Vulnerability index

Browse CVEs

67 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Serv U MEDIUM 5.0
CVE-2023-40053

A vulnerability has been identified within Serv-U 15.4 that allows an authenticated actor to insert content on the file share function feature of Ser…

Mitigation only
Fix from $1,600 2023-12-06
Serv U HIGH 7.2
CVE-2023-40060

A vulnerability has been identified within Serv-U 15.4 and 15.4 Hotfix 1 that, if exploited, allows an actor to bypass multi-factor/two-factor authen…

Mitigation only
Fix from $1,950 2023-09-07
Serv U HIGH 7.2
CVE-2023-35179

A vulnerability has been identified within Serv-U 15.4 that, if exploited, allows an actor to bypass multi-factor/two-factor authentication. The acto…

Mitigation only
Fix from $1,950 2023-08-11
Orion Platform HIGH 7.2
CVE-2023-23836EPSS 80%

SolarWinds Platform version 2022.4.1 was found to be susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversa…

Mitigation only
Fix from $1,950 2023-02-15
Orion Platform HIGH 7.8
CVE-2022-47506

SolarWinds Platform was susceptible to the Directory Traversal Vulnerability. This vulnerability allows a local adversary with authenticated account …

Mitigation only
Fix from $1,950 2023-02-15
Server And Application Monitor HIGH 7.5
CVE-2022-47508

Customers who had configured their polling to occur via Kerberos did not expect NTLM Traffic on their environment, but since we were querying for dat…

Mitigation only
Fix from $1,950 2023-02-15
Orion Platform HIGH 7.2
CVE-2022-47507EPSS 7%

SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level acc…

Mitigation only
Fix from $1,950 2023-02-15
Orion Platform HIGH 7.2
CVE-2022-38111EPSS 85%

SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level acc…

Mitigation only
Fix from $1,950 2023-02-15
Orion Platform HIGH 7.2
CVE-2022-47503EPSS 24%

SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level acc…

Mitigation only
Fix from $1,950 2023-02-15
Orion Platform HIGH 7.2
CVE-2022-47504EPSS 25%

SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level acc…

Mitigation only
Fix from $1,950 2023-02-15
Dynamips HIGH 7.5
CVE-2022-47012

Use of uninitialized variable in function gen_eth_recv in GNS3 dynamips 0.2.21.

No fix yet
Fix from $1,950 2023-01-20
Solarwinds Platform MEDIUM 5.5
CVE-2022-47512

Sensitive information was stored in plain text in a file that is accessible by a user with a local account in Hybrid Cloud Observability (HCO)/ Solar…

Mitigation only
Fix from $1,600 2022-12-19
Serv U MEDIUM 5.4
CVE-2022-38106

This vulnerability happens in the web client versions 15.3.0 to Serv-U 15.3.1. This vulnerability affects the directory creation function.

No fix yet
Fix from $1,600 2022-12-16
Security Event Manager MEDIUM 5.3
CVE-2022-38113

This vulnerability discloses build and services versions in the server response header.

Mitigation only
Fix from $1,600 2022-11-23
Serv U HIGH 7.5
CVE-2021-35250EPSS 13%

A researcher reported a Directory Transversal Vulnerability in Serv-U 15.3. This may allow access to files relating to the Serv-U installation and se…

Mitigation only
Fix from $1,950 2022-04-25
Dameware Mini Remote Control CRITICAL 9.1
CVE-2021-31217

In SolarWinds DameWare Mini Remote Control Server 12.0.1.200, insecure file permissions allow file deletion as SYSTEM.

Mitigation only
Fix from $2,300 2021-07-13
Orion Job Scheduler HIGH 8.8
CVE-2021-31475EPSS 6%

This vulnerability allows remote attackers to execute arbitrary code on affected installations of SolarWinds Orion Job Scheduler 2020.2.1 HF 2. Authe…

Mitigation only
Fix from $1,950 2021-05-21
Orion Platform HIGH 7.8
CVE-2021-27277

This vulnerability allows local attackers to escalate privileges on affected installations of SolarWinds Orion Virtual Infrastructure Monitor 2020.2.…

Mitigation only
Fix from $1,950 2021-04-22
Orion Platform CRITICAL 9.8
CVE-2021-27258

This vulnerability allows remote attackers to execute escalate privileges on affected installations of SolarWinds Orion Platform 2020.2. Authenticati…

Mitigation only
Fix from $2,300 2021-04-14
Patch Manager HIGH 7.8
CVE-2021-27240

This vulnerability allows local attackers to escalate privileges on affected installations of SolarWinds Patch Manager 2020.2.1. An attacker must fir…

Mitigation only
Fix from $1,950 2021-03-29
Network Performance Monitor HIGH 8.8
CVE-2020-27869EPSS 5%

This vulnerability allows remote attackers to escalate privileges on affected installations of SolarWinds Network Performance Monitor 2020 HF1, NPM: …

Mitigation only
Fix from $1,950 2021-02-12
Orion Platform HIGH 7.2
CVE-2020-27871EPSS 90%

This vulnerability allows remote attackers to create arbitrary files on affected installations of SolarWinds Orion Platform 2020.2.1. Although authen…

Mitigation only
Fix from $1,950 2021-02-10
Orion Platform MEDIUM 6.5
CVE-2020-27870

This vulnerability allows remote attackers to disclose sensitive information on affected installations of SolarWinds Orion Platform 2020.2.1. Authent…

Mitigation only
Fix from $1,600 2021-02-10
Web Help Desk MEDIUM 5.4
CVE-2019-16961

SolarWinds Web Help Desk 12.7.0 allows XSS via a Schedule Name.

No fix yet
Fix from $1,600 2021-01-15
Web Help Desk MEDIUM 5.4
CVE-2019-16954

SolarWinds Web Help Desk 12.7.0 allows HTML injection via a Comment in a Help Request ticket.

No fix yet
Fix from $1,600 2021-01-06
Web Help Desk MEDIUM 5.4
CVE-2019-16956

SolarWinds Web Help Desk 12.7.0 allows XSS via the Request Type parameter of a ticket.

No fix yet
Fix from $1,600 2021-01-04
Web Help Desk MEDIUM 5.4
CVE-2019-16960

SolarWinds Web Help Desk 12.7.0 allows XSS via a CSV template file with a crafted Location Name field.

No fix yet
Fix from $1,600 2021-01-04
Orion Platform CRITICAL 9.8
CVE-2020-10148 KEVEPSS 92%

The SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands. This vulnerability cou…

Mitigation only
Fix from $2,300 2020-12-29
Webhelpdesk MEDIUM 6.5
CVE-2019-16959

SolarWinds Web Help Desk 12.7.0 allows CSV Injection, also known as Formula Injection, via a file attached to a ticket.

No fix yet
Fix from $1,600 2020-12-21
Webhelpdesk MEDIUM 5.4
CVE-2019-16955

SolarWinds Web Help Desk 12.7.0 allows XSS via an uploaded SVG document in a request.

No fix yet
Fix from $1,600 2020-12-18