VYPR

Vendor CVEs

SolarWinds

All CVEs

342 total · sorted by risk
  • CVE-2025-40551CriKEVJan 28, 2026
    risk 0.85cvss 9.8epss 0.84

    SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, which would allow an attacker to run commands on the host machine. This could be exploited without authentication.

  • CVE-2021-35211CriKEVJul 14, 2021
    risk 0.84cvss 9.0epss 0.91

    Microsoft discovered a remote code execution (RCE) vulnerability in the SolarWinds Serv-U product utilizing a Remote Memory Escape Vulnerability. If exploited, a threat actor may be able to gain privileged access to the machine hosting Serv-U Only. SolarWinds Serv-U Managed File…

  • CVE-2025-26399CriKEVSep 23, 2025
    risk 0.83cvss 9.8epss 0.88

    SolarWinds Web Help Desk was found to be susceptible to an unauthenticated AjaxProxy deserialization remote code execution vulnerability that, if exploited, would allow an attacker to run commands on the host machine. This vulnerability is a patch bypass of CVE-2024-28988, which…

  • CVE-2020-10148CriKEVDec 29, 2020
    risk 0.83cvss 9.8epss 0.92

    The SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands. This vulnerability could allow a remote attacker to bypass authentication and execute API commands which may result in a compromise of the SolarWinds…

  • CVE-2024-28987CriKEVAug 21, 2024
    risk 0.82cvss 9.1epss 0.93

    The SolarWinds Web Help Desk (WHD) software is affected by a hardcoded credential vulnerability, allowing remote unauthenticated user to access internal functionality and modify data.

  • CVE-2024-28986CriKEVAug 13, 2024
    risk 0.82cvss 9.8epss 0.85

    SolarWinds Web Help Desk was found to be susceptible to a Java Deserialization Remote Code Execution vulnerability that, if exploited, would allow an attacker to run commands on the host machine. While it was reported as an unauthenticated vulnerability, SolarWinds has been…

  • CVE-2024-28995HigKEVJun 6, 2024
    risk 0.79cvss 8.6epss 1.00

    SolarWinds Serv-U was susceptible to a directory transversal vulnerability that would allow access to read sensitive files on the host machine.

  • CVE-2025-40536HigKEVJan 28, 2026
    risk 0.74cvss 8.1epss 0.72

    SolarWinds Web Help Desk was found to be susceptible to a security control bypass vulnerability that if exploited, could allow an unauthenticated attacker to gain access to certain restricted functionality.

  • CVE-2021-31474CriMay 21, 2021
    risk 0.71cvss 9.8epss 0.94

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of SolarWinds Network Performance Monitor 2020.2.1. Authentication is not required to exploit this vulnerability. The specific flaw exists within the SolarWinds.Serialization library.…

  • CVE-2012-2576CriDec 20, 2017
    risk 0.71cvss 9.8epss 0.59

    SQL injection vulnerability in the LoginServlet page in SolarWinds Storage Manager before 5.1.2, SolarWinds Storage Profiler before 5.1.2, and SolarWinds Backup Profiler before 5.1.2 allows remote attackers to execute arbitrary SQL commands via the loginName field.

  • CVE-2016-2345CriMar 17, 2016
    risk 0.71cvss 9.8epss 0.51

    Stack-based buffer overflow in dwrcs.exe in the dwmrcs daemon in SolarWinds DameWare Mini Remote Control 12.0 allows remote attackers to execute arbitrary code via a crafted string.

  • CVE-2025-40553CriJan 28, 2026
    risk 0.69cvss 9.8epss 0.60

    SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, which would allow an attacker to run commands on the host machine. This could be exploited without authentication.

  • CVE-2017-7722CriApr 12, 2017
    risk 0.69cvss 10.0epss 0.13

    In SolarWinds Log & Event Manager (LEM) before 6.3.1 Hotfix 4, a menu system is encountered when the SSH service is accessed with "cmc" and "password" (the default username and password). By exploiting a vulnerability in the restrictssh feature of the menuing script, an attacker…

  • CVE-2016-4350CriMay 9, 2016
    risk 0.69cvss 9.8epss 0.70

    Multiple SQL injection vulnerabilities in the Web Services web server in SolarWinds Storage Resource Monitor (SRM) Profiler (formerly Storage Manager (STM)) before 6.2.3 allow remote attackers to execute arbitrary SQL commands via the (1) ScriptSchedule parameter in the…

  • CVE-2025-40554CriJan 28, 2026
    risk 0.68cvss 9.8epss 0.57

    SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that, if exploited, could allow an attacker to invoke specific actions within Web Help Desk.

  • CVE-2025-40552CriJan 28, 2026
    risk 0.68cvss 9.8epss 0.50

    SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that if exploited, would allow a malicious actor to execute actions and methods that should be protected by authentication.

