VYPR

Vendor CVEs

SolarWinds

All CVEs

342 total · sorted by risk
  • CVE-2002-1209Nov 4, 2002
    risk 0.04cvss epss 0.13

    Directory traversal vulnerability in SolarWinds TFTP Server 5.0.55, and possibly earlier, allows remote attackers to read arbitrary files via "..\" (dot-dot backslash) sequences in a GET request.

  • CVE-2001-0054Feb 16, 2001
    risk 0.04cvss epss 0.12

    Directory traversal vulnerability in FTP Serv-U before 2.5i allows remote attackers to escape the FTP root and read arbitrary files by appending a string such as "/..%20." to a CD command, a variant of a .. (dot dot) attack.

  • CVE-2012-2602Aug 12, 2012
    risk 0.03cvss epss 0.06

    Multiple cross-site request forgery (CSRF) vulnerabilities in SolarWinds Orion Network Performance Monitor (NPM) before 10.3.1 allow remote attackers to hijack the authentication of administrators for requests that (1) create user accounts via CreateUserStepContainer actions to…

  • CVE-2015-7839Oct 15, 2015
    risk 0.01cvss epss 0.07

    SolarWinds Log and Event Manager (LEM) allows remote attackers to execute arbitrary commands on managed computers via a request to services/messagebroker/nonsecurestreamingamf involving the traceroute functionality.

  • CVE-2015-1501Feb 16, 2015
    risk 0.01cvss epss 0.07

    The factory.loadExtensionFactory function in TSUnicodeGraphEditorControl in SolarWinds Server and Application Monitor (SAM) allow remote attackers to execute arbitrary code via a UNC path to a crafted binary.

  • CVE-2015-1500Feb 16, 2015
    risk 0.01cvss epss 0.08

    Multiple stack-based buffer overflows in the TSUnicodeGraphEditorControl in SolarWinds Server and Application Monitor (SAM) allow remote attackers to execute arbitrary code via unspecified vectors to (1) graphManager.load or (2) factory.load.

  • CVE-2014-3459Aug 7, 2014
    risk 0.01cvss epss 0.12

    Heap-based buffer overflow in SolarWinds Network Configuration Manager (NCM) before 7.3 allows remote attackers to execute arbitrary code via the PEstrarg1 property.

  • CVE-2026-28323CriJul 30, 2026
    risk 0.00cvss 9.8epss 0.01

    SolarWinds Web Help Desk is found to be affected by a SAML authentication bypass vulnerability. This requires the SAML 2.0 authentication method to be enabled.

  • CVE-2026-28321CriJul 21, 2026
    risk 0.00cvss 9.1epss 0.00

    SolarWinds Serv-U is affected by a broken access control vulnerability that could allow arbitrary file read and write, which can then be used to escalate privileges and execute code as root. A domain administrator access is required, and the impact is lower in Windows…

  • CVE-2026-28317CriJul 21, 2026
    risk 0.00cvss 9.1epss 0.00

    SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation. This issue requires domain administrator access. The impact is lower in Windows deployments.

  • CVE-2026-28316CriJul 21, 2026
    risk 0.00cvss 9.1epss 0.01

    SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation to a system administrator with the ability to execute commands as the root user. This issue requires a domain account with administrator access. The…

  • CVE-2026-28315MedJul 21, 2026
    risk 0.00cvss 6.2epss 0.00

    SolarWinds Serv-U was found to be affected by a stored cross-site scripting vulnerability that could lead to session hijacking or information disclosure from an administrator account.

  • CVE-2026-28314CriJul 21, 2026
    risk 0.00cvss 9.1epss 0.00

    SolarWinds Serv-U is affected by an insecure direct object reference vulnerability that leads to an account takeover. User authentication is required. The impact is lower in Windows deployments.

  • CVE-2026-28313CriJul 21, 2026
    risk 0.00cvss 9.1epss 0.00

    SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to SMTP hijacking leading to arbitrary account takeover. The impact is lower in Windows deployments.

