VYPR

Vendor CVEs

SolarWinds

All CVEs

342 total · sorted by risk
  • CVE-2025-40541CriFeb 24, 2026
    risk 0.59cvss 9.1epss 0.01

    An Insecure Direct Object Reference (IDOR) vulnerability exists in Serv-U, which when exploited, gives a malicious actor the ability to execute native code as a privileged account. This issue requires administrative privileges to abuse. On Windows deployments, the risk is…

  • CVE-2025-40540CriFeb 24, 2026
    risk 0.59cvss 9.1epss 0.00

    A type confusion vulnerability exists in Serv-U which when exploited, gives a malicious actor the ability to execute arbitrary native code as privileged account. This issue requires administrative privileges to abuse. On Windows deployments, the risk is scored as a medium…

  • CVE-2025-40539CriFeb 24, 2026
    risk 0.59cvss 9.1epss 0.00

    A type confusion vulnerability exists in Serv-U which when exploited, gives a malicious actor the ability to execute arbitrary native code as privileged account. This issue requires administrative privileges to abuse. On Windows deployments, the risk is scored as a medium…

  • CVE-2025-40538CriFeb 24, 2026
    risk 0.59cvss 9.1epss 0.01

    A broken access control vulnerability exists in Serv-U which when exploited, gives a malicious actor the ability to create a system admin user and execute arbitrary code as a privileged account via domain admin or group admin privileges. This issue requires administrative…

  • CVE-2025-40549CriNov 18, 2025
    risk 0.59cvss 9.1epss 0.01

    A Path Restriction Bypass vulnerability exists in Serv-U that when abused, could give a malicious actor with access to admin privileges the ability to execute code on a directory. This issue requires administrative privileges to abuse. On Windows systems, this scored as medium…

  • CVE-2025-40548CriNov 18, 2025
    risk 0.59cvss 9.1epss 0.01

    A missing validation process exists in Serv U when abused, could give a malicious actor with access to admin privileges the ability to execute code. This issue requires administrative privileges to abuse. On Windows deployments, the risk is scored as a medium because services…

  • CVE-2025-40547CriNov 18, 2025
    risk 0.59cvss 9.1epss 0.01

    A logic error vulnerability exists in Serv-U which when abused could give a malicious actor with access to admin privileges the ability to execute code. This issue requires administrative privileges to abuse. On Windows deployments, the risk is scored as a medium because…

  • CVE-2024-28991CriSep 12, 2024
    risk 0.59cvss 9.0epss 0.03

    SolarWinds Access Rights Manager (ARM) was found to be susceptible to a remote code execution vulnerability. If exploited, this vulnerability would allow an authenticated user to abuse the service, resulting in remote code execution.

  • CVE-2024-23478HigFeb 15, 2024
    risk 0.59cvss 8.0epss 0.82

    SolarWinds Access Rights Manager (ARM) was found to be susceptible to a Remote Code Execution Vulnerability. If exploited, this vulnerability allows an authenticated user to abuse a SolarWinds service, resulting in remote code execution.

  • CVE-2023-40057CriFeb 15, 2024
    risk 0.59cvss 9.0epss 0.04

    The SolarWinds Access Rights Manager was found to be susceptible to a Remote Code Execution Vulnerability. If exploited, this vulnerability allows an authenticated user to abuse a SolarWinds service resulting in remote code execution.

  • CVE-2022-36964HigNov 29, 2022
    risk 0.59cvss 8.8epss 0.17

    SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with valid access to SolarWinds Web Console to execute arbitrary commands.

  • CVE-2021-31217CriJul 13, 2021
    risk 0.59cvss 9.1epss 0.04

    In SolarWinds DameWare Mini Remote Control Server 12.0.1.200, insecure file permissions allow file deletion as SYSTEM.

  • CVE-2020-13169CriSep 17, 2020
    risk 0.59cvss 9.0epss 0.02

    Stored XSS (Cross-Site Scripting) exists in the SolarWinds Orion Platform before before 2020.2.1 on multiple forms and pages. This vulnerability may lead to the Information Disclosure and Escalation of Privileges (takeover of administrator account).

  • CVE-2018-16792CriDec 5, 2018
    risk 0.59cvss 9.1epss 0.01

    SolarWinds SFTP/SCP server through 2018-09-10 is vulnerable to XXE via a world readable and writable configuration file that allows an attacker to exfiltrate data.

  • CVE-2021-35212HigAug 31, 2021
    risk 0.58cvss 8.9epss 0.02

    An SQL injection Privilege Escalation Vulnerability was discovered in the Orion Platform reported by the ZDI Team. A blind Boolean SQL injection which could lead to full read/write over the Orion database content including the Orion certificate for any authenticated user.

