Solarwinds
solarwinds
317 CVEs • 57 products
Products (57)
Click to collapseToggle
Products (57)
Click to collapse
CVEs (317)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
SolarWinds Serv-U MFT before 15.1.6 HFv1 assigns authenticated users a low-entropy session token that can be included in requests to the application as a URL parameter in lieu of a session cookie. This session token's va...Show more |
1Solarwinds 3Backup Profiler Storage ManagerStorage ProfilerMay 13, 2026 Dec 20, 2017 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 SQL injection vulnerability in the LoginServlet page in SolarWinds Storage Manager before 5.1.2, SolarWinds Storage Profiler before 5.1.2, and SolarWinds Backup Profiler before 5.1.2 allows remote attackers to execute ar...Show more |
1Solarwinds 1Network Performance Monitor May 13, 2026 Oct 3, 2017 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 The 'Upload logo from external path' function of SolarWinds Network Performance Monitor version 12.0.15300.90 allows remote attackers to cause a denial of service (permanent display of a "Cannot exit above the top direct...Show more |
1Solarwinds 1Network Performance Monitor May 13, 2026 Oct 3, 2017 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 Persistent cross-site scripting (XSS) in the Add Node function of SolarWinds Network Performance Monitor version 12.0.15300.90 allows remote attackers to introduce arbitrary JavaScript into various vulnerable parameters. |
1Solarwinds 1Log & Event Manager May 13, 2026 Apr 12, 2017 N/A· v4 10.0 CRITICAL· v3 10.0 HIGH· v2 In SolarWinds Log & Event Manager (LEM) before 6.3.1 Hotfix 4, a menu system is encountered when the SSH service is accessed with "cmc" and "password" (the default username and password). By exploiting a vulnerability in...Show more |
1Solarwinds 1Log & Event Manager May 13, 2026 Apr 10, 2017 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 SolarWinds Log & Event Manager (LEM) before 6.3.1 Hotfix 4 allows an authenticated user to execute arbitrary commands. |
1Solarwinds 1Log & Event Manager May 13, 2026 Apr 10, 2017 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 SolarWinds Log & Event Manager (LEM) before 6.3.1 Hotfix 4 allows an authenticated user to browse the server's filesystem and read the contents of arbitrary files contained within. |
1Solarwinds 1Log And Event Manager May 13, 2026 Mar 24, 2017 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 The editbanner feature in SolarWinds LEM (aka SIEM) through 6.3.1 allows remote authenticated users to execute arbitrary code by editing /usr/local/contego/scripts/mgrconfig.pl. |
1Solarwinds 1Log And Event Manager May 13, 2026 Mar 24, 2017 N/A· v4 8.8 HIGH· v3 7.2 HIGH· v2 SolarWinds LEM (aka SIEM) before 6.3.1 has an incorrect sudo configuration, which allows local users to obtain root access by editing /usr/local/contego/scripts/hostname.sh. |
Multiple cross-site request forgery (CSRF) vulnerabilities in the web interface in the Scheduler in SolarWinds (formerly Serv-U) FTP Voyager 16.2.0 allow remote attackers to hijack the authentication of users for request...Show more |
1Solarwinds 1Virtualization Manager May 6, 2026 Jun 24, 2016 N/A· v4 4.7 MEDIUM· v3 1.9 LOW· v2 SolarWinds Virtualization Manager 6.3.1 and earlier uses weak encryption to store passwords in /etc/shadow, which allows local users with superuser privileges to obtain user passwords via a brute force attack. |
1Solarwinds 1Virtualization Manager Apr 21, 2026 Jun 17, 2016 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 SolarWinds Virtualization Manager 6.3.1 and earlier allow local users to gain privileges by leveraging a misconfiguration of sudo, as demonstrated by "sudo cat /etc/passwd." |
1Solarwinds 1Virtualization Manager May 6, 2026 Jun 17, 2016 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The RMI service in SolarWinds Virtualization Manager 6.3.1 and earlier allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library. |
1Solarwinds 1Storage Resource Monitor May 6, 2026 May 9, 2016 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Multiple SQL injection vulnerabilities in the Web Services web server in SolarWinds Storage Resource Monitor (SRM) Profiler (formerly Storage Manager (STM)) before 6.2.3 allow remote attackers to execute arbitrary SQL co...Show more |
1Solarwinds 1Dameware Mini Remote Control May 6, 2026 Nov 17, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 Stack-based buffer overflow in the URI handler in DWRCC.exe in SolarWinds DameWare Mini Remote Control before 12.0 HotFix 1 allows remote attackers to execute arbitrary code via a crafted commandline argument in a link. |
The command line management console (CMC) in SolarWinds Log and Event Manager (LEM) before 6.2.0 allows remote attackers to execute arbitrary code via unspecified vectors involving the ping feature. |
SolarWinds Log and Event Manager (LEM) allows remote attackers to execute arbitrary commands on managed computers via a request to services/messagebroker/nonsecurestreamingamf involving the traceroute functionality. |
ProcessFileUpload.jsp in SolarWinds Storage Manager before 6.2 allows remote attackers to upload and execute arbitrary files via unspecified vectors. |
The RSM (aka RSMWinService) service in SolarWinds N-Able N-Central before 9.5.1.4514 uses the same password decryption key across different customers' installations, which makes it easier for remote authenticated users t...Show more |
The AuthenticationFilter class in SolarWinds Storage Manager allows remote attackers to upload and execute arbitrary scripts via unspecified vectors. |