VYPR

Vendor CVEs

SolarWinds

All CVEs

342 total · sorted by risk
  • CVE-2019-9017HigMay 2, 2019
    risk 0.53cvss 7.5epss 0.21

    DWRCC in SolarWinds DameWare Mini Remote Control 10.0 x64 has a Buffer Overflow associated with the size field for the machine name.

  • CVE-2024-23477HigFeb 15, 2024
    risk 0.52cvss 7.9epss 0.08

    The SolarWinds Access Rights Manager (ARM) was found to be susceptible to a Directory Traversal Remote Code Execution Vulnerability. If exploited, this vulnerability allows an unauthenticated user to achieve a Remote Code Execution.

  • CVE-2023-50395HigFeb 6, 2024
    risk 0.52cvss 8.0epss 0.02

    SQL Injection Remote Code Execution Vulnerability was found using an update statement in the SolarWinds Platform. This vulnerability requires user authentication to be exploited

  • CVE-2023-35188HigFeb 6, 2024
    risk 0.52cvss 8.0epss 0.02

    SQL Injection Remote Code Execution Vulnerability was found using a create statement in the SolarWinds Platform. This vulnerability requires user authentication to be exploited.

  • CVE-2023-40056HigNov 28, 2023
    risk 0.52cvss 8.0epss 0.05

    SQL Injection Remote Code Vulnerability was found in the SolarWinds Platform. This vulnerability can be exploited with a low privileged account.

  • CVE-2023-40055HigNov 9, 2023
    risk 0.52cvss 8.0epss 0.02

    The Network Configuration Manager was susceptible to a Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows a low-level user to perform the actions with SYSTEM privileges. We found this issue was not resolved in CVE-2023-33227

  • CVE-2023-40054HigNov 9, 2023
    risk 0.52cvss 8.0epss 0.03

    The Network Configuration Manager was susceptible to a Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows a low-level user to perform the actions with SYSTEM privileges. We found this issue was not resolved in CVE-2023-33226

  • CVE-2023-40062HigNov 1, 2023
    risk 0.52cvss 8.0epss 0.03

    SolarWinds Platform Incomplete List of Disallowed Inputs Remote Code Execution Vulnerability. If executed, this vulnerability would allow a low-privileged user to execute commands with SYSTEM privileges.

  • CVE-2023-33227HigNov 1, 2023
    risk 0.52cvss 8.0epss 0.02

    The Network Configuration Manager was susceptible to a Directory Traversal Remote Code Execution Vulnerability This vulnerability allows a low level user to perform the actions with SYSTEM privileges.

  • CVE-2023-33226HigNov 1, 2023
    risk 0.52cvss 8.0epss 0.02

    The Network Configuration Manager was susceptible to a Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows a low-level user to perform the actions with SYSTEM privileges.

  • CVE-2023-35186HigOct 19, 2023
    risk 0.52cvss 8.0epss 0.02

    The SolarWinds Access Rights Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows an authenticated user to abuse SolarWinds service resulting in remote code execution.

  • CVE-2021-35234HigDec 20, 2021
    risk 0.52cvss 8.0epss 0.03

    Numerous exposed dangerous functions within Orion Core has allows for read-only SQL injection leading to privileged escalation. An attacker with low-user privileges may steal password hashes and password salt information.

  • CVE-2021-35222HigAug 31, 2021
    risk 0.52cvss 8.0epss 0.03

    This vulnerability allows attackers to impersonate users and perform arbitrary actions leading to a Remote Code Execution (RCE) from the Alerts Settings page.

  • CVE-2025-26397HigJul 24, 2025
    risk 0.51cvss 7.8epss 0.00

    SolarWinds Observability Self-Hosted is susceptible to Deserialization of Untrusted Data Local Privilege Escalation vulnerability. An attacker with low privileges can escalate privileges to run malicious files copied to a permission-protected folder. This vulnerability requires…

  • CVE-2025-26396HigJun 2, 2025
    risk 0.51cvss 7.8epss 0.00

    The SolarWinds Dameware Mini Remote Control was determined to be affected by Incorrect Permissions Local Privilege Escalation Vulnerability. This vulnerability requires local access and a valid low privilege account to be susceptible to this vulnerability.

  • CVE-2024-45710HigOct 16, 2024
    risk 0.51cvss 7.8epss 0.00

    SolarWinds Platform is susceptible to an Uncontrolled Search Path Element Local Privilege Escalation vulnerability. This requires a low privilege account and local access to the affected node machine.

