Vendor CVEs
SolarWinds
All CVEs
342 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-9017 | Hig | 0.53 | 7.5 | 0.21 | May 2, 2019 | DWRCC in SolarWinds DameWare Mini Remote Control 10.0 x64 has a Buffer Overflow associated with the size field for the machine name. | ||
| CVE-2024-23477 | Hig | 0.52 | 7.9 | 0.08 | Feb 15, 2024 | The SolarWinds Access Rights Manager (ARM) was found to be susceptible to a Directory Traversal Remote Code Execution Vulnerability. If exploited, this vulnerability allows an unauthenticated user to achieve a Remote Code Execution. | ||
| CVE-2023-50395 | Hig | 0.52 | 8.0 | 0.02 | Feb 6, 2024 | SQL Injection Remote Code Execution Vulnerability was found using an update statement in the SolarWinds Platform. This vulnerability requires user authentication to be exploited | ||
| CVE-2023-35188 | Hig | 0.52 | 8.0 | 0.02 | Feb 6, 2024 | SQL Injection Remote Code Execution Vulnerability was found using a create statement in the SolarWinds Platform. This vulnerability requires user authentication to be exploited. | ||
| CVE-2023-40056 | Hig | 0.52 | 8.0 | 0.05 | Nov 28, 2023 | SQL Injection Remote Code Vulnerability was found in the SolarWinds Platform. This vulnerability can be exploited with a low privileged account. | ||
| CVE-2023-40055 | Hig | 0.52 | 8.0 | 0.02 | Nov 9, 2023 | The Network Configuration Manager was susceptible to a Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows a low-level user to perform the actions with SYSTEM privileges. We found this issue was not resolved in CVE-2023-33227 | ||
| CVE-2023-40054 | Hig | 0.52 | 8.0 | 0.03 | Nov 9, 2023 | The Network Configuration Manager was susceptible to a Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows a low-level user to perform the actions with SYSTEM privileges. We found this issue was not resolved in CVE-2023-33226 | ||
| CVE-2023-40062 | Hig | 0.52 | 8.0 | 0.03 | Nov 1, 2023 | SolarWinds Platform Incomplete List of Disallowed Inputs Remote Code Execution Vulnerability. If executed, this vulnerability would allow a low-privileged user to execute commands with SYSTEM privileges. | ||
| CVE-2023-33227 | Hig | 0.52 | 8.0 | 0.02 | Nov 1, 2023 | The Network Configuration Manager was susceptible to a Directory Traversal Remote Code Execution Vulnerability This vulnerability allows a low level user to perform the actions with SYSTEM privileges. | ||
| CVE-2023-33226 | Hig | 0.52 | 8.0 | 0.02 | Nov 1, 2023 | The Network Configuration Manager was susceptible to a Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows a low-level user to perform the actions with SYSTEM privileges. | ||
| CVE-2023-35186 | Hig | 0.52 | 8.0 | 0.02 | Oct 19, 2023 | The SolarWinds Access Rights Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows an authenticated user to abuse SolarWinds service resulting in remote code execution. | ||
| CVE-2021-35234 | Hig | 0.52 | 8.0 | 0.03 | Dec 20, 2021 | Numerous exposed dangerous functions within Orion Core has allows for read-only SQL injection leading to privileged escalation. An attacker with low-user privileges may steal password hashes and password salt information. | ||
| CVE-2021-35222 | Hig | 0.52 | 8.0 | 0.03 | Aug 31, 2021 | This vulnerability allows attackers to impersonate users and perform arbitrary actions leading to a Remote Code Execution (RCE) from the Alerts Settings page. | ||
| CVE-2025-26397 | Hig | 0.51 | 7.8 | 0.00 | Jul 24, 2025 | SolarWinds Observability Self-Hosted is susceptible to Deserialization of Untrusted Data Local Privilege Escalation vulnerability. An attacker with low privileges can escalate privileges to run malicious files copied to a permission-protected folder. This vulnerability requires… | ||
| CVE-2025-26396 | Hig | 0.51 | 7.8 | 0.00 | Jun 2, 2025 | The SolarWinds Dameware Mini Remote Control was determined to be affected by Incorrect Permissions Local Privilege Escalation Vulnerability. This vulnerability requires local access and a valid low privilege account to be susceptible to this vulnerability. | ||
