Skip to main content

Vendor archive

solarwinds CVEs

Beta · best-effort

319 CVEs tagged to vendor solarwinds57 Critical, 130 High, 127 Medium, 5 Low, 0 Unrated.

CVE-2020-15574

Published Jul 7, 2020

SolarWinds Serv-U File Server before 15.2.1 mishandles the Same-Site cookie attribute, aka Case Number 00331893.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-15573

Published Jul 7, 2020

SolarWinds Serv-U File Server before 15.2.1 has a "Cross-script vulnerability," aka Case Numbers 00041778 and 00306421.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-13912

Published Jun 7, 2020

SolarWinds Advanced Monitoring Agent before 10.8.9 allows local users to gain privileges via a Trojan horse .exe file, because everyone can write to a certain .exe file.

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2019-20002

Published Apr 27, 2020

Formula Injection exists in the export feature in SolarWinds WebHelpDesk 12.7.1 via a value (provided by a low-privileged user in the Subject field of a help request form) that is…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-5734

Published Apr 7, 2020

Classic buffer overflow in SolarWinds Dameware allows a remote, unauthenticated attacker to cause a denial of service by sending a large 'SigPubkeyLen' during ECDH key exchange.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-12769

Published Mar 18, 2020

SolarWinds Serv-U Managed File Transfer (MFT) Web client before 15.1.6 Hotfix 2 is vulnerable to Cross-Site Request Forgery in the file upload functionality via ?Command=Upload wi…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-7984

Published Jan 26, 2020

SolarWinds N-central before 12.1 SP1 HF5 and 12.2 before SP1 HF2 allows remote attackers to retrieve cleartext domain admin credentials from the Agent & Probe settings, and obtain…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-17127

Published Jan 17, 2020

A Stored Client Side Template Injection (CSTI) with Angular was discovered in the SolarWinds Orion Platform 2019.2 HF1 in many application forms. An attacker can inject an Angular…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-17125

Published Jan 17, 2020

A Reflected Client Side Template Injection (CSTI) with Angular was discovered in the SolarWinds Orion Platform 2019.2 HF1 in many forms. An attacker can inject an Angular expressi…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-19829

Published Dec 18, 2019

A cross-site scripting (XSS) vulnerability exists in SolarWinds Serv-U FTP Server 15.1.7 in the email parameter, a different vulnerability than CVE-2018-19934 and CVE-2019-13182.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-3980

Published Oct 8, 2019

The Solarwinds Dameware Mini Remote Client agent v12.1.0.89 supports smart card authentication which can allow a user to upload an executable to be executed on the DWRCS.exe host.…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-19386

Published Aug 14, 2019

SolarWinds Database Performance Analyzer 11.1.457 contains an instance of Reflected XSS in its idcStateError component, where the page parameter is reflected into the HREF of the…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 226-250 of 319 CVEsPage 10 of 13