  • CVE-2024-28988CriSep 1, 2025
    risk 0.67cvss 9.8epss 0.39

    SolarWinds Web Help Desk was found to be susceptible to a Java Deserialization Remote Code Execution vulnerability that, if exploited, would allow an attacker to run commands on the host machine. This vulnerability was found by the ZDI team after researching a previous…

  • CVE-2021-25274CriFeb 3, 2021
    risk 0.67cvss 9.8epss 0.36

    The Collector Service in SolarWinds Orion Platform before 2020.2.4 uses MSMQ (Microsoft Message Queue) and doesn't set permissions on its private queues. As a result, remote unauthenticated clients can send messages to TCP port 1801 that the Collector Service will process.…

  • CVE-2019-8917CriFeb 18, 2019
    risk 0.67cvss 9.8epss 0.36

    SolarWinds Orion NPM before 12.4 suffers from a SYSTEM remote code execution vulnerability in the OrionModuleEngine service. This service establishes a NetTcpBinding endpoint that allows remote, unauthenticated clients to connect and call publicly exposed methods. The…

  • CVE-2016-3643HigKEVJun 17, 2016
    risk 0.66cvss 7.8epss 0.04

    SolarWinds Virtualization Manager 6.3.1 and earlier allow local users to gain privileges by leveraging a misconfiguration of sudo, as demonstrated by "sudo cat /etc/passwd."

  • CVE-2024-28075CriMay 14, 2024
    risk 0.65cvss 9.0epss 0.78

    The SolarWinds Access Rights Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows an authenticated user to abuse SolarWinds service resulting in remote code execution. We thank Trend Micro Zero Day Initiative (ZDI) for its ongoing…

  • CVE-2024-0692HigMar 1, 2024
    risk 0.65cvss 8.8epss 0.92

    The SolarWinds Security Event Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows an unauthenticated user to abuse SolarWinds’ service, resulting in remote code execution.

  • CVE-2019-12181HigJun 17, 2019
    risk 0.65cvss 8.8epss 0.66

    A privilege escalation vulnerability exists in SolarWinds Serv-U before 15.1.7 for Linux.

  • CVE-2016-3642CriJun 17, 2016
    risk 0.65cvss 9.8epss 0.13

    The RMI service in SolarWinds Virtualization Manager 6.3.1 and earlier allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.

  • CVE-2024-23472CriJul 17, 2024
    risk 0.64cvss 9.6epss 0.19

    SolarWinds Access Rights Manager (ARM) is susceptible to Directory Traversal vulnerability. This vulnerability allows an authenticated user to arbitrary read and delete files in ARM.

  • CVE-2024-23469CriJul 17, 2024
    risk 0.64cvss 9.6epss 0.18

    SolarWinds Access Rights Manager (ARM) is susceptible to a Remote Code Execution vulnerability. If exploited, this vulnerability allows an unauthenticated user to perform the actions with SYSTEM privileges.

  • CVE-2022-36958HigOct 20, 2022
    risk 0.64cvss 8.8epss 0.83

    SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with valid access to SolarWinds Web Console to execute arbitrary commands.

  • CVE-2021-35217HigSep 8, 2021
    risk 0.64cvss 8.9epss 0.73

    Insecure Deseralization of untrusted data remote code execution vulnerability was discovered in Patch Manager Orion Platform Integration module and reported to us by ZDI. An Authenticated Attacker could exploit it by executing WSAsyncExecuteTasks deserialization of untrusted…

  • CVE-2021-35218HigSep 1, 2021
    risk 0.64cvss 8.9epss 0.76

    Deserialization of Untrusted Data in the Web Console Chart Endpoint can lead to remote code execution. An unauthorized attacker who has network access to the Orion Patch Manager Web Console could potentially exploit this and compromise the server

  • CVE-2021-35216HigSep 1, 2021
    risk 0.64cvss 8.9epss 0.81

    Insecure Deserialization of untrusted data remote code execution vulnerability was discovered in Patch Manager Orion Platform Integration module. An Authenticated Attacker with network access via HTTP can compromise this vulnerability can result in Remote Code Execution.

  • CVE-2021-27258CriApr 14, 2021
    risk 0.64cvss 9.8epss 0.04

    This vulnerability allows remote attackers to execute escalate privileges on affected installations of SolarWinds Orion Platform 2020.2. Authentication is not required to exploit this vulnerability. The specific flaw exists within the SaveUserSetting endpoint. The issue results…

  • CVE-2020-35481CriFeb 3, 2021
    risk 0.64cvss 9.8epss 0.01

    SolarWinds Serv-U before 15.2.2 allows Unauthenticated Macro Injection.

  • CVE-2020-15543CriJul 5, 2020
    risk 0.64cvss 9.8epss 0.02

    SolarWinds Serv-U FTP server before 15.2.1 does not validate an argument path.

  • CVE-2020-15542CriJul 5, 2020
    risk 0.64cvss 9.8epss 0.02

    SolarWinds Serv-U FTP server before 15.2.1 mishandles the CHMOD command.