| CVE-2024-45710 | Hig | 0.51 | 7.8 | 0.00 | Oct 16, 2024 | SolarWinds Platform is susceptible to an Uncontrolled Search Path Element Local Privilege Escalation vulnerability. This requires a low privilege account and local access to the affected node machine. | ||
| CVE-2024-29000 | Hig | 0.51 | 7.9 | 0.00 | May 20, 2024 | The SolarWinds Platform was determined to be affected by a reflected cross-site scripting vulnerability affecting the web console. A high-privileged user and user interaction is required to exploit this vulnerability. | ||
| CVE-2023-35183 | Hig | 0.51 | 7.8 | 0.00 | Oct 19, 2023 | The SolarWinds Access Rights Manager was susceptible to Privilege Escalation Vulnerability. This vulnerability allows authenticated users to abuse local resources to Privilege Escalation. | ||
| CVE-2023-35181 | Hig | 0.51 | 7.8 | 0.00 | Oct 19, 2023 | The SolarWinds Access Rights Manager was susceptible to Privilege Escalation Vulnerability. This vulnerability allows users to abuse incorrect folder permission resulting in Privilege Escalation. | ||
| CVE-2022-47505 | Hig | 0.51 | 7.8 | 0.00 | Apr 21, 2023 | The SolarWinds Platform was susceptible to the Local Privilege Escalation Vulnerability. This vulnerability allows a local adversary with a valid system user account to escalate local privileges. | ||
| CVE-2022-47506 | Hig | 0.51 | 7.8 | 0.01 | Feb 15, 2023 | SolarWinds Platform was susceptible to the Directory Traversal Vulnerability. This vulnerability allows a local adversary with authenticated account access to edit the default configuration, enabling the execution of arbitrary commands. | ||
| CVE-2021-27277 | Hig | 0.51 | 7.8 | 0.01 | Apr 22, 2021 | This vulnerability allows local attackers to escalate privileges on affected installations of SolarWinds Orion Virtual Infrastructure Monitor 2020.2. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this… | ||
| CVE-2021-27240 | Hig | 0.51 | 7.8 | 0.00 | Mar 29, 2021 | This vulnerability allows local attackers to escalate privileges on affected installations of SolarWinds Patch Manager 2020.2.1. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific… | ||
| CVE-2021-25275 | Hig | 0.51 | 7.8 | 0.01 | Feb 3, 2021 | SolarWinds Orion Platform before 2020.2.4, as used by various SolarWinds products, installs and uses a SQL Server backend, and stores database credentials to access this backend in a file readable by unprivileged users. As a result, any user having access to the filesystem can… | ||
| CVE-2020-25620 | Hig | 0.51 | 7.8 | 0.00 | Dec 16, 2020 | An issue was discovered in SolarWinds N-Central 12.3.0.670. Hard-coded Credentials exist by default for local user accounts named [email protected] and [email protected]. These allow logins to the N-Central Administrative Console (NAC) and/or the regular web interface. | ||
| CVE-2019-20002 | Hig | 0.51 | 7.8 | 0.01 | Apr 27, 2020 | Formula Injection exists in the export feature in SolarWinds WebHelpDesk 12.7.1 via a value (provided by a low-privileged user in the Subject field of a help request form) that is mishandled in a TicketActions/view?tab=group TSV export by an admin user. | ||
| CVE-2020-5734 | Hig | 0.51 | 7.5 | 0.25 | Apr 7, 2020 | Classic buffer overflow in SolarWinds Dameware allows a remote, unauthenticated attacker to cause a denial of service by sending a large 'SigPubkeyLen' during ECDH key exchange. | ||
| CVE-2018-19999 | Hig | 0.51 | 7.8 | 0.01 | Jun 7, 2019 | The local management interface in SolarWinds Serv-U FTP Server 15.1.6.25 has incorrect access controls that permit local users to bypass authentication in the application and execute code in the context of the Windows SYSTEM account, leading to privilege escalation. To exploit… | ||
