Vendor CVEs
SolarWinds
All CVEs
342 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-38114 | Med | 0.40 | 6.1 | 0.01 | Nov 23, 2022 | This vulnerability occurs when a web server fails to correctly process the Content-Length of POST requests. This can lead to HTTP request smuggling or XSS. | ||
| CVE-2022-36965 | Med | 0.40 | 6.1 | 0.01 | Sep 30, 2022 | Insufficient sanitization of inputs in QoE application input field could lead to stored and Dom based XSS attack. This issue is fixed and released in SolarWinds Platform (2022.3.0). | ||
| CVE-2021-35247 | Med | 0.40 | 4.3 | 0.03 | KEV | Jan 10, 2022 | Serv-U web login screen to LDAP authentication was allowing characters that were not sufficiently sanitized. SolarWinds has updated the input mechanism to perform additional validation and sanitization. Please Note: No downstream affect has been detected as the LDAP servers… | |
| CVE-2021-25179 | Med | 0.40 | 6.1 | 0.01 | May 5, 2021 | SolarWinds Serv-U before 15.2 is affected by Cross Site Scripting (XSS) via the HTTP Host header. | ||
| CVE-2020-15575 | Med | 0.40 | 6.1 | 0.02 | Jul 7, 2020 | SolarWinds Serv-U File Server before 15.2.1 allows XSS as demonstrated by Tenable Scan, aka Case Number 00484194. | ||
| CVE-2020-15573 | Med | 0.40 | 6.1 | 0.02 | Jul 7, 2020 | SolarWinds Serv-U File Server before 15.2.1 has a "Cross-script vulnerability," aka Case Numbers 00041778 and 00306421. | ||
| CVE-2019-17127 | Med | 0.40 | 6.1 | 0.02 | Jan 17, 2020 | A Stored Client Side Template Injection (CSTI) with Angular was discovered in the SolarWinds Orion Platform 2019.2 HF1 in many application forms. An attacker can inject an Angular expression and escape the Angular sandbox to achieve stored XSS. This can lead to privilege… | ||
| CVE-2019-17125 | Med | 0.40 | 6.1 | 0.02 | Jan 17, 2020 | A Reflected Client Side Template Injection (CSTI) with Angular was discovered in the SolarWinds Orion Platform 2019.2 HF1 in many forms. An attacker can inject an Angular expression and escape the Angular sandbox to achieve stored XSS. | ||
| CVE-2018-19386 | Med | 0.40 | 6.1 | 0.09 | Aug 14, 2019 | SolarWinds Database Performance Analyzer 11.1.457 contains an instance of Reflected XSS in its idcStateError component, where the page parameter is reflected into the HREF of the 'Try Again' Button on the page, aka a /iwc/idcStateError.iwc?page= URI. | ||
| CVE-2021-35219 | Med | 0.39 | 6.0 | 0.01 | Aug 31, 2021 | ExportToPdfCmd Arbitrary File Read Information Disclosure Vulnerability using ImportAlert function within the Alerts Settings page. | ||
| CVE-2026-28298 | Med | 0.38 | 5.9 | 0.00 | Mar 26, 2026 | SolarWinds Observability Self-Hosted was found to be affected by a stored cross-site scripting vulnerability, which when exploited, can lead to unintended script execution. | ||
| CVE-2024-28072 | Med | 0.37 | 5.7 | 0.01 | May 3, 2024 | A highly privileged account can overwrite arbitrary files on the system with log output. The log file path tags were not sanitized properly. | ||
| CVE-2025-26398 | Med | 0.36 | 5.6 | 0.00 | Aug 12, 2025 | SolarWinds Database Performance Analyzer was found to contain a hard-coded cryptographic key. If exploited, this vulnerability could lead to a machine-in-the-middle (MITM) attack against users. This vulnerability requires additional software not installed by default, local… | ||
| CVE-2024-28989 | Med | 0.36 | 5.5 | 0.00 | Feb 11, 2025 | SolarWinds Web Help Desk was found to have a hardcoded cryptographic key that could allow the disclosure of sensitive information from the software. | ||
