Restriction Bypass via referrer spoof was discovered in SolarWinds Web Help Desk 12.7.2. An attacker can access the 'Web Help Desk Getting Sta…
Web Help Desk
after 12.7.2
MEDIUM 5.4
CVE-2021-28674
The node management page in SolarWinds Orion Platform before 2020.2.5 HF1 allows an attacker to create or delete a node (outside of the attacker's pe…
Orion Platform
after 2020.2.5
CRITICAL 10.0
CVE-2021-35211 KEVEPSS 91%
Microsoft discovered a remote code execution (RCE) vulnerability in the SolarWinds Serv-U product utilizing a Remote Memory Escape Vulnerability. If …
Serv U
15.2.3+
CRITICAL 9.1
CVE-2021-31217
In SolarWinds DameWare Mini Remote Control Server 12.0.1.200, insecure file permissions allow file deletion as SYSTEM.
Dameware Mini Remote Control
Mitigation only
CRITICAL 9.8
CVE-2021-31474EPSS 94%
This vulnerability allows remote attackers to execute arbitrary code on affected installations of SolarWinds Network Performance Monitor 2020.2.1. Au…
Network Performance Monitor
2020.2.5+
HIGH 8.8
CVE-2021-31475EPSS 6%
This vulnerability allows remote attackers to execute arbitrary code on affected installations of SolarWinds Orion Job Scheduler 2020.2.1 HF 2. Authe…
Orion Job Scheduler
Mitigation only
MEDIUM 5.4
CVE-2021-32604
Share/IncomingWizard.htm in SolarWinds Serv-U before 15.2.3 mishandles the user-supplied SenderEmail parameter, aka "Share URL XSS."
Serv U
15.2.3+
MEDIUM 6.1
CVE-2021-25179
SolarWinds Serv-U before 15.2 is affected by Cross Site Scripting (XSS) via the HTTP Host header.
Serv U File Server
15.2+
HIGH 7.5
CVE-2021-3154
An issue was discovered in SolarWinds Serv-U before 15.2.2. Unauthenticated attackers can retrieve cleartext passwords via macro Injection. NOTE: thi…
Serv U
15.2.2+
HIGH 7.8
CVE-2021-27277
This vulnerability allows local attackers to escalate privileges on affected installations of SolarWinds Orion Virtual Infrastructure Monitor 2020.2.…
Orion Platform
Mitigation only