| CVE-2024-28992 | Hig | 0.50 | 7.6 | 0.02 | Jul 17, 2024 | The SolarWinds Access Rights Manager was susceptible to a Directory Traversal and Information Disclosure Vulnerability. This vulnerability allows an unauthenticated user to perform arbitrary file deletion and leak sensitive information. | ||
| CVE-2024-23474 | Hig | 0.50 | 7.6 | 0.02 | Jul 17, 2024 | The SolarWinds Access Rights Manager was found to be susceptible to an Arbitrary File Deletion and Information Disclosure vulnerability. | ||
| CVE-2024-23468 | Hig | 0.50 | 7.6 | 0.03 | Jul 17, 2024 | The SolarWinds Access Rights Manager was susceptible to a Directory Traversal and Information Disclosure Vulnerability. This vulnerability allows an unauthenticated user to perform arbitrary file deletion and leak sensitive information. | ||
| CVE-2021-35250 | Hig | 0.50 | 7.5 | 0.13 | Apr 25, 2022 | A researcher reported a Directory Transversal Vulnerability in Serv-U 15.3. This may allow access to files relating to the Serv-U installation and server files. This issue has been resolved in Serv-U 15.3 Hotfix 1. | ||
| CVE-2019-3957 | Hig | 0.50 | 7.4 | 0.26 | Jun 7, 2019 | Dameware Remote Mini Control version 12.1.0.34 and prior contains an unauthenticated remote buffer over-read due to the server not properly validating RsaSignatureLen during key negotiation, which could crash the application or leak sensitive information. | ||
| CVE-2025-40537 | Hig | 0.49 | 7.5 | 0.01 | Jan 28, 2026 | SolarWinds Web Help Desk was found to be susceptible to a hardcoded credentials vulnerability that, under certain situations, could allow access to administrative functions. | ||
| CVE-2024-45711 | Hig | 0.49 | 7.5 | 0.06 | Oct 16, 2024 | SolarWinds Serv-U is vulnerable to a directory traversal vulnerability where remote code execution is possible depending on privileges given to the authenticated user. This issue requires a user to be authenticated and this is present when software environment variables are… | ||
| CVE-2024-28993 | Hig | 0.49 | 7.6 | 0.01 | Jul 17, 2024 | The SolarWinds Access Rights Manager was susceptible to a Directory Traversal and Information Disclosure Vulnerability. This vulnerability allows an unauthenticated user to perform arbitrary file deletion and leak sensitive information. | ||
| CVE-2024-28996 | Hig | 0.49 | 7.5 | 0.00 | Jun 4, 2024 | The SolarWinds Platform was determined to be affected by a SWQL Injection Vulnerability. Attack complexity is high for this vulnerability. | ||
| CVE-2024-29003 | Hig | 0.49 | 7.5 | 0.01 | Apr 18, 2024 | The SolarWinds Platform was susceptible to a XSS vulnerability that affects the maps section of the user interface. This vulnerability requires authentication and requires user interaction. | ||
| CVE-2024-29001 | Hig | 0.49 | 7.5 | 0.01 | Apr 18, 2024 | A SolarWinds Platform SWQL Injection Vulnerability was identified in the user interface. This vulnerability requires authentication and user interaction to be exploited. | ||
| CVE-2023-23841 | Hig | 0.49 | 7.5 | 0.00 | Jun 15, 2023 | SolarWinds Serv-U is submitting an HTTP request when changing or updating the attributes for File Share or File request. Part of the URL of the request discloses sensitive data. | ||
| CVE-2023-23837 | Hig | 0.49 | 7.5 | 0.01 | Apr 25, 2023 | No exception handling vulnerability which revealed sensitive or excessive information to users. | ||
| CVE-2022-47508 | Hig | 0.49 | 7.5 | 0.01 | Feb 15, 2023 | Customers who had configured their polling to occur via Kerberos did not expect NTLM Traffic on their environment, but since we were querying for data via IP address this prevented us from utilizing Kerberos. | ||
| CVE-2022-47504 | Hig | 0.49 | 7.2 | 0.25 | Feb 15, 2023 | SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to SolarWinds Web Console to execute arbitrary commands. | ||
| CVE-2022-47503 | Hig | 0.49 | 7.2 | 0.24 | Feb 15, 2023 | SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to SolarWinds Web Console to execute arbitrary commands. | ||