| CVE-2022-47512 | Med | 0.36 | 5.5 | 0.00 | Dec 19, 2022 | Sensitive information was stored in plain text in a file that is accessible by a user with a local account in Hybrid Cloud Observability (HCO)/ SolarWinds Platform 2022.4. No other versions are affected | ||
| CVE-2021-35228 | Med | 0.36 | 5.5 | 0.01 | Oct 21, 2021 | This vulnerability occurred due to missing input sanitization for one of the output fields that is extracted from headers on specific section of page causing a reflective cross site scripting attack. An attacker would need to perform a Man in the Middle attack in order to change… | ||
| CVE-2019-12864 | Med | 0.36 | 5.5 | 0.00 | May 4, 2020 | SolarWinds Orion Platform 2018.4 HF3 (NPM 12.4, NetPath 1.1.4) is vulnerable to Information Leakage, because of improper error handling with stack traces, as demonstrated by discovering a full pathname upon a 500 Internal Server Error via the… | ||
| CVE-2019-13182 | Med | 0.36 | 5.4 | 0.06 | Dec 16, 2019 | A stored cross-site scripting (XSS) vulnerability exists in the web UI of SolarWinds Serv-U FTP Server 15.1.7. | ||
| CVE-2025-26391 | Med | 0.35 | 5.4 | 0.00 | Nov 18, 2025 | SolarWinds Observability Self-Hosted XSS Vulnerability. The SolarWinds Platform was susceptible to a XSS vulnerability that affects user-created URL fields. This vulnerability requires authentication from a low-level account. | ||
| CVE-2025-26392 | Med | 0.35 | 5.4 | 0.00 | Oct 21, 2025 | SolarWinds Observability Self-Hosted is susceptible to SQL injection vulnerability that may display sensitive data using a low-level account. This vulnerability requires authentication from a low-privilege account. | ||
| CVE-2025-26393 | Med | 0.35 | 5.4 | 0.00 | Mar 17, 2025 | SolarWinds Service Desk is affected by a broken access control vulnerability. The issue allows authenticated users to escalate privileges, leading to unauthorized data manipulation. | ||
| CVE-2022-38110 | Med | 0.35 | 5.4 | 0.00 | Jan 20, 2023 | In Database Performance Analyzer (DPA) 2022.4 and older releases, certain URL vectors are susceptible to authenticated reflected cross-site scripting. | ||
| CVE-2022-38106 | Med | 0.35 | 5.4 | 0.01 | Dec 16, 2022 | This vulnerability happens in the web client versions 15.3.0 to Serv-U 15.3.1. This vulnerability affects the directory creation function. | ||
| CVE-2022-38115 | Med | 0.35 | 5.3 | 0.01 | Nov 23, 2022 | Insecure method vulnerability in which allowed HTTP methods are disclosed. E.g., OPTIONS, DELETE, TRACE, and PUT | ||
| CVE-2022-38113 | Med | 0.35 | 5.3 | 0.01 | Nov 23, 2022 | This vulnerability discloses build and services versions in the server response header. | ||
| CVE-2022-36966 | Med | 0.35 | 5.4 | 0.00 | Oct 20, 2022 | Users with Node Management rights were able to view and edit all nodes due to Insufficient control on URL parameter causing insecure direct object reference (IDOR) vulnerability in SolarWinds Platform 2022.3 and previous. | ||
| CVE-2021-35251 | Med | 0.35 | 5.3 | 0.01 | Mar 10, 2022 | Sensitive information could be displayed when a detailed technical error message is posted. This information could disclose environmental details about the Web Help Desk installation. | ||
| CVE-2021-35243 | Med | 0.35 | 5.3 | 0.01 | Dec 23, 2021 | The HTTP PUT and DELETE methods were enabled in the Web Help Desk web server (12.7.7 and earlier), allowing users to execute dangerous HTTP requests. The HTTP PUT method is normally used to upload data that is saved on the server with a user-supplied URL. While the DELETE method… | ||
| CVE-2021-35235 | Med | 0.35 | 5.3 | 0.01 | Oct 27, 2021 | The ASP.NET debug feature is enabled by default in Kiwi Syslog Server 9.7.2 and previous versions. ASP.NET allows remote debugging of web applications, if configured to do so. Debug mode causes ASP.NET to compile applications with extra information. The information enables a… | ||
