Vulnerability index

Browse CVEs

292 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2019-9546 SolarWinds Orion Platform before 2018.4 Hotfix 2 allows privilege escalation through the RabbitMQ service. Orion Platform 2018.4+ Fix from $2,3002019-03-01 CRITICAL 9.8 CVE-2019-8917EPSS 36% SolarWinds Orion NPM before 12.4 suffers from a SYSTEM remote code execution vulnerability in the OrionModuleEngine service. This service establishes… Orion Network Performance Monitor 12.4+ Fix from $2,3002019-02-18 CRITICAL 9.8 CVE-2018-16791 In SolarWinds SFTP/SCP Server through 2018-09-10, the configuration file is world readable and writable, and stores user passwords in an insecure man… Sftp\/scp Server after 20180910 Fix from $2,3002018-12-05 CRITICAL 9.1 CVE-2018-16792 SolarWinds SFTP/SCP server through 2018-09-10 is vulnerable to XXE via a world readable and writable configuration file that allows an attacker to ex… Sftp\/scp Server after 2018-09-10 Fix from $2,3002018-12-05 HIGH 7.8 CVE-2018-12897 SolarWinds DameWare Mini Remote Control before 12.1 has a Buffer Overflow. Dameware Mini Remote Control 12.1+ Fix from $1,9502018-09-07 HIGH 7.3 CVE-2018-10240 SolarWinds Serv-U MFT before 15.1.6 HFv1 assigns authenticated users a low-entropy session token that can be included in requests to the application … Serv U after 15.1.6 Fix from $1,9502018-05-16 MEDIUM 6.5 CVE-2018-10241 A denial of service vulnerability in SolarWinds Serv-U before 15.1.6 HFv1 allows an authenticated user to crash the application (with a NULL pointer … Serv U after 15.1.6 Fix from $1,6002018-05-16 CRITICAL 9.8 CVE-2012-2576EPSS 59% SQL injection vulnerability in the LoginServlet page in SolarWinds Storage Manager before 5.1.2, SolarWinds Storage Profiler before 5.1.2, and SolarW… Backup Profiler 5.1.2+ Fix from $2,3002017-12-20 CRITICAL 10.0 CVE-2017-7722EPSS 13% In SolarWinds Log & Event Manager (LEM) before 6.3.1 Hotfix 4, a menu system is encountered when the SSH service is accessed with "cmc" and "password… Log \& Event Manager Patch available Fix from $2,3002017-04-12 HIGH 8.8 CVE-2017-7647 SolarWinds Log & Event Manager (LEM) before 6.3.1 Hotfix 4 allows an authenticated user to execute arbitrary commands. Log \& Event Manager after 6.3.1 Fix from $1,9502017-04-10 MEDIUM 6.5 CVE-2017-7646 SolarWinds Log & Event Manager (LEM) before 6.3.1 Hotfix 4 allows an authenticated user to browse the server's filesystem and read the contents of ar… Log \& Event Manager after 6.3.1 Fix from $1,6002017-04-10 HIGH 8.8 CVE-2017-5198 SolarWinds LEM (aka SIEM) before 6.3.1 has an incorrect sudo configuration, which allows local users to obtain root access by editing /usr/local/cont… Log And Event Manager 6.3.1+ Fix from $1,9502017-03-24 HIGH 8.8 CVE-2017-5199 The editbanner feature in SolarWinds LEM (aka SIEM) through 6.3.1 allows remote authenticated users to execute arbitrary code by editing /usr/local/c… Log And Event Manager after 6.3.1 Fix from $1,9502017-03-24 HIGH 8.8 CVE-2017-6803 Multiple cross-site request forgery (CSRF) vulnerabilities in the web interface in the Scheduler in SolarWinds (formerly Serv-U) FTP Voyager 16.2.0 a… Ftp Voyager No fix yet Fix from $1,9502017-03-20 HIGH 7.8 CVE-2016-3643 KEV SolarWinds Virtualization Manager 6.3.1 and earlier allow local users to gain privileges by leveraging a misconfiguration of sudo, as demonstrated by… Virtualization Manager after 6.3.1 Fix from $1,9502016-06-17 CRITICAL 9.8 CVE-2016-3642EPSS 13% The RMI service in SolarWinds Virtualization Manager 6.3.1 and earlier allows remote