Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 9.8
CVE-2021-27258
This vulnerability allows remote attackers to execute escalate privileges on affected installations of SolarWinds Orion Platform 2020.2. Authenticati…
Orion Platform
Mitigation only
HIGH 7.8
CVE-2021-27240
This vulnerability allows local attackers to escalate privileges on affected installations of SolarWinds Patch Manager 2020.2.1. An attacker must fir…
Patch Manager
Mitigation only
HIGH 8.8
CVE-2020-27869EPSS 5%
This vulnerability allows remote attackers to escalate privileges on affected installations of SolarWinds Network Performance Monitor 2020 HF1, NPM: …
Network Performance Monitor
Mitigation only
HIGH 7.2
CVE-2020-27871EPSS 90%
This vulnerability allows remote attackers to create arbitrary files on affected installations of SolarWinds Orion Platform 2020.2.1. Although authen…
Orion Platform
Mitigation only
MEDIUM 6.5
CVE-2020-27870
This vulnerability allows remote attackers to disclose sensitive information on affected installations of SolarWinds Orion Platform 2020.2.1. Authent…
Orion Platform
Mitigation only
CRITICAL 9.8
CVE-2021-25274EPSS 36%
The Collector Service in SolarWinds Orion Platform before 2020.2.4 uses MSMQ (Microsoft Message Queue) and doesn't set permissions on its private que…
Orion Platform
2020.2.4+
HIGH 7.8
CVE-2021-25275
SolarWinds Orion Platform before 2020.2.4, as used by various SolarWinds products, installs and uses a SQL Server backend, and stores database creden…
Orion Platform
2020.2.4+
HIGH 7.1
CVE-2021-25276
In SolarWinds Serv-U before 15.2.2 Hotfix 1, there is a directory containing user profile files (that include users' password hashes) that is world r…
Serv U
15.2.2+
CRITICAL 9.8
CVE-2020-35481
SolarWinds Serv-U before 15.2.2 allows Unauthenticated Macro Injection.
Serv U
15.2.2+
MEDIUM 5.4
CVE-2020-35482
SolarWinds Serv-U before 15.2.2 allows authenticated reflected XSS.
Serv U
15.2.2+
MEDIUM 6.5
CVE-2020-27994
SolarWinds Serv-U before 15.2.2 allows Authenticated Directory Traversal.
Serv U
15.2.2+
MEDIUM 5.4
CVE-2020-28001
SolarWinds Serv-U before 15.2.2 allows Authenticated Stored XSS.
Serv U
15.2.2+
MEDIUM 5.4
CVE-2019-16961
SolarWinds Web Help Desk 12.7.0 allows XSS via a Schedule Name.
Web Help Desk
No fix yet
MEDIUM 5.4
CVE-2019-16954
SolarWinds Web Help Desk 12.7.0 allows HTML injection via a Comment in a Help Request ticket.
Web Help Desk
No fix yet
MEDIUM 5.4
CVE-2019-16956
SolarWinds Web Help Desk 12.7.0 allows XSS via the Request Type parameter of a ticket.
Web Help Desk
No fix yet
MEDIUM 5.4
CVE-2019-16960
SolarWinds Web Help Desk 12.7.0 allows XSS via a CSV template file with a crafted Location Name field.
Web Help Desk
No fix yet
CRITICAL 9.8
CVE-2020-10148 KEVEPSS 92%
The SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands. This vulnerability cou…
Orion Platform
Mitigation only
MEDIUM 6.5
CVE-2019-16959
SolarWinds Web Help Desk 12.7.0 allows CSV Injection, also known as Formula Injection, via a file attached to a ticket.
Webhelpdesk
No fix yet
MEDIUM 5.4
CVE-2019-16955
SolarWinds Web Help Desk 12.7.0 allows XSS via an uploaded SVG document in a request.
Webhelpdesk
No fix yet
MEDIUM 5.4
CVE-2019-16957
SolarWinds Web Help Desk 12.7.0 allows XSS via the First Name field of a User Account.
Webhelpdesk
No fix yet
HIGH 8.8
CVE-2020-25622
An issue was discovered in SolarWinds N-Central 12.3.0.670. The AdvancedScripts HTTP endpoint allows CSRF.
N Central
Mitigation only
HIGH 8.4
CVE-2020-25621
An issue was discovered in SolarWinds N-Central 12.3.0.670. The local database does not require authentication: security is only based on ability to …
N Central
Mitigation only
HIGH 7.8
CVE-2020-25620
An issue was discovered in SolarWinds N-Central 12.3.0.670. Hard-coded Credentials exist by default for local user accounts named [email protected] …
N Central
Mitigation only
HIGH 8.8
CVE-2020-25617
An issue was discovered in SolarWinds N-Central 12.3.0.670. The AdvancedScripts HTTP endpoint allows Relative Path Traversal by an authenticated user…
N Central
Mitigation only
HIGH 8.8
CVE-2020-25618
An issue was discovered in SolarWinds N-Central 12.3.0.670. The sudo configuration has incorrect access control because the nable web user account is…
N Central
Mitigation only
MEDIUM 5.4
CVE-2018-16243
SolarWinds Database Performance Analyzer (DPA) 11.1.468 and 12.0.3074 have several persistent XSS vulnerabilities, related to logViewer.iwc, centralM…
Database Performance Analyzer
Mitigation only
MEDIUM 5.4
CVE-2019-16958
Cross-site Scripting (XSS) vulnerability in SolarWinds Web Help Desk 12.7.0 allows attacker to inject arbitrary web script or HTML via Location Name.
Help Desk
No fix yet
HIGH 8.8
CVE-2020-15909
SolarWinds N-central through 2020.1 allows session hijacking and requires user interaction or physical access. The N-Central JSESSIONID cookie attrib…
N Central
after 2020.1
CRITICAL 9.0
CVE-2020-13169
Stored XSS (Cross-Site Scripting) exists in the SolarWinds Orion Platform before before 2020.2.1 on multiple forms and pages. This vulnerability may …
Orion Platform
2020.2.1+
HIGH 7.5
CVE-2020-15574
SolarWinds Serv-U File Server before 15.2.1 mishandles the Same-Site cookie attribute, aka Case Number 00331893.
Serv U
15.2.1+