← Back

Solarwinds

solarwinds

319 CVEs • 57 products

Products (57)

Click to collapse
Toggle
Serv U
serv-u
Web Help Desk
web_help_desk
N Central
n-central
Tftp Server
tftp_server
Webhelpdesk
webhelpdesk
Patch Manager
patch_manager
Ftp Voyager
ftp_voyager
Netpath
netpath
Kiwi Cattools
kiwi_cattools
Dameware
dameware
Help Desk
help_desk
Pingdom
pingdom
Sql Sentry
sql_sentry
Dynamips
dynamips

CVEs (319)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Solarwinds
2Network Performance Monitor Orion Platform 2018 Netpath
Network Performance Monitor Orion Platform 2018 Npm
Jun 17, 2026
Feb 17, 2020
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
SolarWinds Network Performance Monitor (Orion Platform 2018, NPM 12.3, NetPath 1.1.3) allows XSS by authenticated users via a crafted onerror attribute of a VIDEO element in an action for an ALERT.
1Solarwinds
1N Central
Jun 17, 2026
Jan 26, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
SolarWinds N-central before 12.1 SP1 HF5 and 12.2 before SP1 HF2 allows remote attackers to retrieve cleartext domain admin credentials from the Agent & Probe settings, and obtain other sensitive information. The attacke...Show more
SolarWinds N-central before 12.1 SP1 HF5 and 12.2 before SP1 HF2 allows remote attackers to retrieve cleartext domain admin credentials from the Agent & Probe settings, and obtain other sensitive information. The attacker can use a customer ID to self register and read any aspects of the agent/appliance configuration.Show less
1Solarwinds
1Orion Platform
Jun 17, 2026
Jan 17, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A Stored Client Side Template Injection (CSTI) with Angular was discovered in the SolarWinds Orion Platform 2019.2 HF1 in many application forms. An attacker can inject an Angular expression and escape the Angular sandbo...Show more
A Stored Client Side Template Injection (CSTI) with Angular was discovered in the SolarWinds Orion Platform 2019.2 HF1 in many application forms. An attacker can inject an Angular expression and escape the Angular sandbox to achieve stored XSS. This can lead to privilege escalation.Show less
1Solarwinds
1Orion Platform
Jun 17, 2026
Jan 17, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A Reflected Client Side Template Injection (CSTI) with Angular was discovered in the SolarWinds Orion Platform 2019.2 HF1 in many forms. An attacker can inject an Angular expression and escape the Angular sandbox to achi...Show more
A Reflected Client Side Template Injection (CSTI) with Angular was discovered in the SolarWinds Orion Platform 2019.2 HF1 in many forms. An attacker can inject an Angular expression and escape the Angular sandbox to achieve stored XSS.Show less
1Solarwinds
1Serv U Ftp Server
Jun 17, 2026
Dec 18, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A cross-site scripting (XSS) vulnerability exists in SolarWinds Serv-U FTP Server 15.1.7 in the email parameter, a different vulnerability than CVE-2018-19934 and CVE-2019-13182.
1Solarwinds
1Serv U Ftp Server
Jun 17, 2026
Dec 16, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A stored cross-site scripting (XSS) vulnerability exists in the web UI of SolarWinds Serv-U FTP Server 15.1.7.
1Solarwinds
1Serv U Ftp Server
Jun 17, 2026
Dec 16, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
A CSV injection vulnerability exists in the web UI of SolarWinds Serv-U FTP Server v15.1.7.
1Solarwinds
1Dameware Mini Remote Control
Jun 17, 2026
Oct 8, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The Solarwinds Dameware Mini Remote Client agent v12.1.0.89 supports smart card authentication which can allow a user to upload an executable to be executed on the DWRCS.exe host. An unauthenticated, remote attacker can...Show more
The Solarwinds Dameware Mini Remote Client agent v12.1.0.89 supports smart card authentication which can allow a user to upload an executable to be executed on the DWRCS.exe host. An unauthenticated, remote attacker can request smart card login and upload and execute an arbitrary executable run under the Local System account.Show less
1Solarwinds
1Database Performance Analyzer
Nov 21, 2024
Aug 14, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
SolarWinds Database Performance Analyzer 11.1.457 contains an instance of Reflected XSS in its idcStateError component, where the page parameter is reflected into the HREF of the 'Try Again' Button on the page, aka a /iw...Show more
SolarWinds Database Performance Analyzer 11.1.457 contains an instance of Reflected XSS in its idcStateError component, where the page parameter is reflected into the HREF of the 'Try Again' Button on the page, aka a /iwc/idcStateError.iwc?page= URI.Show less
