Skip to main content

Vendor archive

solarwinds CVEs

Beta · best-effort

319 CVEs tagged to vendor solarwinds57 Critical, 130 High, 127 Medium, 5 Low, 0 Unrated.

CVE-2020-35481

Published Feb 3, 2021

SolarWinds Serv-U before 15.2.2 allows Unauthenticated Macro Injection.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-10148

Published Dec 29, 2020

The SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands. This vulnerability could allow a remote attacker to…

CVSS 9.8 · Critical
evidence mentions
8
Buzz score
60.0
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2019-16959

Published Dec 21, 2020

SolarWinds Web Help Desk 12.7.0 allows CSV Injection, also known as Formula Injection, via a file attached to a ticket.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-25622

Published Dec 16, 2020

An issue was discovered in SolarWinds N-Central 12.3.0.670. The AdvancedScripts HTTP endpoint allows CSRF.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-25621

Published Dec 16, 2020

An issue was discovered in SolarWinds N-Central 12.3.0.670. The local database does not require authentication: security is only based on ability to access a network interface. Th…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2020-25619

Published Dec 16, 2020

An issue was discovered in SolarWinds N-Central 12.3.0.670. The SSH component does not restrict the Communication Channel to Intended Endpoints. An attacker can leverage an SSH fe…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-25618

Published Dec 16, 2020

An issue was discovered in SolarWinds N-Central 12.3.0.670. The sudo configuration has incorrect access control because the nable web user account is effectively able to run arbit…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-25617

Published Dec 16, 2020

An issue was discovered in SolarWinds N-Central 12.3.0.670. The AdvancedScripts HTTP endpoint allows Relative Path Traversal by an authenticated user of the N-Central Administrati…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-16243

Published Dec 15, 2020

SolarWinds Database Performance Analyzer (DPA) 11.1.468 and 12.0.3074 have several persistent XSS vulnerabilities, related to logViewer.iwc, centralManage.cen, userAdministration.…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-16958

Published Dec 1, 2020

Cross-site Scripting (XSS) vulnerability in SolarWinds Web Help Desk 12.7.0 allows attacker to inject arbitrary web script or HTML via Location Name.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-15910

Published Oct 19, 2020

SolarWinds N-Central version 12.3 GA and lower does not set the JSESSIONID attribute to HTTPOnly. This makes it possible to influence the cookie with javascript. An attacker could…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-15909

Published Oct 19, 2020

SolarWinds N-central through 2020.1 allows session hijacking and requires user interaction or physical access. The N-Central JSESSIONID cookie attribute is not checked against mul…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-13169

Published Sep 17, 2020

Stored XSS (Cross-Site Scripting) exists in the SolarWinds Orion Platform before before 2020.2.1 on multiple forms and pages. This vulnerability may lead to the Information Disclo…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-15576

Published Jul 7, 2020

SolarWinds Serv-U File Server before 15.2.1 allows information disclosure via an HTTP response.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-15575

Published Jul 7, 2020

SolarWinds Serv-U File Server before 15.2.1 allows XSS as demonstrated by Tenable Scan, aka Case Number 00484194.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 201-225 of 319 CVEsPage 9 of 13