| CVE-2022-47012 | Hig | 0.49 | 7.5 | 0.01 | Jan 20, 2023 | Use of uninitialized variable in function gen_eth_recv in GNS3 dynamips 0.2.21. | ||
| CVE-2022-38112 | Hig | 0.49 | 7.5 | 0.00 | Jan 20, 2023 | In DPA 2022.4 and older releases, generated heap memory dumps contain sensitive information in cleartext. | ||
| CVE-2021-35252 | Hig | 0.49 | 7.5 | 0.01 | Dec 16, 2022 | Common encryption key appears to be used across all deployed instances of Serv-U FTP Server. Because of this an encrypted value that is exposed to an attacker can be simply recovered to plaintext. | ||
| CVE-2021-35239 | Hig | 0.49 | 7.5 | 0.01 | Aug 31, 2021 | A security researcher found a user with Orion map manage rights could store XSS through via text box hyperlink. | ||
| CVE-2021-3154 | Hig | 0.49 | 7.5 | 0.01 | May 4, 2021 | An issue was discovered in SolarWinds Serv-U before 15.2.2. Unauthenticated attackers can retrieve cleartext passwords via macro Injection. NOTE: this had a distinct fix relative to CVE-2020-35481. | ||
| CVE-2020-15576 | Hig | 0.49 | 7.5 | 0.02 | Jul 7, 2020 | SolarWinds Serv-U File Server before 15.2.1 allows information disclosure via an HTTP response. |
- risk 0.53cvss 7.5epss 0.21
DWRCC in SolarWinds DameWare Mini Remote Control 10.0 x64 has a Buffer Overflow associated with the size field for the machine name.
- risk 0.52cvss 7.9epss 0.08
The SolarWinds Access Rights Manager (ARM) was found to be susceptible to a Directory Traversal Remote Code Execution Vulnerability. If exploited, this vulnerability allows an unauthenticated user to achieve a Remote Code Execution.
- risk 0.52cvss 8.0epss 0.02
SQL Injection Remote Code Execution Vulnerability was found using an update statement in the SolarWinds Platform. This vulnerability requires user authentication to be exploited
- risk 0.52cvss 8.0epss 0.02
SQL Injection Remote Code Execution Vulnerability was found using a create statement in the SolarWinds Platform. This vulnerability requires user authentication to be exploited.
- risk 0.52cvss 8.0epss 0.05
SQL Injection Remote Code Vulnerability was found in the SolarWinds Platform. This vulnerability can be exploited with a low privileged account.
- risk 0.52cvss 8.0epss 0.02
The Network Configuration Manager was susceptible to a Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows a low-level user to perform the actions with SYSTEM privileges. We found this issue was not resolved in CVE-2023-33227
- risk 0.52cvss 8.0epss 0.03
The Network Configuration Manager was susceptible to a Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows a low-level user to perform the actions with SYSTEM privileges. We found this issue was not resolved in CVE-2023-33226
- risk 0.52cvss 8.0epss 0.03
SolarWinds Platform Incomplete List of Disallowed Inputs Remote Code Execution Vulnerability. If executed, this vulnerability would allow a low-privileged user to execute commands with SYSTEM privileges.
- risk 0.52cvss 8.0epss 0.02
The Network Configuration Manager was susceptible to a Directory Traversal Remote Code Execution Vulnerability This vulnerability allows a low level user to perform the actions with SYSTEM privileges.
- risk 0.52cvss 8.0epss 0.02
The Network Configuration Manager was susceptible to a Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows a low-level user to perform the actions with SYSTEM privileges.
- risk 0.52cvss 8.0epss 0.02
The SolarWinds Access Rights Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows an authenticated user to abuse SolarWinds service resulting in remote code execution.
- risk 0.52cvss 8.0epss 0.03
Numerous exposed dangerous functions within Orion Core has allows for read-only SQL injection leading to privileged escalation. An attacker with low-user privileges may steal password hashes and password salt information.