  • CVE-2021-35213HigAug 31, 2021
    risk 0.58cvss 8.9epss 0.03

    An Improper Access Control Privilege Escalation Vulnerability was discovered in the User Setting of Orion Platform version 2020.2.5. It allows a guest user to elevate privileges to the Administrator using this vulnerability. Authentication is required to exploit the…

  • CVE-2021-31475HigMay 21, 2021
    risk 0.58cvss 8.8epss 0.06

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of SolarWinds Orion Job Scheduler 2020.2.1 HF 2. Authentication is required to exploit this vulnerability. The specific flaw exists within the JobRouterService WCF service. The issue…

  • CVE-2020-27869HigFeb 12, 2021
    risk 0.58cvss 8.8epss 0.05

    This vulnerability allows remote attackers to escalate privileges on affected installations of SolarWinds Network Performance Monitor 2020 HF1, NPM: 2020.2. Authentication is required to exploit this vulnerability. The specific flaw exists within the WriteToFile method. The…

  • CVE-2020-14005HigJun 24, 2020
    risk 0.58cvss 8.8epss 0.14

    Solarwinds Orion (with Web Console WPM 2019.4.1, and Orion Platform HF4 or NPM HF2 2019.4) allows remote attackers to execute arbitrary code via a defined event.

  • CVE-2023-40061HigNov 1, 2023
    risk 0.57cvss 8.8epss 0.00

     Insecure job execution mechanism vulnerability. This vulnerability can lead to other attacks as a result.

  • CVE-2023-35187HigOct 19, 2023
    risk 0.57cvss 8.8epss 0.03

    The SolarWinds Access Rights Manager was susceptible to a Directory Traversal Remote Code Vulnerability. This vulnerability allows an unauthenticated user to achieve the Remote Code Execution.

  • CVE-2023-35184HigOct 19, 2023
    risk 0.57cvss 8.8epss 0.01

    The SolarWinds Access Rights Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows an unauthenticated user to abuse a SolarWinds service resulting in a remote code execution.

  • CVE-2023-35182HigOct 19, 2023
    risk 0.57cvss 8.8epss 0.02

    The SolarWinds Access Rights Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability can be abused by unauthenticated users on SolarWinds ARM Server.

  • CVE-2022-36960HigNov 29, 2022
    risk 0.57cvss 8.8epss 0.01

    SolarWinds Platform was susceptible to Improper Input Validation. This vulnerability allows a remote adversary with valid access to SolarWinds Web Console to escalate user privileges.

  • CVE-2020-25622HigDec 16, 2020
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in SolarWinds N-Central 12.3.0.670. The AdvancedScripts HTTP endpoint allows CSRF.

  • CVE-2020-25618HigDec 16, 2020
    risk 0.57cvss 8.8epss 0.03

    An issue was discovered in SolarWinds N-Central 12.3.0.670. The sudo configuration has incorrect access control because the nable web user account is effectively able to run arbitrary OS commands as root (i.e., the use of root privileges is not limited to specific programs…

  • CVE-2020-25617HigDec 16, 2020
    risk 0.57cvss 8.8epss 0.03

    An issue was discovered in SolarWinds N-Central 12.3.0.670. The AdvancedScripts HTTP endpoint allows Relative Path Traversal by an authenticated user of the N-Central Administration Console (NAC), leading to execution of OS commands as root.

  • CVE-2020-15909HigOct 19, 2020
    risk 0.57cvss 8.8epss 0.02

    SolarWinds N-central through 2020.1 allows session hijacking and requires user interaction or physical access. The N-Central JSESSIONID cookie attribute is not checked against multiple sources such as sourceip, MFA claim, etc. as long as the victim stays logged in within…

  • CVE-2019-12769HigMar 18, 2020
    risk 0.57cvss 8.8epss 0.01

    SolarWinds Serv-U Managed File Transfer (MFT) Web client before 15.1.6 Hotfix 2 is vulnerable to Cross-Site Request Forgery in the file upload functionality via ?Command=Upload with the Dir and File parameters.

  • CVE-2018-13442HigJul 16, 2019
    risk 0.57cvss 8.8epss 0.02

    SolarWinds Network Performance Monitor 12.3 allows SQL Injection via the /api/ActiveAlertsOnThisEntity/GetActiveAlerts TriggeringObjectEntityNames parameter.

  • CVE-2017-7647HigApr 10, 2017
    risk 0.57cvss 8.8epss 0.03

    SolarWinds Log & Event Manager (LEM) before 6.3.1 Hotfix 4 allows an authenticated user to execute arbitrary commands.

  • CVE-2017-5199HigMar 24, 2017
    risk 0.57cvss 8.8epss 0.03

    The editbanner feature in SolarWinds LEM (aka SIEM) through 6.3.1 allows remote authenticated users to execute arbitrary code by editing /usr/local/contego/scripts/mgrconfig.pl.

