Solarwinds
solarwinds
319 CVEs • 57 products
Products (57)
Click to collapseToggle
Products (57)
Click to collapse
CVEs (319)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
SolarWinds Serv-U before 15.2.2 allows authenticated reflected XSS. |
SolarWinds Serv-U before 15.2.2 allows Unauthenticated Macro Injection. |
SolarWinds Serv-U before 15.2.2 allows Authenticated Stored XSS. |
SolarWinds Serv-U before 15.2.2 allows Authenticated Directory Traversal. |
SolarWinds Web Help Desk 12.7.0 allows XSS via a Schedule Name. |
SolarWinds Web Help Desk 12.7.0 allows HTML injection via a Comment in a Help Request ticket. |
SolarWinds Web Help Desk 12.7.0 allows XSS via a CSV template file with a crafted Location Name field. |
SolarWinds Web Help Desk 12.7.0 allows XSS via the Request Type parameter of a ticket. |
The SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands. This vulnerability could allow a remote attacker to bypass authentication and execute API com...Show more |
SolarWinds Web Help Desk 12.7.0 allows CSV Injection, also known as Formula Injection, via a file attached to a ticket. |
SolarWinds Web Help Desk 12.7.0 allows XSS via the First Name field of a User Account. |
SolarWinds Web Help Desk 12.7.0 allows XSS via an uploaded SVG document in a request. |
An issue was discovered in SolarWinds N-Central 12.3.0.670. The AdvancedScripts HTTP endpoint allows CSRF. |
An issue was discovered in SolarWinds N-Central 12.3.0.670. The local database does not require authentication: security is only based on ability to access a network interface. The database has keys and passwords. |
An issue was discovered in SolarWinds N-Central 12.3.0.670. Hard-coded Credentials exist by default for local user accounts named support@n-able.com and nableadmin@n-able.com. These allow logins to the N-Central Administ...Show more |
An issue was discovered in SolarWinds N-Central 12.3.0.670. The SSH component does not restrict the Communication Channel to Intended Endpoints. An attacker can leverage an SSH feature (port forwarding with a temporary k...Show more |
An issue was discovered in SolarWinds N-Central 12.3.0.670. The sudo configuration has incorrect access control because the nable web user account is effectively able to run arbitrary OS commands as root (i.e., the use o...Show more |
An issue was discovered in SolarWinds N-Central 12.3.0.670. The AdvancedScripts HTTP endpoint allows Relative Path Traversal by an authenticated user of the N-Central Administration Console (NAC), leading to execution of...Show more |
1Solarwinds 1Database Performance Analyzer Nov 21, 2024 Dec 15, 2020 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 SolarWinds Database Performance Analyzer (DPA) 11.1.468 and 12.0.3074 have several persistent XSS vulnerabilities, related to logViewer.iwc, centralManage.cen, userAdministration.iwc, database.iwc, alertManagement.iwc, e...Show more |
Cross-site Scripting (XSS) vulnerability in SolarWinds Web Help Desk 12.7.0 allows attacker to inject arbitrary web script or HTML via Location Name. |