  • CVE-2026-28312CriJul 21, 2026
    risk 0.00cvss 9.1epss 0.00

    SolarWinds Serv-U is affected by a privilege escalation vulnerability. This would elevate a group’s access to system administrator and allow code execution as root. The impact is lower in Windows deployments.

  • CVE-2026-28310CriJul 21, 2026
    risk 0.00cvss 9.1epss 0.00

    SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to escalate their user type to that of a system administrator. The impact is lower in Windows deployments.

  • CVE-2026-28309CriJul 21, 2026
    risk 0.00cvss 9.1epss 0.00

    SolarWinds Serv-U is affected by a broken access control vulnerability that allows a domain administrator to create system administrator accounts. The impact is lower in Windows deployments.

  • CVE-2026-28308CriJul 21, 2026
    risk 0.00cvss 9.1epss 0.01

    SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution. Domain administrator access is required. The impact is lower in Windows deployments.

  • CVE-2026-28307CriJul 21, 2026
    risk 0.00cvss 9.1epss 0.00

    SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain user group to be elevated into an administrator group. The impact is lower in Windows deployments.

  • CVE-2026-28306CriJul 21, 2026
    risk 0.00cvss 9.1epss 0.00

    SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to elevate their privileges to a system administrator. The impact is lower in Windows deployments.

  • CVE-2026-28305CriJul 21, 2026
    risk 0.00cvss 9.1epss 0.01

    SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution as root. A domain account with admin privileges and read and write access to the home directory is required. The impact is lower in Windows…

  • CVE-2026-28304CriJul 21, 2026
    risk 0.00cvss 9.1epss 0.01

    SolarWinds Serv-U is affected by a remote code execution vulnerability that, when exploited, can allow the arbitrary execution of code remotely as root. The impact is lower in Windows deployments.

  • CVE-2026-28302CriJul 21, 2026
    risk 0.00cvss 9.1epss 0.01

    SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation and remote code execution as root. This issue requires group administrator access. The impact is lower in Windows deployments.

  • CVE-2026-28322MedJun 30, 2026
    risk 0.00cvss 5.6epss 0.00

    SolarWinds Database Performance Analyzer was found to be affected by a stored cross-site scripting vulnerability, which when exploited, can lead to unintended script execution.

  • CVE-2015-8220Nov 17, 2015
    risk 0.00cvss epss 0.05

    Stack-based buffer overflow in the URI handler in DWRCC.exe in SolarWinds DameWare Mini Remote Control before 12.0 HotFix 1 allows remote attackers to execute arbitrary code via a crafted commandline argument in a link.

  • CVE-2015-7840Oct 15, 2015
    risk 0.00cvss epss 0.04

    The command line management console (CMC) in SolarWinds Log and Event Manager (LEM) before 6.2.0 allows remote attackers to execute arbitrary code via unspecified vectors involving the ping feature.

  • CVE-2015-7838Oct 15, 2015
    risk 0.00cvss epss 0.05

    ProcessFileUpload.jsp in SolarWinds Storage Manager before 6.2 allows remote attackers to upload and execute arbitrary files via unspecified vectors.

  • CVE-2015-5610Jul 21, 2015
    risk 0.00cvss epss 0.02

    The RSM (aka RSMWinService) service in SolarWinds N-Able N-Central before 9.5.1.4514 uses the same password decryption key across different customers' installations, which makes it easier for remote authenticated users to obtain the cleartext domain-administrator password by…

  • CVE-2014-9566Mar 10, 2015
    risk 0.00cvss epss 0.48

    Multiple SQL injection vulnerabilities in the Manage Accounts page in the AccountManagement.asmx service in the Solarwinds Orion Platform 2015.1, as used in Network Performance Monitor (NPM) before 11.5, NetFlow Traffic Analyzer (NTA) before 4.1, Network Configuration Manager…

  • CVE-2014-5504Sep 4, 2014
    risk 0.00cvss epss 0.05

    SolarWinds Log and Event Manager before 6.0 uses "static" credentials, which makes it easier for remote attackers to obtain access to the database and execute arbitrary code via unspecified vectors, related to HyperSQL.