- risk 0.52cvss 8.0epss 0.03
This vulnerability allows attackers to impersonate users and perform arbitrary actions leading to a Remote Code Execution (RCE) from the Alerts Settings page.
- risk 0.51cvss 7.8epss 0.00
SolarWinds Observability Self-Hosted is susceptible to Deserialization of Untrusted Data Local Privilege Escalation vulnerability. An attacker with low privileges can escalate privileges to run malicious files copied to a permission-protected folder. This vulnerability requires…
- risk 0.51cvss 7.8epss 0.00
The SolarWinds Dameware Mini Remote Control was determined to be affected by Incorrect Permissions Local Privilege Escalation Vulnerability. This vulnerability requires local access and a valid low privilege account to be susceptible to this vulnerability.
- risk 0.51cvss 7.8epss 0.00
SolarWinds Platform is susceptible to an Uncontrolled Search Path Element Local Privilege Escalation vulnerability. This requires a low privilege account and local access to the affected node machine.
- risk 0.51cvss 7.9epss 0.00
The SolarWinds Platform was determined to be affected by a reflected cross-site scripting vulnerability affecting the web console. A high-privileged user and user interaction is required to exploit this vulnerability.
- risk 0.51cvss 7.8epss 0.00
The SolarWinds Access Rights Manager was susceptible to Privilege Escalation Vulnerability. This vulnerability allows authenticated users to abuse local resources to Privilege Escalation.
- risk 0.51cvss 7.8epss 0.00
The SolarWinds Access Rights Manager was susceptible to Privilege Escalation Vulnerability. This vulnerability allows users to abuse incorrect folder permission resulting in Privilege Escalation.
- risk 0.51cvss 7.8epss 0.00
The SolarWinds Platform was susceptible to the Local Privilege Escalation Vulnerability. This vulnerability allows a local adversary with a valid system user account to escalate local privileges.
- risk 0.51cvss 7.8epss 0.01
SolarWinds Platform was susceptible to the Directory Traversal Vulnerability. This vulnerability allows a local adversary with authenticated account access to edit the default configuration, enabling the execution of arbitrary commands.
- risk 0.51cvss 7.8epss 0.01
This vulnerability allows local attackers to escalate privileges on affected installations of SolarWinds Orion Virtual Infrastructure Monitor 2020.2. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this…
- risk 0.51cvss 7.8epss 0.00
This vulnerability allows local attackers to escalate privileges on affected installations of SolarWinds Patch Manager 2020.2.1. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific…
- risk 0.51cvss 7.8epss 0.01
SolarWinds Orion Platform before 2020.2.4, as used by various SolarWinds products, installs and uses a SQL Server backend, and stores database credentials to access this backend in a file readable by unprivileged users. As a result, any user having access to the filesystem can…
- risk 0.51cvss 7.8epss 0.00
An issue was discovered in SolarWinds N-Central 12.3.0.670. Hard-coded Credentials exist by default for local user accounts named [email protected] and [email protected]. These allow logins to the N-Central Administrative Console (NAC) and/or the regular web interface.
- risk 0.51cvss 7.8epss 0.01
Formula Injection exists in the export feature in SolarWinds WebHelpDesk 12.7.1 via a value (provided by a low-privileged user in the Subject field of a help request form) that is mishandled in a TicketActions/view?tab=group TSV export by an admin user.
- risk 0.51cvss 7.5epss 0.25
Classic buffer overflow in SolarWinds Dameware allows a remote, unauthenticated attacker to cause a denial of service by sending a large 'SigPubkeyLen' during ECDH key exchange.
- risk 0.51cvss 7.8epss 0.01
The local management interface in SolarWinds Serv-U FTP Server 15.1.6.25 has incorrect access controls that permit local users to bypass authentication in the application and execute code in the context of the Windows SYSTEM account, leading to privilege escalation. To exploit…
- risk 0.50cvss 7.6epss 0.02
The SolarWinds Access Rights Manager was susceptible to a Directory Traversal and Information Disclosure Vulnerability. This vulnerability allows an unauthenticated user to perform arbitrary file deletion and leak sensitive information.
