Vulnerability index

Browse CVEs

292 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Web Help Desk CRITICAL 9.8
CVE-2026-28323

SolarWinds Web Help Desk is found to be affected by a SAML authentication bypass vulnerability. This requires the SAML 2.0 authentication method to b…

No fix yet
Fix from $2,300 2026-07-30
Serv U CRITICAL 9.1
CVE-2026-28317

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation. This issue requires …

Fix: 2026.3+
Fix from $2,300 2026-07-21
Serv U CRITICAL 9.1
CVE-2026-28321

SolarWinds Serv-U is affected by a broken access control vulnerability that could allow arbitrary file read and write, which can then be used to esca…

Fix: 2026.3+
Fix from $2,300 2026-07-21
Serv U CRITICAL 9.1
CVE-2026-28312

SolarWinds Serv-U is affected by a privilege escalation vulnerability. This would elevate a group’s access to system administrator and allow code exe…

Fix: 2026.3+
Fix from $2,300 2026-07-21
Serv U CRITICAL 9.1
CVE-2026-28313

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to SMTP hijacking leading to arbitrary accoun…

Fix: 2026.3+
Fix from $2,300 2026-07-21
Serv U CRITICAL 9.1
CVE-2026-28314

SolarWinds Serv-U is affected by an insecure direct object reference vulnerability that leads to an account takeover. User authentication is required…

Fix: 2026.3+
Fix from $2,300 2026-07-21
Serv U CRITICAL 9.1
CVE-2026-28316

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation to a system administr…

Fix: 2026.3+
Fix from $2,300 2026-07-21
Serv U MEDIUM 6.2
CVE-2026-28315

SolarWinds Serv-U was found to be affected by a stored cross-site scripting vulnerability that could lead to session hijacking or information disclos…

Fix: 2026.3+
Fix from $1,600 2026-07-21
Serv U CRITICAL 9.1
CVE-2026-28304

SolarWinds Serv-U is affected by a remote code execution vulnerability that, when exploited, can allow the arbitrary execution of code remotely as ro…

Fix: 2026.3+
Fix from $2,300 2026-07-21
Serv U CRITICAL 9.1
CVE-2026-28305

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution as root. A domain ac…

Fix: 2026.3+
Fix from $2,300 2026-07-21
Serv U CRITICAL 9.1
CVE-2026-28306

SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to elevate their privileges to a system admi…

Fix: 2026.3+
Fix from $2,300 2026-07-21
Serv U CRITICAL 9.1
CVE-2026-28307

SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain user group to be elevated into an administrator group. The…

Fix: 2026.3+
Fix from $2,300 2026-07-21
Serv U CRITICAL 9.1
CVE-2026-28308

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution. Domain administrato…

Fix: 2026.3+
Fix from $2,300 2026-07-21
Serv U CRITICAL 9.1
CVE-2026-28309

SolarWinds Serv-U is affected by a broken access control vulnerability that allows a domain administrator to create system administrator accounts. Th…

Fix: 2026.3+
Fix from $2,300 2026-07-21
Serv U CRITICAL 9.1
CVE-2026-28310

SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to escalate their user type to that of a sys…

Fix: 2026.3+
Fix from $2,300 2026-07-21
Serv U CRITICAL 9.1
CVE-2026-28302

SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation and remote code execu…

Fix: 2026.3+
Fix from $2,300 2026-07-21
Serv U HIGH 7.5
CVE-2026-28318 KEVEPSS 8%

SolarWinds Serv-U is susceptible to specially crafted POST requests that crash the Serv-U service without authentication using Content-Encoding: defl…

Fix: 15.5.4+
Fix from $1,950 2026-06-04
Web Help Desk HIGH 7.5
CVE-2026-28299

SolarWinds Web Help Desk is found to be affected by a denial-of-service vulnerability, which when exploited, could cause the Web Help Desk server to …

Fix: 2026.2+
Fix from $1,950 2026-06-02
Ftp Voyager MEDIUM 5.5
CVE-2018-25252

FTP Voyager 16.2.0 contains a denial of service vulnerability that allows local attackers to crash the application by injecting oversized buffer data…

Fix: after 16.2.0
Fix from $1,600 2026-04-04
Observability Self Hosted HIGH 8.7
CVE-2026-28297

SolarWinds Observability Self-Hosted was found to be affected by a stored cross-site scripting vulnerability, which when exploited, can lead to unint…

Fix: 2026.1.1+
Fix from $1,950 2026-03-26
Observability Self Hosted HIGH 8.1
CVE-2026-28298

SolarWinds Observability Self-Hosted was found to be affected by a stored cross-site scripting vulnerability, which when exploited, can lead to unint…

Fix: 2026.1.1+
Fix from $1,950 2026-03-26
Serv U HIGH 7.2
CVE-2025-40540

A type confusion vulnerability exists in Serv-U which when exploited, gives a malicious actor the ability to execute arbitrary native code as privile…

Fix: 15.5.4+
Fix from $1,950 2026-02-24
Serv U HIGH 7.2
CVE-2025-40541

An Insecure Direct Object Reference (IDOR) vulnerability exists in Serv-U, which when exploited, gives a malicious actor the ability to execute nativ…

Fix: 15.5.4+
Fix from $1,950 2026-02-24
Serv U HIGH 7.2
CVE-2025-40538

A broken access control vulnerability exists in Serv-U which when exploited, gives a malicious actor the ability to create a system admin user and ex…

Fix: 15.5.4+
Fix from $1,950 2026-02-24
Serv U HIGH 7.2
CVE-2025-40539

A type confusion vulnerability exists in Serv-U which when exploited, gives a malicious actor the ability to execute arbitrary native code as privile…

Fix: 15.5.4+
Fix from $1,950 2026-02-24
Web Help Desk CRITICAL 9.8
CVE-2025-40551 KEVEPSS 84%

SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, whi…

Fix: 2026.1+
Fix from $2,300 2026-01-28
Web Help Desk CRITICAL 9.8
CVE-2025-40552EPSS 50%

SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that if exploited, would allow a malicious actor to ex…

Fix: 2026.1+
Fix from $2,300 2026-01-28
Web Help Desk CRITICAL 9.8
CVE-2025-40553EPSS 60%

SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, whi…

Fix: 2026.1+
Fix from $2,300 2026-01-28
Web Help Desk CRITICAL 9.8
CVE-2025-40554EPSS 57%

SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that, if exploited, could allow an attacker to invoke …

Fix: 2026.1+
Fix from $2,300 2026-01-28
Web Help Desk HIGH 7.5
CVE-2025-40537

SolarWinds Web Help Desk was found to be susceptible to a hardcoded credentials vulnerability that, under certain situations, could allow access to a…

Fix: 2026.1+
Fix from $1,950 2026-01-28