CVEs (8)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Solarwinds 1Network Performance Monitor Nov 21, 2024 Oct 21, 2021 N/A· v4 6.4 MEDIUM· v3 5.5 MEDIUM· v2 Each authenticated Orion Platform user in a MSP (Managed Service Provider) environment can view and browse all NetPath Services from all that MSP's customers. This can lead to any user having a limited insight into other...Show more |
1Solarwinds 1Network Performance Monitor Nov 21, 2024 May 21, 2021 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 This vulnerability allows remote attackers to execute arbitrary code on affected installations of SolarWinds Network Performance Monitor 2020.2.1. Authentication is not required to exploit this vulnerability. The specifi...Show more |
1Solarwinds 1Network Performance Monitor Nov 21, 2024 Feb 12, 2021 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 This vulnerability allows remote attackers to escalate privileges on affected installations of SolarWinds Network Performance Monitor 2020 HF1, NPM: 2020.2. Authentication is required to exploit this vulnerability. The s...Show more |
1Solarwinds 3Netpath Network Performance MonitorOrion PlatformNov 21, 2024 May 4, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 SolarWinds Orion Platform 2018.4 HF3 (NPM 12.4, NetPath 1.1.4) is vulnerable to Information Leakage, because of improper error handling with stack traces, as demonstrated by discovering a full pathname upon a 500 Interna...Show more |
1Solarwinds 3Netpath Network Performance MonitorOrion PlatformNov 21, 2024 Feb 25, 2020 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 SolarWinds Orion Platform 2018.4 HF3 (NPM 12.4, NetPath 1.1.4) allows Stored HTML Injection by administrators via the Web Console Settings screen. |
1Solarwinds 1Network Performance Monitor Nov 21, 2024 Jul 16, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 SolarWinds Network Performance Monitor 12.3 allows SQL Injection via the /api/ActiveAlertsOnThisEntity/GetActiveAlerts TriggeringObjectEntityNames parameter. |
1Solarwinds 1Network Performance Monitor May 13, 2026 Oct 3, 2017 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 The 'Upload logo from external path' function of SolarWinds Network Performance Monitor version 12.0.15300.90 allows remote attackers to cause a denial of service (permanent display of a "Cannot exit above the top direct...Show more |
1Solarwinds 1Network Performance Monitor May 13, 2026 Oct 3, 2017 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 Persistent cross-site scripting (XSS) in the Add Node function of SolarWinds Network Performance Monitor version 12.0.15300.90 allows remote attackers to introduce arbitrary JavaScript into various vulnerable parameters. |