Vulnerability index

Browse CVEs

292 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2021-27258 This vulnerability allows remote attackers to execute escalate privileges on affected installations of SolarWinds Orion Platform 2020.2. Authenticati… Orion Platform Mitigation only Fix from $2,3002021-04-14 HIGH 7.8 CVE-2021-27240 This vulnerability allows local attackers to escalate privileges on affected installations of SolarWinds Patch Manager 2020.2.1. An attacker must fir… Patch Manager Mitigation only Fix from $1,9502021-03-29 HIGH 8.8 CVE-2020-27869EPSS 5% This vulnerability allows remote attackers to escalate privileges on affected installations of SolarWinds Network Performance Monitor 2020 HF1, NPM: … Network Performance Monitor Mitigation only Fix from $1,9502021-02-12 HIGH 7.2 CVE-2020-27871EPSS 90% This vulnerability allows remote attackers to create arbitrary files on affected installations of SolarWinds Orion Platform 2020.2.1. Although authen… Orion Platform Mitigation only Fix from $1,9502021-02-10 MEDIUM 6.5 CVE-2020-27870 This vulnerability allows remote attackers to disclose sensitive information on affected installations of SolarWinds Orion Platform 2020.2.1. Authent… Orion Platform Mitigation only Fix from $1,6002021-02-10 CRITICAL 9.8 CVE-2021-25274EPSS 36% The Collector Service in SolarWinds Orion Platform before 2020.2.4 uses MSMQ (Microsoft Message Queue) and doesn't set permissions on its private que… Orion Platform 2020.2.4+ Fix from $2,3002021-02-03 HIGH 7.8 CVE-2021-25275 SolarWinds Orion Platform before 2020.2.4, as used by various SolarWinds products, installs and uses a SQL Server backend, and stores database creden… Orion Platform 2020.2.4+ Fix from $1,9502021-02-03 HIGH 7.1 CVE-2021-25276 In SolarWinds Serv-U before 15.2.2 Hotfix 1, there is a directory containing user profile files (that include users' password hashes) that is world r… Serv U 15.2.2+ Fix from $1,9502021-02-03 CRITICAL 9.8 CVE-2020-35481 SolarWinds Serv-U before 15.2.2 allows Unauthenticated Macro Injection. Serv U 15.2.2+ Fix from $2,3002021-02-03 MEDIUM 5.4 CVE-2020-35482 SolarWinds Serv-U before 15.2.2 allows authenticated reflected XSS. Serv U 15.2.2+ Fix from $1,6002021-02-03 MEDIUM 6.5 CVE-2020-27994 SolarWinds Serv-U before 15.2.2 allows Authenticated Directory Traversal. Serv U 15.2.2+ Fix from $1,6002021-02-03 MEDIUM 5.4 CVE-2020-28001 SolarWinds Serv-U before 15.2.2 allows Authenticated Stored XSS. Serv U 15.2.2+ Fix from $1,6002021-02-03 MEDIUM 5.4 CVE-2019-16961 SolarWinds Web Help Desk 12.7.0 allows XSS via a Schedule Name. Web Help Desk No fix yet Fix from $1,6002021-01-15 MEDIUM 5.4 CVE-2019-16954 SolarWinds Web Help Desk 12.7.0 allows HTML injection via a Comment in a Help Request ticket. Web Help Desk No fix yet Fix from $1,6002021-01-06 MEDIUM 5.4 CVE-2019-16956 SolarWinds Web Help Desk 12.7.0 allows XSS via the Request Type parameter of a ticket. Web Help Desk No fix yet Fix from $1,6002021-01-04 MEDIUM 5.4 CVE-2019-16960 SolarWinds Web Help Desk 12.7.0 allows XSS via a CSV template file with a crafted Location Name field. Web Help Desk No fix yet Fix from $1,6002021-01-04 CRITICAL 9.8 CVE-2020-10148 KEVEPSS 92% The SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands. This vulnerability cou… Orion Platform Mitigation only Fix from $2,3002020-12-29 MEDIUM 6.5 CVE-2019-16959 SolarWinds Web Help Desk 12.7.0 allows CSV Injection, also known as Formula Injection, via a file attached to a ticket. Webhelpdesk No fix yet Fix from $1,6002020-12-21 MEDIUM 5.4 CVE-2019-16955 SolarWinds Web Help Desk 12.7.0 allows XSS via an uploaded SVG document in a request. Webhelpdesk No fix yet Fix from $1,6002020-12-18 MEDIUM 5.4 CVE-2019-16957 SolarWinds Web Help Desk 12.7.0 allows XSS via the First Name field of a User Account. Webhelpdesk No fix yet Fix from $1,6002020-12-18 HIGH 8.8 CVE-2020-25622 An issue was discovered in SolarWinds N-Central 12.3.0.670. The AdvancedScripts HTTP endpoint allows CSRF. N Central Mitigation only Fix from $1,9502020-12-16 HIGH 8.4 CVE-2020-25621 An issue was discovered in SolarWinds N-Central 12.3.0.670. The local database does not require authentication: security is only based on ability to … N Central Mitigation only Fix from $1,9502020-12-16 HIGH 7.8 CVE-2020-25620 An issue was discovered in SolarWinds N-Central 12.3.0.670. Hard-coded Credentials exist by default for local user accounts named [email protected] N Central Mitigation only Fix from $1,9502020-12-16 HIGH 8.8 CVE-2020-25617 An issue was discovered in SolarWinds N-Central 12.3.0.670. The AdvancedScripts HTTP endpoint allows Relative Path Traversal by an authenticated user… N Central Mitigation only Fix from $1,9502020-12-16 HIGH 8.8 CVE-2020-25618 An issue was discovered in SolarWinds N-Central 12.3.0.670. The sudo configuration has incorrect access control because the nable web user account is… N Central Mitigation only Fix from $1,9502020-12-16 MEDIUM 5.4 CVE-2018-16243 SolarWinds Database Performance Analyzer (DPA) 11.1.468 and 12.0.3074 have several persistent XSS vulnerabilities, related to logViewer.iwc, centralM… Database Performance Analyzer Mitigation only Fix from $1,6002020-12-15 MEDIUM 5.4 CVE-2019-16958 Cross-site Scripting (XSS) vulnerability in SolarWinds Web Help Desk 12.7.0 allows attacker to inject arbitrary web script or HTML via Location Name. Help Desk No fix yet Fix from $1,6002020-12-01 HIGH 8.8 CVE-2020-15909 SolarWinds N-central through 2020.1 allows session hijacking and requires user interaction or physical access. The N-Central JSESSIONID cookie attrib… N Central after 2020.1 Fix from $1,9502020-10-19 CRITICAL 9.0 CVE-2020-13169 Stored XSS (Cross-Site Scripting) exists in the SolarWinds Orion Platform before before 2020.2.1 on multiple forms and pages. This vulnerability may … Orion Platform 2020.2.1+ Fix from $2,3002020-09-17 HIGH 7.5 CVE-2020-15574 SolarWinds Serv-U File Server before 15.2.1 mishandles the Same-Site cookie attribute, aka Case Number 00331893. Serv U 15.2.1+ Fix from $1,9502020-07-07