| CVE-2021-35233 | Med | 0.35 | 5.3 | 0.01 | Oct 27, 2021 | The HTTP TRACK & TRACE methods were enabled in Kiwi Syslog Server 9.7.1 and earlier. These methods are intended for diagnostic purposes only. If enabled, the web server will respond to requests that use these methods by returning exact HTTP request that was received in the… | ||
| CVE-2021-32076 | Med | 0.35 | 5.3 | 0.01 | Aug 26, 2021 | Access Restriction Bypass via referrer spoof was discovered in SolarWinds Web Help Desk 12.7.2. An attacker can access the 'Web Help Desk Getting Started Wizard', especially the admin account creation page, from a non-privileged IP address network range or loopback address by… | ||
| CVE-2021-28674 | Med | 0.35 | 5.4 | 0.01 | Jul 30, 2021 | The node management page in SolarWinds Orion Platform before 2020.2.5 HF1 allows an attacker to create or delete a node (outside of the attacker's perimeter) via an account with write permissions. This occurs because node IDs are predictable (with incrementing numbers) and the… | ||
| CVE-2021-32604 | Med | 0.35 | 5.4 | 0.02 | May 11, 2021 | Share/IncomingWizard.htm in SolarWinds Serv-U before 15.2.3 mishandles the user-supplied SenderEmail parameter, aka "Share URL XSS." | ||
| CVE-2020-35482 | Med | 0.35 | 5.4 | 0.02 | Feb 3, 2021 | SolarWinds Serv-U before 15.2.2 allows authenticated reflected XSS. | ||
| CVE-2020-28001 | Med | 0.35 | 5.4 | 0.04 | Feb 3, 2021 | SolarWinds Serv-U before 15.2.2 allows Authenticated Stored XSS. | ||
| CVE-2019-16961 | Med | 0.35 | 5.4 | 0.01 | Jan 15, 2021 | SolarWinds Web Help Desk 12.7.0 allows XSS via a Schedule Name. | ||
| CVE-2019-16954 | Med | 0.35 | 5.4 | 0.01 | Jan 6, 2021 | SolarWinds Web Help Desk 12.7.0 allows HTML injection via a Comment in a Help Request ticket. | ||
| CVE-2019-16960 | Med | 0.35 | 5.4 | 0.01 | Jan 4, 2021 | SolarWinds Web Help Desk 12.7.0 allows XSS via a CSV template file with a crafted Location Name field. | ||
| CVE-2019-16956 | Med | 0.35 | 5.4 | 0.02 | Jan 4, 2021 | SolarWinds Web Help Desk 12.7.0 allows XSS via the Request Type parameter of a ticket. | ||
| CVE-2019-16957 | Med | 0.35 | 5.4 | 0.01 | Dec 18, 2020 | SolarWinds Web Help Desk 12.7.0 allows XSS via the First Name field of a User Account. | ||
| CVE-2019-16955 | Med | 0.35 | 5.4 | 0.02 | Dec 18, 2020 | SolarWinds Web Help Desk 12.7.0 allows XSS via an uploaded SVG document in a request. | ||
| CVE-2018-16243 | Med | 0.35 | 5.4 | 0.01 | Dec 15, 2020 | SolarWinds Database Performance Analyzer (DPA) 11.1.468 and 12.0.3074 have several persistent XSS vulnerabilities, related to logViewer.iwc, centralManage.cen, userAdministration.iwc, database.iwc, alertManagement.iwc, eventAnnotations.iwc, and central.cen. | ||
| CVE-2019-16958 | Med | 0.35 | 5.4 | 0.01 | Dec 1, 2020 | Cross-site Scripting (XSS) vulnerability in SolarWinds Web Help Desk 12.7.0 allows attacker to inject arbitrary web script or HTML via Location Name. | ||
| CVE-2020-14007 | Med | 0.35 | 5.4 | 0.01 | Jun 24, 2020 | Solarwinds Orion (with Web Console WPM 2019.4.1, and Orion Platform HF4 or NPM HF2 2019.4) allows XSS via a name of an alert definition. | ||
| CVE-2020-14006 | Med | 0.35 | 5.4 | 0.01 | Jun 24, 2020 | Solarwinds Orion (with Web Console WPM 2019.4.1, and Orion Platform HF4 or NPM HF2 2019.4) allows XSS via a Responsible Team. | ||
| CVE-2019-12954 | Med | 0.35 | 5.4 | 0.01 | Feb 17, 2020 | SolarWinds Network Performance Monitor (Orion Platform 2018, NPM 12.3, NetPath 1.1.3) allows XSS by authenticated users via a crafted onerror attribute of a VIDEO element in an action for an ALERT. | ||
