VYPR

Vendor CVEs

SolarWinds

All CVEs

342 total · sorted by risk
  • CVE-2020-15574HigJul 7, 2020
    risk 0.49cvss 7.5epss 0.02

    SolarWinds Serv-U File Server before 15.2.1 mishandles the Same-Site cookie attribute, aka Case Number 00331893.

  • CVE-2020-7984HigJan 26, 2020
    risk 0.49cvss 7.5epss 0.02

    SolarWinds N-central before 12.1 SP1 HF5 and 12.2 before SP1 HF2 allows remote attackers to retrieve cleartext domain admin credentials from the Agent & Probe settings, and obtain other sensitive information. The attacker can use a customer ID to self register and read any…

  • CVE-2022-36962HigNov 29, 2022
    risk 0.48cvss 7.2epss 0.09

    SolarWinds Platform was susceptible to Command Injection. This vulnerability allows a remote adversary with complete control over the SolarWinds database to execute arbitrary commands.

  • CVE-2022-36957HigOct 20, 2022
    risk 0.48cvss 7.2epss 0.12

    SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to SolarWinds Web Console to execute arbitrary commands.

  • CVE-2020-13912HigJun 7, 2020
    risk 0.48cvss 7.3epss 0.01

    SolarWinds Advanced Monitoring Agent before 10.8.9 allows local users to gain privileges via a Trojan horse .exe file, because everyone can write to a certain .exe file.

  • CVE-2018-10240HigMay 16, 2018
    risk 0.48cvss 7.3epss 0.01

    SolarWinds Serv-U MFT before 15.1.6 HFv1 assigns authenticated users a low-entropy session token that can be included in requests to the application as a URL parameter in lieu of a session cookie. This session token's value can be brute-forced by an attacker to obtain the…

  • CVE-2023-40060HigSep 7, 2023
    risk 0.47cvss 7.2epss 0.01

    A vulnerability has been identified within Serv-U 15.4 and 15.4 Hotfix 1 that, if exploited, allows an actor to bypass multi-factor/two-factor authentication. The actor must have administrator-level access to Serv-U to perform this action. 15.4.  SolarWinds found that the…

  • CVE-2023-35179HigAug 11, 2023
    risk 0.47cvss 7.2epss 0.01

    A vulnerability has been identified within Serv-U 15.4 that, if exploited, allows an actor to bypass multi-factor/two-factor authentication. The actor must have administrator-level access to Serv-U to perform this action. 

  • CVE-2023-23842HigJul 26, 2023
    risk 0.47cvss 7.2epss 0.03

    The SolarWinds Network Configuration Manager was susceptible to the Directory Traversal Vulnerability. This vulnerability allows users with administrative access to SolarWinds Web Console to execute arbitrary commands.

  • CVE-2023-33225HigJul 26, 2023
    risk 0.47cvss 7.2epss 0.03

    The SolarWinds Platform was susceptible to the Incorrect Comparison Vulnerability. This vulnerability allows users with administrative access to SolarWinds Web Console to execute arbitrary commands with SYSTEM privileges.

  • CVE-2023-33224HigJul 26, 2023
    risk 0.47cvss 7.2epss 0.03

    The SolarWinds Platform was susceptible to the Incorrect Behavior Order Vulnerability. This vulnerability allows users with administrative access to SolarWinds Web Console to execute arbitrary commands with NETWORK SERVICE privileges.

  • CVE-2023-23844HigJul 26, 2023
    risk 0.47cvss 7.2epss 0.03

    The SolarWinds Platform was susceptible to the Incorrect Comparison Vulnerability. This vulnerability allows users with administrative access to SolarWinds Web Console to execute arbitrary commands with SYSTEM privileges.

  • CVE-2023-23843HigJul 26, 2023
    risk 0.47cvss 7.2epss 0.03

    The SolarWinds Platform was susceptible to the Incorrect Comparison Vulnerability. This vulnerability allows users with administrative access to SolarWinds Web Console to execute arbitrary commands.

  • CVE-2022-36963HigApr 21, 2023
    risk 0.47cvss 7.2epss 0.08

    The SolarWinds Platform was susceptible to the Command Injection Vulnerability. This vulnerability allows a remote adversary with a valid SolarWinds Platform admin account to execute arbitrary commands.

  • CVE-2022-47507HigFeb 15, 2023
    risk 0.47cvss 7.2epss 0.07

    SolarWinds Platform was susceptible to the Deserialization of Untrusted Data. This vulnerability allows a remote adversary with Orion admin-level account access to SolarWinds Web Console to execute arbitrary commands.

  • CVE-2018-15906HigMar 21, 2019
    risk 0.47cvss 7.2epss 0.08

    SolarWinds Serv-U FTP Server 15.1.6 allows remote authenticated users to execute arbitrary code by leveraging the Import feature and modifying a CSV file.