attackers to execute arbitrary commands via a crafted serialized… Virtualization Manager after 6.3.1 Fix from $2,3002016-06-17 CRITICAL 9.8 CVE-2016-4350EPSS 70% Multiple SQL injection vulnerabilities in the Web Services web server in SolarWinds Storage Resource Monitor (SRM) Profiler (formerly Storage Manager… Storage Resource Monitor after 6.2.1 Fix from $2,3002016-05-09 HIGH 7.5 CVE-2015-8220 Stack-based buffer overflow in the URI handler in DWRCC.exe in SolarWinds DameWare Mini Remote Control before 12.0 HotFix 1 allows remote attackers t… Dameware Mini Remote Control after 12.0 Fix from $1,9502015-11-17 HIGH 7.5 CVE-2015-7840 The command line management console (CMC) in SolarWinds Log and Event Manager (LEM) before 6.2.0 allows remote attackers to execute arbitrary code vi… Log And Event Manager after 6.1 Fix from $1,9502015-10-15 HIGH 7.5 CVE-2015-7839EPSS 7% SolarWinds Log and Event Manager (LEM) allows remote attackers to execute arbitrary commands on managed computers via a request to services/messagebr… Log And Event Manager Mitigation only Fix from $1,9502015-10-15 HIGH 10.0 CVE-2015-7838 ProcessFileUpload.jsp in SolarWinds Storage Manager before 6.2 allows remote attackers to upload and execute arbitrary files via unspecified vectors. Storage Manager after 6.1 Fix from $1,9502015-10-15 HIGH 10.0 CVE-2015-5371EPSS 93% The AuthenticationFilter class in SolarWinds Storage Manager allows remote attackers to upload and execute arbitrary scripts via unspecified vectors. Storage Manager Mitigation only Fix from $1,9502015-07-06 HIGH 10.0 CVE-2015-2284EPSS 73% userlogin.jsp in SolarWinds Firewall Security Manager (FSM) before 6.6.5 HotFix1 allows remote attackers to gain privileges and execute arbitrary cod… Firewall Security Manager after 6.6.5 Fix from $1,9502015-03-24 HIGH 7.5 CVE-2014-9566EPSS 48% Multiple SQL injection vulnerabilities in the Manage Accounts page in the AccountManagement.asmx service in the Solarwinds Orion Platform 2015.1, as … Orion Ip Address Manager after 11.4 Fix from $1,9502015-03-10 MEDIUM 6.8 CVE-2015-1501EPSS 7% The factory.loadExtensionFactory function in TSUnicodeGraphEditorControl in SolarWinds Server and Application Monitor (SAM) allow remote attackers to… Server And Application Monitor Mitigation only Fix from $1,6002015-02-16 MEDIUM 6.8 CVE-2015-1500EPSS 8% Multiple stack-based buffer overflows in the TSUnicodeGraphEditorControl in SolarWinds Server and Application Monitor (SAM) allow remote attackers to… Server And Application Monitor Patch available Fix from $1,6002015-02-16 HIGH 7.5 CVE-2014-5504EPSS 5% SolarWinds Log and Event Manager before 6.0 uses "static" credentials, which makes it easier for remote attackers to obtain access to the database an… Log And Event Manager after 5.7.0 Fix from $1,9502014-09-04 MEDIUM 6.8 CVE-2014-3459EPSS 12% Heap-based buffer overflow in SolarWinds Network Configuration Manager (NCM) before 7.3 allows remote attackers to execute arbitrary code via the PEs… Network Configuration Manager after 7.2.2 Fix from $1,6002014-08-07 HIGH 9.3 CVE-2013-3249EPSS 6% Stack-based buffer overflow in the "Add from text file" feature in the DameWare Exporter tool (DWExporter.exe) in DameWare Remote Support 10.0.0.372,… Dameware Remote Support after 10.0.0.372 Fix from $1,9502014-03-20 MEDIUM 6.8 CVE-2012-2602EPSS 6% Multiple cross-site request forgery (CSRF) vulnerabilities in SolarWinds Orion Network Performance Monitor (NPM) before 10.3.1 allow remote attackers… Orion Network Performance Monitor after 10.2.2 Fix from $1,6002012-08-12