- risk 0.50cvss 7.6epss 0.02
The SolarWinds Access Rights Manager was found to be susceptible to an Arbitrary File Deletion and Information Disclosure vulnerability.
- risk 0.50cvss 7.6epss 0.03
The SolarWinds Access Rights Manager was susceptible to a Directory Traversal and Information Disclosure Vulnerability. This vulnerability allows an unauthenticated user to perform arbitrary file deletion and leak sensitive information.
- risk 0.50cvss 7.5epss 0.13
A researcher reported a Directory Transversal Vulnerability in Serv-U 15.3. This may allow access to files relating to the Serv-U installation and server files. This issue has been resolved in Serv-U 15.3 Hotfix 1.
- risk 0.50cvss 7.4epss 0.26
Dameware Remote Mini Control version 12.1.0.34 and prior contains an unauthenticated remote buffer over-read due to the server not properly validating RsaSignatureLen during key negotiation, which could crash the application or leak sensitive information.
- risk 0.49cvss 7.5epss 0.01
SolarWinds Web Help Desk was found to be susceptible to a hardcoded credentials vulnerability that, under certain situations, could allow access to administrative functions.
- risk 0.49cvss 7.5epss 0.06
SolarWinds Serv-U is vulnerable to a directory traversal vulnerability where remote code execution is possible depending on privileges given to the authenticated user. This issue requires a user to be authenticated and this is present when software environment variables are…
- risk 0.49cvss 7.6epss 0.01
The SolarWinds Access Rights Manager was susceptible to a Directory Traversal and Information Disclosure Vulnerability. This vulnerability allows an unauthenticated user to perform arbitrary file deletion and leak sensitive information.
- risk 0.49cvss 7.5epss 0.00
The SolarWinds Platform was determined to be affected by a SWQL Injection Vulnerability. Attack complexity is high for this vulnerability.
- risk 0.49cvss 7.5epss 0.01
The SolarWinds Platform was susceptible to a XSS vulnerability that affects the maps section of the user interface. This vulnerability requires authentication and requires user interaction.
- risk 0.49cvss 7.5epss 0.01
A SolarWinds Platform SWQL Injection Vulnerability was identified in the user interface. This vulnerability requires authentication and user interaction to be exploited.
- risk 0.49cvss 7.5epss 0.00
SolarWinds Serv-U is submitting an HTTP request when changing or updating the attributes for File Share or File request. Part of the URL of the request discloses sensitive data.
- risk 0.49cvss 7.5epss 0.01
No exception handling vulnerability which revealed sensitive or excessive information to users.
- risk 0.49cvss 7.5epss 0.01
Customers who had configured their polling to occur via Kerberos did not expect NTLM Traffic on their environment, but since we were querying for data via IP address this prevented us from utilizing Kerberos.
- risk 0.49cvss 7.2epss 0.25
SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to SolarWinds Web Console to execute arbitrary commands.
- risk 0.49cvss 7.2epss 0.24
SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to SolarWinds Web Console to execute arbitrary commands.
- risk 0.49cvss 7.5epss 0.01
Use of uninitialized variable in function gen_eth_recv in GNS3 dynamips 0.2.21.
- risk 0.49cvss 7.5epss 0.00
In DPA 2022.4 and older releases, generated heap memory dumps contain sensitive information in cleartext.
- risk 0.49cvss 7.5epss 0.01
Common encryption key appears to be used across all deployed instances of Serv-U FTP Server. Because of this an encrypted value that is exposed to an attacker can be simply recovered to plaintext.
- risk 0.49cvss 7.5epss 0.01
A security researcher found a user with Orion map manage rights could store XSS through via text box hyperlink.
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in SolarWinds Serv-U before 15.2.2. Unauthenticated attackers can retrieve cleartext passwords via macro Injection. NOTE: this had a distinct fix relative to CVE-2020-35481.
- risk 0.49cvss 7.5epss 0.02
SolarWinds Serv-U File Server before 15.2.1 allows information disclosure via an HTTP response.
Page 3 of 7