Skip to main content

Vendor archive

solarwinds CVEs

Beta · best-effort

319 CVEs tagged to vendor solarwinds57 Critical, 130 High, 127 Medium, 5 Low, 0 Unrated.

CVE-2021-35234

Published Dec 20, 2021

Numerous exposed dangerous functions within Orion Core has allows for read-only SQL injection leading to privileged escalation. An attacker with low-user privileges may steal pass…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2021-35237

Published Oct 29, 2021

A missing HTTP header (X-Frame-Options) in Kiwi Syslog Server has left customers vulnerable to click jacking. Clickjacking is an attack that occurs when an attacker uses a transpa…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-35236

Published Oct 27, 2021

The Secure flag is not set in the SSL Cookie of Kiwi Syslog Server 9.7.2 and previous versions. The Secure attribute tells the browser to only send the cookie if the request is be…

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2021-35235

Published Oct 27, 2021

The ASP.NET debug feature is enabled by default in Kiwi Syslog Server 9.7.2 and previous versions. ASP.NET allows remote debugging of web applications, if configured to do so. Deb…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-35233

Published Oct 27, 2021

The HTTP TRACK & TRACE methods were enabled in Kiwi Syslog Server 9.7.1 and earlier. These methods are intended for diagnostic purposes only. If enabled, the web server will respo…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-35231

Published Oct 25, 2021

As a result of an unquoted service path vulnerability present in the Kiwi Syslog Server Installation Wizard, a local attacker could gain escalated privileges by inserting an execu…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-35230

Published Oct 22, 2021

As a result of an unquoted service path vulnerability present in the Kiwi CatTools Installation Wizard, a local attacker could gain escalated privileges by inserting an executable…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-35228

Published Oct 21, 2021

This vulnerability occurred due to missing input sanitization for one of the output fields that is extracted from headers on specific section of page causing a reflective cross si…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-35225

Published Oct 21, 2021

Each authenticated Orion Platform user in a MSP (Managed Service Provider) environment can view and browse all NetPath Services from all that MSP's customers. This can lead to any…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-35214

Published Oct 12, 2021

The vulnerability in SolarWinds Pingdom can be described as a failure to invalidate user session upon password or email address change. When running multiple active sessions in se…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-35217

Published Sep 8, 2021

Insecure Deseralization of untrusted data remote code execution vulnerability was discovered in Patch Manager Orion Platform Integration module and reported to us by ZDI. An Authe…

CVSS 8.9 · High
Vendor/product tagsBeta · best-effort

CVE-2021-35218

Published Sep 1, 2021

Deserialization of Untrusted Data in the Web Console Chart Endpoint can lead to remote code execution. An unauthorized attacker who has network access to the Orion Patch Manager W…

CVSS 8.9 · High
Vendor/product tagsBeta · best-effort

CVE-2021-35216

Published Sep 1, 2021

Insecure Deserialization of untrusted data remote code execution vulnerability was discovered in Patch Manager Orion Platform Integration module. An Authenticated Attacker with ne…

CVSS 8.9 · High
Vendor/product tagsBeta · best-effort

CVE-2021-35215

Published Sep 1, 2021

Insecure deserialization leading to Remote Code Execution was detected in the Orion Platform version 2020.2.5. Authentication is required to exploit this vulnerability.

CVSS 8.9 · High
Vendor/product tagsBeta · best-effort

CVE-2021-35238

Published Sep 1, 2021

User with Orion Platform Admin Rights could store XSS through URL POST parameter in CreateExternalWebsite website.

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-35212

Published Aug 31, 2021

An SQL injection Privilege Escalation Vulnerability was discovered in the Orion Platform reported by the ZDI Team. A blind Boolean SQL injection which could lead to full read/writ…

CVSS 8.9 · High
Vendor/product tagsBeta · best-effort

CVE-2021-35223

Published Aug 31, 2021

The Serv-U File Server allows for events such as user login failures to be audited by executing a command. This command can be supplied with parameters that can take the form of u…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort
Showing 151-175 of 319 CVEsPage 7 of 13