  • CVE-2020-15541CriJul 5, 2020
    risk 0.64cvss 9.8epss 0.07

    SolarWinds Serv-U FTP server before 15.2.1 allows remote command execution.

  • CVE-2019-3980CriOct 8, 2019
    risk 0.64cvss 9.8epss 0.05

    The Solarwinds Dameware Mini Remote Client agent v12.1.0.89 supports smart card authentication which can allow a user to upload an executable to be executed on the DWRCS.exe host. An unauthenticated, remote attacker can request smart card login and upload and execute an…

  • CVE-2019-9546CriMar 1, 2019
    risk 0.64cvss 9.8epss 0.03

    SolarWinds Orion Platform before 2018.4 Hotfix 2 allows privilege escalation through the RabbitMQ service.

  • CVE-2018-16791CriDec 5, 2018
    risk 0.64cvss 9.8epss 0.02

    In SolarWinds SFTP/SCP Server through 2018-09-10, the configuration file is world readable and writable, and stores user passwords in an insecure manner, allowing an attacker to determine passwords for potentially privileged accounts. This also grants the attacker an ability to…

  • CVE-2024-28074CriJul 17, 2024
    risk 0.63cvss 9.6epss 0.11

    It was discovered that a previous vulnerability was not completely fixed with SolarWinds Access Rights Manager. While some controls were implemented the researcher was able to bypass these and use a different method to exploit the vulnerability.

  • CVE-2024-23475CriJul 17, 2024
    risk 0.63cvss 9.6epss 0.02

    The SolarWinds Access Rights Manager was susceptible to a Directory Traversal and Information Disclosure Vulnerability. This vulnerability allows an unauthenticated user to perform arbitrary file deletion and leak sensitive information.

  • CVE-2024-23471CriJul 17, 2024
    risk 0.63cvss 9.6epss 0.01

    The SolarWinds Access Rights Manager was found to be susceptible to a Remote Code Execution Vulnerability. If exploited, this vulnerability allows an authenticated user to abuse a SolarWinds service resulting in remote code execution.

  • CVE-2024-23467CriJul 17, 2024
    risk 0.63cvss 9.6epss 0.03

    The SolarWinds Access Rights Manager was susceptible to a Directory Traversal and Information Disclosure Vulnerability. This vulnerability allows an unauthenticated user to perform remote code execution.

  • CVE-2024-23466CriJul 17, 2024
    risk 0.63cvss 9.6epss 0.03

    SolarWinds Access Rights Manager (ARM) is susceptible to a Directory Traversal Remote Code Execution vulnerability. If exploited, this vulnerability allows an unauthenticated user to perform the actions with SYSTEM privileges.

  • CVE-2024-23479CriFeb 15, 2024
    risk 0.63cvss 9.6epss 0.06

    SolarWinds Access Rights Manager (ARM) was found to be susceptible to a Directory Traversal Remote Code Execution Vulnerability. If exploited, this vulnerability allows an unauthenticated user to achieve a Remote Code Execution.

  • CVE-2024-23476CriFeb 15, 2024
    risk 0.63cvss 9.6epss 0.07

    The SolarWinds Access Rights Manager (ARM) was found to be susceptible to a Directory Traversal Remote Code Execution Vulnerability. If exploited, this vulnerability allows an unauthenticated user to achieve the Remote Code Execution.

  • CVE-2022-36961HigSep 30, 2022
    risk 0.63cvss 8.8epss 0.75

    A vulnerable component of Orion Platform was vulnerable to SQL Injection, an authenticated attacker could leverage this for privilege escalation or remote code execution.

  • CVE-2021-35215HigSep 1, 2021
    risk 0.63cvss 8.9epss 0.70

    Insecure deserialization leading to Remote Code Execution was detected in the Orion Platform version 2020.2.5. Authentication is required to exploit this vulnerability.

  • CVE-2024-23470CriJul 17, 2024
    risk 0.62cvss 9.6epss 0.01

    The SolarWinds Access Rights Manager was found to be susceptible to a pre-authentication remote code execution vulnerability. If exploited, this vulnerability allows an unauthenticated user to run commands and executables.

  • CVE-2026-28318HigKEVJun 4, 2026
    risk 0.61cvss 7.5epss 0.08

    SolarWinds Serv-U is susceptible to specially crafted POST requests that crash the Serv-U service without authentication using Content-Encoding: deflate. Mitigation steps are provided to secure customer environments in the SolarWinds Trust Center if you are unable to deploy the…

  • CVE-2017-6803HigMar 20, 2017
    risk 0.61cvss 8.8epss 0.04

    Multiple cross-site request forgery (CSRF) vulnerabilities in the web interface in the Scheduler in SolarWinds (formerly Serv-U) FTP Voyager 16.2.0 allow remote attackers to hijack the authentication of users for requests that (1) change the admin password, (2) terminate the…

Page 1 of 7