← Back

Solarwinds

solarwinds

317 CVEs • 57 products

Products (57)

Click to collapse
Toggle
Serv U
serv-u
Web Help Desk
web_help_desk
N Central
n-central
Tftp Server
tftp_server
Webhelpdesk
webhelpdesk
Patch Manager
patch_manager
Ftp Voyager
ftp_voyager
Netpath
netpath
Kiwi Cattools
kiwi_cattools
Dameware
dameware
Help Desk
help_desk
Pingdom
pingdom
Sql Sentry
sql_sentry
Dynamips
dynamips

CVEs (317)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Solarwinds
1Serv U
Nov 21, 2024
May 16, 2018
N/A· v4
7.3 HIGH· v3
5.0 MEDIUM· v2
SolarWinds Serv-U MFT before 15.1.6 HFv1 assigns authenticated users a low-entropy session token that can be included in requests to the application as a URL parameter in lieu of a session cookie. This session token's va...Show more
SolarWinds Serv-U MFT before 15.1.6 HFv1 assigns authenticated users a low-entropy session token that can be included in requests to the application as a URL parameter in lieu of a session cookie. This session token's value can be brute-forced by an attacker to obtain the corresponding session cookie and hijack the user's session.Show less
1Solarwinds
3Backup Profiler
Storage ManagerStorage Profiler
May 13, 2026
Dec 20, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
SQL injection vulnerability in the LoginServlet page in SolarWinds Storage Manager before 5.1.2, SolarWinds Storage Profiler before 5.1.2, and SolarWinds Backup Profiler before 5.1.2 allows remote attackers to execute ar...Show more
SQL injection vulnerability in the LoginServlet page in SolarWinds Storage Manager before 5.1.2, SolarWinds Storage Profiler before 5.1.2, and SolarWinds Backup Profiler before 5.1.2 allows remote attackers to execute arbitrary SQL commands via the loginName field.Show less
1Solarwinds
1Network Performance Monitor
May 13, 2026
Oct 3, 2017
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
The 'Upload logo from external path' function of SolarWinds Network Performance Monitor version 12.0.15300.90 allows remote attackers to cause a denial of service (permanent display of a "Cannot exit above the top direct...Show more
The 'Upload logo from external path' function of SolarWinds Network Performance Monitor version 12.0.15300.90 allows remote attackers to cause a denial of service (permanent display of a "Cannot exit above the top directory" error message throughout the entire web application) via a ".." in the path field. In other words, the denial of service is caused by an incorrect implementation of a directory-traversal protection mechanism.Show less
1Solarwinds
1Network Performance Monitor
May 13, 2026
Oct 3, 2017
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Persistent cross-site scripting (XSS) in the Add Node function of SolarWinds Network Performance Monitor version 12.0.15300.90 allows remote attackers to introduce arbitrary JavaScript into various vulnerable parameters.
1Solarwinds
1Log & Event Manager
May 13, 2026
Apr 12, 2017
N/A· v4
10.0 CRITICAL· v3
10.0 HIGH· v2
In SolarWinds Log & Event Manager (LEM) before 6.3.1 Hotfix 4, a menu system is encountered when the SSH service is accessed with "cmc" and "password" (the default username and password). By exploiting a vulnerability in...Show more
In SolarWinds Log & Event Manager (LEM) before 6.3.1 Hotfix 4, a menu system is encountered when the SSH service is accessed with "cmc" and "password" (the default username and password). By exploiting a vulnerability in the restrictssh feature of the menuing script, an attacker can escape from the restricted shell.Show less
1Solarwinds
1Log & Event Manager
May 13, 2026
Apr 10, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
SolarWinds Log & Event Manager (LEM) before 6.3.1 Hotfix 4 allows an authenticated user to execute arbitrary commands.
1Solarwinds
1Log & Event Manager
May 13, 2026
Apr 10, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
SolarWinds Log & Event Manager (LEM) before 6.3.1 Hotfix 4 allows an authenticated user to browse the server's filesystem and read the contents of arbitrary files contained within.
1Solarwinds
1Log And Event Manager
May 13, 2026
Mar 24, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The editbanner feature in SolarWinds LEM (aka SIEM) through 6.3.1 allows remote authenticated users to execute arbitrary code by editing /usr/local/contego/scripts/mgrconfig.pl.
1Solarwinds
1Log And Event Manager
May 13, 2026
Mar 24, 2017
N/A· v4
8.8 HIGH· v3
7.2 HIGH· v2
SolarWinds LEM (aka SIEM) before 6.3.1 has an incorrect sudo configuration, which allows local users to obtain root access by editing /usr/local/contego/scripts/hostname.sh.
1Solarwinds
1Ftp Voyager
May 13, 2026
Mar 20, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Multiple cross-site request forgery (CSRF) vulnerabilities in the web interface in the Scheduler in SolarWinds (formerly Serv-U) FTP Voyager 16.2.0 allow remote attackers to hijack the authentication of users for request...Show more