  • CVE-2025-26395HigJun 10, 2025
    risk 0.46cvss 7.1epss 0.00

    SolarWinds Observability Self-Hosted was susceptible to a cross-site scripting (XSS) vulnerability due to an unsanitized field in the URL. The attack requires authentication using an administrator-level account and user interaction is required.

  • CVE-2024-45717HigDec 4, 2024
    risk 0.46cvss 7.0epss 0.00

    The SolarWinds Platform was susceptible to a XSS vulnerability that affects the search and node information section of the user interface. This vulnerability requires authentication and requires user interaction.

  • CVE-2024-45715HigOct 16, 2024
    risk 0.46cvss 7.1epss 0.00

    The SolarWinds Platform was susceptible to a Cross-Site Scripting vulnerability when performing an edit function to existing elements.

  • CVE-2024-29004HigJun 4, 2024
    risk 0.46cvss 7.1epss 0.00

    The SolarWinds Platform was determined to be affected by a stored cross-site scripting vulnerability affecting the web console. A high-privileged user and user interaction is required to exploit this vulnerability.

  • CVE-2024-28999MedJun 4, 2024
    risk 0.46cvss 6.4epss 0.14

    The SolarWinds Platform was determined to be affected by a Race Condition Vulnerability affecting the web console.

  • CVE-2024-28076HigApr 18, 2024
    risk 0.46cvss 7.0epss 0.00

    The SolarWinds Platform was susceptible to a Arbitrary Open Redirection Vulnerability. A potential attacker can redirect to different domain when using URL parameter with relative entry in the correct format

  • CVE-2021-25276HigFeb 3, 2021
    risk 0.46cvss 7.1epss 0.00

    In SolarWinds Serv-U before 15.2.2 Hotfix 1, there is a directory containing user profile files (that include users' password hashes) that is world readable and writable. An unprivileged Windows user (having access to the server's filesystem) can add an FTP user by copying a…

  • CVE-2023-23845MedSep 13, 2023
    risk 0.45cvss 6.8epss 0.05

    The SolarWinds Platform was susceptible to the Incorrect Comparison Vulnerability. This vulnerability allows users with administrative access to SolarWinds Web Console to execute arbitrary commands with NETWORK SERVICE privileges.

  • CVE-2023-23840MedSep 13, 2023
    risk 0.45cvss 6.8epss 0.05

    The SolarWinds Platform was susceptible to the Incorrect Comparison Vulnerability. This vulnerability allows users with administrative access to SolarWinds Web Console to execute arbitrary commands with NETWORK SERVICE privileges.

  • CVE-2021-35244MedDec 20, 2021
    risk 0.45cvss 6.8epss 0.06

    The "Log alert to a file" action within action management enables any Orion Platform user with Orion alert management rights to write to any file. An attacker with Orion alert management rights could use this vulnerability to perform an unrestricted file upload causing a remote…

  • CVE-2024-52612MedFeb 11, 2025
    risk 0.44cvss 6.8epss 0.01

    SolarWinds Platform is vulnerable to a reflected cross-site scripting vulnerability. This was caused by an insufficient sanitation of input parameters. This vulnerability requires authentication by a high- privileged account to be exploitable.

  • CVE-2023-35185MedOct 19, 2023
    risk 0.44cvss 6.8epss 0.01

    The SolarWinds Access Rights Manager was susceptible to a Directory Traversal Remote Code Vulnerability using SYSTEM privileges.

  • CVE-2021-35229MedApr 21, 2022
    risk 0.44cvss 6.8epss 0.03

    Cross-site scripting vulnerability is present in Database Performance Monitor 2022.1.7779 and previous versions when using a complex SQL query

  • CVE-2021-35232MedDec 27, 2021
    risk 0.44cvss 6.8epss 0.00

    Hard coded credentials discovered in SolarWinds Web Help Desk product. Through these credentials, the attacker with local access to the Web Help Desk host machine allows to execute arbitrary HQL queries against the database and leverage the vulnerability to steal the password…

  • CVE-2021-35248MedDec 20, 2021
    risk 0.44cvss 6.8epss 0.01

    It has been reported that any Orion user, e.g. guest accounts can query the Orion.UserSettings entity and enumerate users and their basic settings.

  • CVE-2021-35231MedOct 25, 2021
    risk 0.44cvss 6.7epss 0.00

    As a result of an unquoted service path vulnerability present in the Kiwi Syslog Server Installation Wizard, a local attacker could gain escalated privileges by inserting an executable into the path of the affected service or uninstall entry. Example vulnerable path:…

  • CVE-2021-35230MedOct 22, 2021
    risk 0.44cvss 6.7epss 0.00

    As a result of an unquoted service path vulnerability present in the Kiwi CatTools Installation Wizard, a local attacker could gain escalated privileges by inserting an executable into the path of the affected service or uninstall entry.