  • CVE-2024-29000HigMay 20, 2024
    risk 0.51cvss 7.9epss 0.00

    The SolarWinds Platform was determined to be affected by a reflected cross-site scripting vulnerability affecting the web console. A high-privileged user and user interaction is required to exploit this vulnerability.

  • CVE-2023-35183HigOct 19, 2023
    risk 0.51cvss 7.8epss 0.00

    The SolarWinds Access Rights Manager was susceptible to Privilege Escalation Vulnerability. This vulnerability allows authenticated users to abuse local resources to Privilege Escalation.

  • CVE-2023-35181HigOct 19, 2023
    risk 0.51cvss 7.8epss 0.00

    The SolarWinds Access Rights Manager was susceptible to Privilege Escalation Vulnerability. This vulnerability allows users to abuse incorrect folder permission resulting in Privilege Escalation.

  • CVE-2022-47505HigApr 21, 2023
    risk 0.51cvss 7.8epss 0.00

    The SolarWinds Platform was susceptible to the Local Privilege Escalation Vulnerability. This vulnerability allows a local adversary with a valid system user account to escalate local privileges.

  • CVE-2022-47506HigFeb 15, 2023
    risk 0.51cvss 7.8epss 0.01

    SolarWinds Platform was susceptible to the Directory Traversal Vulnerability. This vulnerability allows a local adversary with authenticated account access to edit the default configuration, enabling the execution of arbitrary commands.

  • CVE-2021-27277HigApr 22, 2021
    risk 0.51cvss 7.8epss 0.01

    This vulnerability allows local attackers to escalate privileges on affected installations of SolarWinds Orion Virtual Infrastructure Monitor 2020.2. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this…

  • CVE-2021-27240HigMar 29, 2021
    risk 0.51cvss 7.8epss 0.00

    This vulnerability allows local attackers to escalate privileges on affected installations of SolarWinds Patch Manager 2020.2.1. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific…

  • CVE-2021-25275HigFeb 3, 2021
    risk 0.51cvss 7.8epss 0.01

    SolarWinds Orion Platform before 2020.2.4, as used by various SolarWinds products, installs and uses a SQL Server backend, and stores database credentials to access this backend in a file readable by unprivileged users. As a result, any user having access to the filesystem can…

  • CVE-2020-25620HigDec 16, 2020
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in SolarWinds N-Central 12.3.0.670. Hard-coded Credentials exist by default for local user accounts named [email protected] and [email protected]. These allow logins to the N-Central Administrative Console (NAC) and/or the regular web interface.

  • CVE-2019-20002HigApr 27, 2020
    risk 0.51cvss 7.8epss 0.01

    Formula Injection exists in the export feature in SolarWinds WebHelpDesk 12.7.1 via a value (provided by a low-privileged user in the Subject field of a help request form) that is mishandled in a TicketActions/view?tab=group TSV export by an admin user.

  • CVE-2020-5734HigApr 7, 2020
    risk 0.51cvss 7.5epss 0.25

    Classic buffer overflow in SolarWinds Dameware allows a remote, unauthenticated attacker to cause a denial of service by sending a large 'SigPubkeyLen' during ECDH key exchange.

  • CVE-2018-19999HigJun 7, 2019
    risk 0.51cvss 7.8epss 0.01

    The local management interface in SolarWinds Serv-U FTP Server 15.1.6.25 has incorrect access controls that permit local users to bypass authentication in the application and execute code in the context of the Windows SYSTEM account, leading to privilege escalation. To exploit…

  • CVE-2024-28992HigJul 17, 2024
    risk 0.50cvss 7.6epss 0.02

    The SolarWinds Access Rights Manager was susceptible to a Directory Traversal and Information Disclosure Vulnerability. This vulnerability allows an unauthenticated user to perform arbitrary file deletion and leak sensitive information.

  • CVE-2024-23474HigJul 17, 2024
    risk 0.50cvss 7.6epss 0.02

    The SolarWinds Access Rights Manager was found to be susceptible to an Arbitrary File Deletion and Information Disclosure vulnerability.

  • CVE-2024-23468HigJul 17, 2024
    risk 0.50cvss 7.6epss 0.03

    The SolarWinds Access Rights Manager was susceptible to a Directory Traversal and Information Disclosure Vulnerability. This vulnerability allows an unauthenticated user to perform arbitrary file deletion and leak sensitive information.

  • CVE-2021-35250HigApr 25, 2022
    risk 0.50cvss 7.5epss 0.13

    A researcher reported a Directory Transversal Vulnerability in Serv-U 15.3. This may allow access to files relating to the Serv-U installation and server files. This issue has been resolved in Serv-U 15.3 Hotfix 1.