| CVE-2019-19829 | Med | 0.35 | 5.4 | 0.02 | Dec 18, 2019 | A cross-site scripting (XSS) vulnerability exists in SolarWinds Serv-U FTP Server 15.1.7 in the email parameter, a different vulnerability than CVE-2018-19934 and CVE-2019-13182. | ||
| CVE-2025-26400 | Med | 0.34 | 5.3 | 0.00 | Jul 29, 2025 | SolarWinds Web Help Desk was reported to be affected by an XML External Entity Injection (XXE) vulnerability that could lead to information disclosure. A valid, low-privilege access is required unless the attacker had access to the local server to modify configuration files. | ||
| CVE-2024-45709 | Med | 0.34 | 5.3 | 0.01 | Dec 10, 2024 | SolarWinds Web Help Desk was susceptible to a local file read vulnerability. This vulnerability requires the software be installed on Linux and configured to use non-default development/test mode making exposure to the vulnerability very limited. | ||
| CVE-2021-35246 | Med | 0.34 | 5.3 | 0.00 | Nov 23, 2022 | The application fails to prevent users from connecting to it over unencrypted connections. An attacker able to modify a legitimate user's network traffic could bypass the application's use of SSL/TLS encryption and use the application as a platform for attacks against its users. |
- risk 0.40cvss 6.1epss 0.01
This vulnerability occurs when a web server fails to correctly process the Content-Length of POST requests. This can lead to HTTP request smuggling or XSS.
- risk 0.40cvss 6.1epss 0.01
Insufficient sanitization of inputs in QoE application input field could lead to stored and Dom based XSS attack. This issue is fixed and released in SolarWinds Platform (2022.3.0).
- risk 0.40cvss 4.3epss 0.03
Serv-U web login screen to LDAP authentication was allowing characters that were not sufficiently sanitized. SolarWinds has updated the input mechanism to perform additional validation and sanitization. Please Note: No downstream affect has been detected as the LDAP servers…
- risk 0.40cvss 6.1epss 0.01
SolarWinds Serv-U before 15.2 is affected by Cross Site Scripting (XSS) via the HTTP Host header.
- risk 0.40cvss 6.1epss 0.02
SolarWinds Serv-U File Server before 15.2.1 allows XSS as demonstrated by Tenable Scan, aka Case Number 00484194.
- risk 0.40cvss 6.1epss 0.02
SolarWinds Serv-U File Server before 15.2.1 has a "Cross-script vulnerability," aka Case Numbers 00041778 and 00306421.
- risk 0.40cvss 6.1epss 0.02
A Stored Client Side Template Injection (CSTI) with Angular was discovered in the SolarWinds Orion Platform 2019.2 HF1 in many application forms. An attacker can inject an Angular expression and escape the Angular sandbox to achieve stored XSS. This can lead to privilege…
- risk 0.40cvss 6.1epss 0.02
A Reflected Client Side Template Injection (CSTI) with Angular was discovered in the SolarWinds Orion Platform 2019.2 HF1 in many forms. An attacker can inject an Angular expression and escape the Angular sandbox to achieve stored XSS.
- risk 0.40cvss 6.1epss 0.09
SolarWinds Database Performance Analyzer 11.1.457 contains an instance of Reflected XSS in its idcStateError component, where the page parameter is reflected into the HREF of the 'Try Again' Button on the page, aka a /iwc/idcStateError.iwc?page= URI.
- risk 0.39cvss 6.0epss 0.01
ExportToPdfCmd Arbitrary File Read Information Disclosure Vulnerability using ImportAlert function within the Alerts Settings page.
- risk 0.38cvss 5.9epss 0.00
SolarWinds Observability Self-Hosted was found to be affected by a stored cross-site scripting vulnerability, which when exploited, can lead to unintended script execution.
- risk 0.37cvss 5.7epss 0.01
A highly privileged account can overwrite arbitrary files on the system with log output. The log file path tags were not sanitized properly.