  • CVE-2020-27870MedFeb 10, 2021
    risk 0.43cvss 6.5epss 0.04

    This vulnerability allows remote attackers to disclose sensitive information on affected installations of SolarWinds Orion Platform 2020.2.1. Authentication is required to exploit this vulnerability. The specific flaw exists within ExportToPDF.aspx. The issue results from the…

  • CVE-2020-27994MedFeb 3, 2021
    risk 0.43cvss 6.5epss 0.04

    SolarWinds Serv-U before 15.2.2 allows Authenticated Directory Traversal.

  • CVE-2019-13181MedDec 16, 2019
    risk 0.43cvss 6.5epss 0.03

    A CSV injection vulnerability exists in the web UI of SolarWinds Serv-U FTP Server v15.1.7.

  • CVE-2023-40058MedDec 21, 2023
    risk 0.42cvss 6.5epss 0.01

    Sensitive data was added to our public-facing knowledgebase that, if exploited, could be used to access components of Access Rights Manager (ARM) if the threat actor is in the same environment.

  • CVE-2023-23839MedApr 25, 2023
    risk 0.42cvss 6.5epss 0.01

    The SolarWinds Platform was susceptible to the Exposure of Sensitive Information Vulnerability. This vulnerability allows users to access Orion.WebCommunityStrings SWIS schema object and obtain sensitive information.

  • CVE-2023-23838MedApr 25, 2023
    risk 0.42cvss 6.5epss 0.01

    Directory traversal and file enumeration vulnerability which allowed users to enumerate to different folders of the server.

  • CVE-2021-35226MedOct 10, 2022
    risk 0.42cvss 6.5epss 0.00

    An entity in Network Configuration Manager product is misconfigured and exposing password field to Solarwinds Information Service (SWIS). Exposed credentials are encrypted and require authenticated access with an NCM role.

  • CVE-2021-35240MedAug 31, 2021
    risk 0.42cvss 6.5epss 0.01

    A security researcher stored XSS via a Help Server setting. This affects customers using Internet Explorer, because they do not support 'rel=noopener'.

  • CVE-2019-16959MedDec 21, 2020
    risk 0.42cvss 6.5epss 0.02

    SolarWinds Web Help Desk 12.7.0 allows CSV Injection, also known as Formula Injection, via a file attached to a ticket.

  • CVE-2018-10241MedMay 16, 2018
    risk 0.42cvss 6.5epss 0.02

    A denial of service vulnerability in SolarWinds Serv-U before 15.1.6 HFv1 allows an authenticated user to crash the application (with a NULL pointer dereference) via a specially crafted URL beginning with the /Web%20Client/ substring.

  • CVE-2017-7646MedApr 10, 2017
    risk 0.42cvss 6.5epss 0.01

    SolarWinds Log & Event Manager (LEM) before 6.3.1 Hotfix 4 allows an authenticated user to browse the server's filesystem and read the contents of arbitrary files contained within.

  • CVE-2024-28990MedSep 12, 2024
    risk 0.41cvss 6.3epss 0.00

    SolarWinds Access Rights Manager (ARM) was found to contain a hard-coded credential authentication bypass vulnerability. If exploited, this vulnerability would allow access to the RabbitMQ management console. We thank Trend Micro Zero Day Initiative (ZDI) for its ongoing…

  • CVE-2021-35221MedAug 31, 2021
    risk 0.41cvss 6.3epss 0.02

    Improper Access Control Tampering Vulnerability using ImportAlert function which can lead to a Remote Code Execution (RCE) from the Alerts Settings page.

  • CVE-2018-25252MedApr 4, 2026
    risk 0.40cvss 6.2epss 0.00

    FTP Voyager 16.2.0 contains a denial of service vulnerability that allows local attackers to crash the application by injecting oversized buffer data into the site profile IP field. Attackers can create a malicious site profile containing 500 bytes of repeated characters and…

  • CVE-2026-28297MedMar 26, 2026
    risk 0.40cvss 6.1epss 0.00

    SolarWinds Observability Self-Hosted was found to be affected by a stored cross-site scripting vulnerability, which when exploited, can lead to unintended script execution.

  • CVE-2023-33231MedJul 18, 2023
    risk 0.40cvss 6.1epss 0.01

    XSS attack was possible in DPA 2023.2 due to insufficient input validation

  • CVE-2022-47509MedApr 21, 2023
    risk 0.40cvss 6.1epss 0.01

    The SolarWinds Platform was susceptible to the Incorrect Input Neutralization Vulnerability. This vulnerability allows a remote adversary with a valid SolarWinds Platform account to append URL parameters to inject HTML.

Page 4 of 7