1Solarwinds
1Network Performance Monitor
Nov 21, 2024
Jul 16, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
SolarWinds Network Performance Monitor 12.3 allows SQL Injection via the /api/ActiveAlertsOnThisEntity/GetActiveAlerts TriggeringObjectEntityNames parameter.
1Solarwinds
2Serv U Ftp Server
Serv U Mft Server
Jun 17, 2026
Jun 17, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A privilege escalation vulnerability exists in SolarWinds Serv-U before 15.1.7 for Linux.
1Solarwinds
1Dameware Mini Remote Control
Jun 17, 2026
Jun 7, 2019
N/A· v4
7.4 HIGH· v3
5.8 MEDIUM· v2
Dameware Remote Mini Control version 12.1.0.34 and prior contains an unauthenticated remote buffer over-read due to the server not properly validating RsaSignatureLen during key negotiation, which could crash the applica...Show more
Dameware Remote Mini Control version 12.1.0.34 and prior contains an unauthenticated remote buffer over-read due to the server not properly validating RsaSignatureLen during key negotiation, which could crash the application or leak sensitive information.Show less
1Solarwinds
1Serv U Ftp Server
Nov 21, 2024
Jun 7, 2019
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
The local management interface in SolarWinds Serv-U FTP Server 15.1.6.25 has incorrect access controls that permit local users to bypass authentication in the application and execute code in the context of the Windows SY...Show more
The local management interface in SolarWinds Serv-U FTP Server 15.1.6.25 has incorrect access controls that permit local users to bypass authentication in the application and execute code in the context of the Windows SYSTEM account, leading to privilege escalation. To exploit this vulnerability, an attacker must have local access the the host running Serv-U, and a Serv-U administrator have an active management console session.Show less
1Solarwinds
1Dameware Mini Remote Control
Jun 17, 2026
May 2, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
DWRCC in SolarWinds DameWare Mini Remote Control 10.0 x64 has a Buffer Overflow associated with the size field for the machine name.
1Solarwinds
1Serv U Ftp Server
Nov 21, 2024
Mar 21, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
SolarWinds Serv-U FTP Server 15.1.6.25 has reflected cross-site scripting (XSS) in the Web management interface via URL path and HTTP POST parameter.
1Solarwinds
1Serv U Ftp Server
Nov 21, 2024
Mar 21, 2019
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
SolarWinds Serv-U FTP Server 15.1.6 allows remote authenticated users to execute arbitrary code by leveraging the Import feature and modifying a CSV file.
1Solarwinds
1Orion Platform
Jun 17, 2026
Mar 1, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SolarWinds Orion Platform before 2018.4 Hotfix 2 allows privilege escalation through the RabbitMQ service.
1Solarwinds
1Orion Network Performance Monitor
Jun 17, 2026
Feb 18, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
SolarWinds Orion NPM before 12.4 suffers from a SYSTEM remote code execution vulnerability in the OrionModuleEngine service. This service establishes a NetTcpBinding endpoint that allows remote, unauthenticated clients t...Show more
SolarWinds Orion NPM before 12.4 suffers from a SYSTEM remote code execution vulnerability in the OrionModuleEngine service. This service establishes a NetTcpBinding endpoint that allows remote, unauthenticated clients to connect and call publicly exposed methods. The InvokeActionMethod method may be abused by an attacker to execute commands as the SYSTEM user.Show less
1Solarwinds
1Sftp/scp Server
Nov 21, 2024
Dec 5, 2018
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
SolarWinds SFTP/SCP server through 2018-09-10 is vulnerable to XXE via a world readable and writable configuration file that allows an attacker to exfiltrate data.
1Solarwinds
1Sftp/scp Server
Nov 21, 2024
Dec 5, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
In SolarWinds SFTP/SCP Server through 2018-09-10, the configuration file is world readable and writable, and stores user passwords in an insecure manner, allowing an attacker to determine passwords for potentially privil...Show more
In SolarWinds SFTP/SCP Server through 2018-09-10, the configuration file is world readable and writable, and stores user passwords in an insecure manner, allowing an attacker to determine passwords for potentially privileged accounts. This also grants the attacker an ability to backdoor the server.Show less