  • CVE-2014-2509Jul 1, 2014
    risk 0.00cvss epss 0.02

    Session fixation vulnerability in the Report Advisor (RA) component in EMC Network Configuration Manager (NCM) before 9.3 allows remote attackers to hijack web sessions via a session cookie.

  • CVE-2013-3249Mar 20, 2014
    risk 0.00cvss epss 0.06

    Stack-based buffer overflow in the "Add from text file" feature in the DameWare Exporter tool (DWExporter.exe) in DameWare Remote Support 10.0.0.372, 9.0.1.247, and earlier allows user-assisted attackers to execute arbitrary code via unspecified vectors.

  • CVE-2010-4828Aug 24, 2011
    risk 0.00cvss epss 0.05

    Multiple cross-site scripting (XSS) vulnerabilities in SolarWinds Orion Network Performance Monitor (NPM) 10.1 allow remote attackers to inject arbitrary web script or HTML via the (1) Title parameter to MapView.aspx; NetObject parameter to (2) NodeDetails.aspx and (3)…

  • CVE-2009-4815Apr 27, 2010
    risk 0.00cvss epss 0.03

    Directory traversal vulnerability in Serv-U before 9.2.0.1 allows remote authenticated users to read arbitrary files via unspecified vectors.

  • CVE-2009-3655Oct 9, 2009
    risk 0.00cvss epss 0.04

    Rhino Software Serv-U 7.0.0.1 through 8.2.0.3 allows remote attackers to cause a denial of service (server crash) via unspecified vectors related to the "SITE SET TRANSFERPROGRESS ON" FTP command.

  • CVE-2008-3731Aug 20, 2008
    risk 0.00cvss epss 0.02

    Unspecified vulnerability in Serv-U File Server 7.0.0.1, and other versions before 7.2.0.1, allows remote authenticated users to cause a denial of service (daemon crash) via an SSH session with SFTP commands for directory creation and logging.

  • CVE-2006-1951Apr 24, 2006
    risk 0.00cvss epss 0.04

    Directory traversal vulnerability in SolarWinds TFTP Server 8.1 and earlier allows remote attackers to download arbitrary files via a crafted GET request including "....//" sequences, which are collapsed into "../" sequences by filtering.

  • CVE-2005-3467Nov 2, 2005
    risk 0.00cvss epss 0.02

    Serv-U FTP Server before 6.1.0.4 allows attackers to cause a denial of service (crash) via (1) malformed packets and possibly other unspecified issues with unknown impact and attack vectors including (2) use of "~" in a pathname, and (3) memory consumption of the daemon. NOTE:…

  • CVE-2004-2533Dec 31, 2004
    risk 0.00cvss epss 0.03

    Serv-U FTP Server 4.1 (possibly 4.0) allows remote attackers to cause a denial of service (application crash) via a SITE CHMOD command with a "\\...\" followed by a short string, causing partial memory corruption, a different vulnerability than CVE-2004-2111.

  • CVE-2004-1852Mar 23, 2004
    risk 0.00cvss epss 0.01

    DameWare Mini Remote Control 3.x before 3.74 and 4.x before 4.2 transmits the Blowfish encryption key in plaintext, which allows remote attackers to gain sensitive information.

  • CVE-2002-2393Dec 31, 2002
    risk 0.00cvss epss 0.03

    Serv-U FTP server 3.0, 3.1 and 4.0.0.4 does not accept new connections while validating user folder access rights, which allows remote attackers to cause a denial of service (no new connections) via a series of MKD commands.

  • CVE-2001-1463Nov 19, 2001
    risk 0.00cvss epss 0.03

    The remote administration client for RhinoSoft Serv-U 3.0 sends the user password in plaintext even when S/KEY One-Time Password (OTP) authentication is enabled, which allows remote attackers to sniff passwords.

Page 7 of 7