  • CVE-2017-5198HigMar 24, 2017
    risk 0.57cvss 8.8epss 0.01

    SolarWinds LEM (aka SIEM) before 6.3.1 has an incorrect sudo configuration, which allows local users to obtain root access by editing /usr/local/contego/scripts/hostname.sh.

  • CVE-2024-23473HigMay 14, 2024
    risk 0.56cvss 8.6epss 0.01

    The SolarWinds Access Rights Manager was found to contain a hard-coded credential authentication bypass vulnerability. If exploited, this vulnerability allows access to the RabbitMQ management console. We thank Trend Micro Zero Day Initiative (ZDI) for its ongoing partnership…

  • CVE-2024-28073HigApr 17, 2024
    risk 0.55cvss 8.4epss 0.01

    SolarWinds Serv-U was found to be susceptible to a Directory Traversal Remote Code Vulnerability. This vulnerability requires a highly privileged account to be exploited.

  • CVE-2022-38108HigOct 20, 2022
    risk 0.55cvss 7.2epss 0.68

    SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to SolarWinds Web Console to execute arbitrary commands.

  • CVE-2021-35245HigDec 6, 2021
    risk 0.55cvss 8.4epss 0.01

    When a user has admin rights in Serv-U Console, the user can move, create and delete any files are able to be accessed on the Serv-U host machine.

  • CVE-2021-35223HigAug 31, 2021
    risk 0.55cvss 8.5epss 0.03

    The Serv-U File Server allows for events such as user login failures to be audited by executing a command. This command can be supplied with parameters that can take the form of user string variables, allowing remote code execution.

  • CVE-2020-25621HigDec 16, 2020
    risk 0.55cvss 8.4epss 0.01

    An issue was discovered in SolarWinds N-Central 12.3.0.670. The local database does not require authentication: security is only based on ability to access a network interface. The database has keys and passwords.

  • CVE-2020-12608HigMay 7, 2020
    risk 0.55cvss 7.8epss 0.22

    An issue was discovered in SolarWinds MSP PME (Patch Management Engine) Cache Service before 1.1.15 in the Advanced Monitoring Agent. There are insecure file permissions for %PROGRAMDATA%\SolarWinds MSP\SolarWinds.MSP.CacheService\config\. This can lead to code execution by…

  • CVE-2024-23465HigJul 17, 2024
    risk 0.54cvss 8.3epss 0.02

    The SolarWinds Access Rights Manager was found to be susceptible to an authentication bypass vulnerability. This vulnerability allows an unauthenticated user to gain domain admin access within the Active Directory environment.  

  • CVE-2023-35180HigOct 19, 2023
    risk 0.54cvss 8.0epss 0.27

    The SolarWinds Access Rights Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows authenticated users to abuse SolarWinds ARM API.

  • CVE-2022-38111HigFeb 15, 2023
    risk 0.54cvss 7.2epss 0.85

    SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to SolarWinds Web Console to execute arbitrary commands.

  • CVE-2021-35242HigDec 6, 2021
    risk 0.54cvss 8.3epss 0.01

    Serv-U server responds with valid CSRFToken when the request contains only Session.

  • CVE-2020-27871HigFeb 10, 2021
    risk 0.54cvss 7.2epss 0.90

    This vulnerability allows remote attackers to create arbitrary files on affected installations of SolarWinds Orion Platform 2020.2.1. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw…

  • CVE-2018-12897HigSep 7, 2018
    risk 0.54cvss 7.8epss 0.02

    SolarWinds DameWare Mini Remote Control before 12.1 has a Buffer Overflow.

  • CVE-2026-28299HigJun 2, 2026
    risk 0.53cvss 8.2epss 0.00

    SolarWinds Web Help Desk is found to be affected by a denial-of-service vulnerability, which when exploited, could cause the Web Help Desk server to crash due to insufficient memory.

  • CVE-2023-23836HigFeb 15, 2023
    risk 0.53cvss 7.2epss 0.80

    SolarWinds Platform version 2022.4.1 was found to be susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to the SolarWinds Web Console to execute arbitrary commands.

  • CVE-2021-35254HigMar 25, 2022
    risk 0.53cvss 8.2epss 0.01

    SolarWinds received a report of a vulnerability related to an input that was not sanitized in WebHelpDesk. SolarWinds has removed this input field to prevent the misuse of this input in the future.

  • CVE-2021-35220HigAug 31, 2021
    risk 0.53cvss 8.1epss 0.02

    Command Injection vulnerability in EmailWebPage API which can lead to a Remote Code Execution (RCE) from the Alerts Settings page.

Page 2 of 7