- risk 0.36cvss 5.6epss 0.00
SolarWinds Database Performance Analyzer was found to contain a hard-coded cryptographic key. If exploited, this vulnerability could lead to a machine-in-the-middle (MITM) attack against users. This vulnerability requires additional software not installed by default, local…
- risk 0.36cvss 5.5epss 0.00
SolarWinds Web Help Desk was found to have a hardcoded cryptographic key that could allow the disclosure of sensitive information from the software.
- risk 0.36cvss 5.5epss 0.00
Sensitive information was stored in plain text in a file that is accessible by a user with a local account in Hybrid Cloud Observability (HCO)/ SolarWinds Platform 2022.4. No other versions are affected
- risk 0.36cvss 5.5epss 0.01
This vulnerability occurred due to missing input sanitization for one of the output fields that is extracted from headers on specific section of page causing a reflective cross site scripting attack. An attacker would need to perform a Man in the Middle attack in order to change…
- risk 0.36cvss 5.5epss 0.00
SolarWinds Orion Platform 2018.4 HF3 (NPM 12.4, NetPath 1.1.4) is vulnerable to Information Leakage, because of improper error handling with stack traces, as demonstrated by discovering a full pathname upon a 500 Internal Server Error via the…
- risk 0.36cvss 5.4epss 0.06
A stored cross-site scripting (XSS) vulnerability exists in the web UI of SolarWinds Serv-U FTP Server 15.1.7.
- risk 0.35cvss 5.4epss 0.00
SolarWinds Observability Self-Hosted XSS Vulnerability. The SolarWinds Platform was susceptible to a XSS vulnerability that affects user-created URL fields. This vulnerability requires authentication from a low-level account.
- risk 0.35cvss 5.4epss 0.00
SolarWinds Observability Self-Hosted is susceptible to SQL injection vulnerability that may display sensitive data using a low-level account. This vulnerability requires authentication from a low-privilege account.
- risk 0.35cvss 5.4epss 0.00
SolarWinds Service Desk is affected by a broken access control vulnerability. The issue allows authenticated users to escalate privileges, leading to unauthorized data manipulation.
- risk 0.35cvss 5.4epss 0.00
In Database Performance Analyzer (DPA) 2022.4 and older releases, certain URL vectors are susceptible to authenticated reflected cross-site scripting.
- risk 0.35cvss 5.4epss 0.01
This vulnerability happens in the web client versions 15.3.0 to Serv-U 15.3.1. This vulnerability affects the directory creation function.
- risk 0.35cvss 5.3epss 0.01
Insecure method vulnerability in which allowed HTTP methods are disclosed. E.g., OPTIONS, DELETE, TRACE, and PUT
- risk 0.35cvss 5.3epss 0.01
This vulnerability discloses build and services versions in the server response header.
- risk 0.35cvss 5.4epss 0.00
Users with Node Management rights were able to view and edit all nodes due to Insufficient control on URL parameter causing insecure direct object reference (IDOR) vulnerability in SolarWinds Platform 2022.3 and previous.
- risk 0.35cvss 5.3epss 0.01
Sensitive information could be displayed when a detailed technical error message is posted. This information could disclose environmental details about the Web Help Desk installation.
- risk 0.35cvss 5.3epss 0.01
The HTTP PUT and DELETE methods were enabled in the Web Help Desk web server (12.7.7 and earlier), allowing users to execute dangerous HTTP requests. The HTTP PUT method is normally used to upload data that is saved on the server with a user-supplied URL. While the DELETE method…
- risk 0.35cvss 5.3epss 0.01
The ASP.NET debug feature is enabled by default in Kiwi Syslog Server 9.7.2 and previous versions. ASP.NET allows remote debugging of web applications, if configured to do so. Debug mode causes ASP.NET to compile applications with extra information. The information enables a…
- risk 0.35cvss 5.3epss 0.01
The HTTP TRACK & TRACE methods were enabled in Kiwi Syslog Server 9.7.1 and earlier. These methods are intended for diagnostic purposes only. If enabled, the web server will respond to requests that use these methods by returning exact HTTP request that was received in the…
- risk 0.35cvss 5.3epss 0.01
Access Restriction Bypass via referrer spoof was discovered in SolarWinds Web Help Desk 12.7.2. An attacker can access the 'Web Help Desk Getting Started Wizard', especially the admin account creation page, from a non-privileged IP address network range or loopback address by…
- risk 0.35cvss 5.4epss 0.01
The node management page in SolarWinds Orion Platform before 2020.2.5 HF1 allows an attacker to create or delete a node (outside of the attacker's perimeter) via an account with write permissions. This occurs because node IDs are predictable (with incrementing numbers) and the…
- risk 0.35cvss 5.4epss 0.02
Share/IncomingWizard.htm in SolarWinds Serv-U before 15.2.3 mishandles the user-supplied SenderEmail parameter, aka "Share URL XSS."