  • CVE-2019-3957HigJun 7, 2019
    risk 0.50cvss 7.4epss 0.26

    Dameware Remote Mini Control version 12.1.0.34 and prior contains an unauthenticated remote buffer over-read due to the server not properly validating RsaSignatureLen during key negotiation, which could crash the application or leak sensitive information.

  • CVE-2025-40537HigJan 28, 2026
    risk 0.49cvss 7.5epss 0.01

    SolarWinds Web Help Desk was found to be susceptible to a hardcoded credentials vulnerability that, under certain situations, could allow access to administrative functions.

  • CVE-2024-45711HigOct 16, 2024
    risk 0.49cvss 7.5epss 0.06

    SolarWinds Serv-U is vulnerable to a directory traversal vulnerability where remote code execution is possible depending on privileges given to the authenticated user. This issue requires a user to be authenticated and this is present when software environment variables are…

  • CVE-2024-28993HigJul 17, 2024
    risk 0.49cvss 7.6epss 0.01

    The SolarWinds Access Rights Manager was susceptible to a Directory Traversal and Information Disclosure Vulnerability. This vulnerability allows an unauthenticated user to perform arbitrary file deletion and leak sensitive information.

  • CVE-2024-28996HigJun 4, 2024
    risk 0.49cvss 7.5epss 0.00

    The SolarWinds Platform was determined to be affected by a SWQL Injection Vulnerability. Attack complexity is high for this vulnerability.  

  • CVE-2024-29003HigApr 18, 2024
    risk 0.49cvss 7.5epss 0.01

    The SolarWinds Platform was susceptible to a XSS vulnerability that affects the maps section of the user interface. This vulnerability requires authentication and requires user interaction.

  • CVE-2024-29001HigApr 18, 2024
    risk 0.49cvss 7.5epss 0.01

    A SolarWinds Platform SWQL Injection Vulnerability was identified in the user interface. This vulnerability requires authentication and user interaction to be exploited.

  • CVE-2023-23841HigJun 15, 2023
    risk 0.49cvss 7.5epss 0.00

    SolarWinds Serv-U is submitting an HTTP request when changing or updating the attributes for File Share or File request.  Part of the URL of the request discloses sensitive data.

  • CVE-2023-23837HigApr 25, 2023
    risk 0.49cvss 7.5epss 0.01

    No exception handling vulnerability which revealed sensitive or excessive information to users.

  • CVE-2022-47508HigFeb 15, 2023
    risk 0.49cvss 7.5epss 0.01

    Customers who had configured their polling to occur via Kerberos did not expect NTLM Traffic on their environment, but since we were querying for data via IP address this prevented us from utilizing Kerberos.

  • CVE-2022-47504HigFeb 15, 2023
    risk 0.49cvss 7.2epss 0.25

    SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to SolarWinds Web Console to execute arbitrary commands.

  • CVE-2022-47503HigFeb 15, 2023
    risk 0.49cvss 7.2epss 0.24

    SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to SolarWinds Web Console to execute arbitrary commands.

  • CVE-2022-47012HigJan 20, 2023
    risk 0.49cvss 7.5epss 0.01

    Use of uninitialized variable in function gen_eth_recv in GNS3 dynamips 0.2.21.

  • CVE-2022-38112HigJan 20, 2023
    risk 0.49cvss 7.5epss 0.00

    In DPA 2022.4 and older releases, generated heap memory dumps contain sensitive information in cleartext.

  • CVE-2021-35252HigDec 16, 2022
    risk 0.49cvss 7.5epss 0.01

    Common encryption key appears to be used across all deployed instances of Serv-U FTP Server. Because of this an encrypted value that is exposed to an attacker can be simply recovered to plaintext.

  • CVE-2021-35239HigAug 31, 2021
    risk 0.49cvss 7.5epss 0.01

    A security researcher found a user with Orion map manage rights could store XSS through via text box hyperlink.

  • CVE-2021-3154HigMay 4, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in SolarWinds Serv-U before 15.2.2. Unauthenticated attackers can retrieve cleartext passwords via macro Injection. NOTE: this had a distinct fix relative to CVE-2020-35481.

  • CVE-2020-15576HigJul 7, 2020
    risk 0.49cvss 7.5epss 0.02

    SolarWinds Serv-U File Server before 15.2.1 allows information disclosure via an HTTP response.

Page 3 of 7