- risk 0.35cvss 5.4epss 0.02
SolarWinds Serv-U before 15.2.2 allows authenticated reflected XSS.
- risk 0.35cvss 5.4epss 0.04
SolarWinds Serv-U before 15.2.2 allows Authenticated Stored XSS.
- risk 0.35cvss 5.4epss 0.01
SolarWinds Web Help Desk 12.7.0 allows XSS via a Schedule Name.
- risk 0.35cvss 5.4epss 0.01
SolarWinds Web Help Desk 12.7.0 allows HTML injection via a Comment in a Help Request ticket.
- risk 0.35cvss 5.4epss 0.01
SolarWinds Web Help Desk 12.7.0 allows XSS via a CSV template file with a crafted Location Name field.
- risk 0.35cvss 5.4epss 0.02
SolarWinds Web Help Desk 12.7.0 allows XSS via the Request Type parameter of a ticket.
- risk 0.35cvss 5.4epss 0.01
SolarWinds Web Help Desk 12.7.0 allows XSS via the First Name field of a User Account.
- risk 0.35cvss 5.4epss 0.02
SolarWinds Web Help Desk 12.7.0 allows XSS via an uploaded SVG document in a request.
- risk 0.35cvss 5.4epss 0.01
SolarWinds Database Performance Analyzer (DPA) 11.1.468 and 12.0.3074 have several persistent XSS vulnerabilities, related to logViewer.iwc, centralManage.cen, userAdministration.iwc, database.iwc, alertManagement.iwc, eventAnnotations.iwc, and central.cen.
- risk 0.35cvss 5.4epss 0.01
Cross-site Scripting (XSS) vulnerability in SolarWinds Web Help Desk 12.7.0 allows attacker to inject arbitrary web script or HTML via Location Name.
- risk 0.35cvss 5.4epss 0.01
Solarwinds Orion (with Web Console WPM 2019.4.1, and Orion Platform HF4 or NPM HF2 2019.4) allows XSS via a name of an alert definition.
- risk 0.35cvss 5.4epss 0.01
Solarwinds Orion (with Web Console WPM 2019.4.1, and Orion Platform HF4 or NPM HF2 2019.4) allows XSS via a Responsible Team.
- risk 0.35cvss 5.4epss 0.01
SolarWinds Network Performance Monitor (Orion Platform 2018, NPM 12.3, NetPath 1.1.3) allows XSS by authenticated users via a crafted onerror attribute of a VIDEO element in an action for an ALERT.
- risk 0.35cvss 5.4epss 0.02
A cross-site scripting (XSS) vulnerability exists in SolarWinds Serv-U FTP Server 15.1.7 in the email parameter, a different vulnerability than CVE-2018-19934 and CVE-2019-13182.
- risk 0.34cvss 5.3epss 0.00
SolarWinds Web Help Desk was reported to be affected by an XML External Entity Injection (XXE) vulnerability that could lead to information disclosure. A valid, low-privilege access is required unless the attacker had access to the local server to modify configuration files.
- risk 0.34cvss 5.3epss 0.01
SolarWinds Web Help Desk was susceptible to a local file read vulnerability. This vulnerability requires the software be installed on Linux and configured to use non-default development/test mode making exposure to the vulnerability very limited.
- risk 0.34cvss 5.3epss 0.00
The application fails to prevent users from connecting to it over unencrypted connections. An attacker able to modify a legitimate user's network traffic could bypass the application's use of SSL/TLS encryption and use the application as a platform for attacks against its users.
Page 5 of 7