Multiple cross-site request forgery (CSRF) vulnerabilities in the web interface in the Scheduler in SolarWinds (formerly Serv-U) FTP Voyager 16.2.0 allow remote attackers to hijack the authentication of users for requests that (1) change the admin password, (2) terminate the scheduler, or (3) possibly execute arbitrary commands via crafted requests to Admin/XML/Result.xml.Show less
1Solarwinds
1Virtualization Manager
May 6, 2026
Jun 24, 2016
N/A· v4
4.7 MEDIUM· v3
1.9 LOW· v2
SolarWinds Virtualization Manager 6.3.1 and earlier uses weak encryption to store passwords in /etc/shadow, which allows local users with superuser privileges to obtain user passwords via a brute force attack.
1Solarwinds
1Virtualization Manager
Apr 21, 2026
Jun 17, 2016
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
SolarWinds Virtualization Manager 6.3.1 and earlier allow local users to gain privileges by leveraging a misconfiguration of sudo, as demonstrated by "sudo cat /etc/passwd."
1Solarwinds
1Virtualization Manager
May 6, 2026
Jun 17, 2016
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The RMI service in SolarWinds Virtualization Manager 6.3.1 and earlier allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.
1Solarwinds
1Storage Resource Monitor
May 6, 2026
May 9, 2016
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Multiple SQL injection vulnerabilities in the Web Services web server in SolarWinds Storage Resource Monitor (SRM) Profiler (formerly Storage Manager (STM)) before 6.2.3 allow remote attackers to execute arbitrary SQL co...Show more
Multiple SQL injection vulnerabilities in the Web Services web server in SolarWinds Storage Resource Monitor (SRM) Profiler (formerly Storage Manager (STM)) before 6.2.3 allow remote attackers to execute arbitrary SQL commands via the (1) ScriptSchedule parameter in the ScriptServlet servlet; the (2) winEventId or (3) winEventLog parameter in the WindowsEventLogsServlet servlet; the (4) processOS parameter in the ProcessesServlet servlet; the (5) group, (6) groupName, or (7) clientName parameter in the BackupExceptionsServlet servlet; the (8) valDB or (9) valFS parameter in the BackupAssociationServlet servlet; the (10) orderBy or (11) orderDir parameter in the HostStorageServlet servlet; the (12) fileName, (13) sortField, or (14) sortDirection parameter in the DuplicateFilesServlet servlet; the (15) orderFld or (16) orderDir parameter in the QuantumMonitorServlet servlet; the (17) exitCode parameter in the NbuErrorMessageServlet servlet; the (18) udfName, (19) displayName, (20) udfDescription, (21) udfDataValue, (22) udfSectionName, or (23) udfId parameter in the UserDefinedFieldConfigServlet servlet; the (24) sortField or (25) sortDirection parameter in the XiotechMonitorServlet servlet; the (26) sortField or (27) sortDirection parameter in the BexDriveUsageSummaryServlet servlet; the (28) state parameter in the ScriptServlet servlet; the (29) assignedNames parameter in the FileActionAssignmentServlet servlet; the (30) winEventSource parameter in the WindowsEventLogsServlet servlet; or the (31) name, (32) ipOne, (33) ipTwo, or (34) ipThree parameter in the XiotechMonitorServlet servlet.Show less
1Solarwinds
1Dameware Mini Remote Control
May 6, 2026
Nov 17, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
Stack-based buffer overflow in the URI handler in DWRCC.exe in SolarWinds DameWare Mini Remote Control before 12.0 HotFix 1 allows remote attackers to execute arbitrary code via a crafted commandline argument in a link.
1Solarwinds
1Log And Event Manager
May 6, 2026
Oct 15, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
The command line management console (CMC) in SolarWinds Log and Event Manager (LEM) before 6.2.0 allows remote attackers to execute arbitrary code via unspecified vectors involving the ping feature.
1Solarwinds
1Log And Event Manager
May 6, 2026
Oct 15, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
SolarWinds Log and Event Manager (LEM) allows remote attackers to execute arbitrary commands on managed computers via a request to services/messagebroker/nonsecurestreamingamf involving the traceroute functionality.
1Solarwinds
1Storage Manager
May 6, 2026
Oct 15, 2015
N/A· v4
N/A· v3
10.0 HIGH· v2
ProcessFileUpload.jsp in SolarWinds Storage Manager before 6.2 allows remote attackers to upload and execute arbitrary files via unspecified vectors.
1Solarwinds
1N Able N Central
May 6, 2026
Jul 21, 2015
N/A· v4
N/A· v3
4.0 MEDIUM· v2
The RSM (aka RSMWinService) service in SolarWinds N-Able N-Central before 9.5.1.4514 uses the same password decryption key across different customers' installations, which makes it easier for remote authenticated users t...Show more
The RSM (aka RSMWinService) service in SolarWinds N-Able N-Central before 9.5.1.4514 uses the same password decryption key across different customers' installations, which makes it easier for remote authenticated users to obtain the cleartext domain-administrator password by locating the encrypted password within HTML source code and then leveraging knowledge of this key from another installation.Show less
1Solarwinds
1Storage Manager
May 6, 2026
Jul 6, 2015
N/A· v4
N/A· v3
10.0 HIGH· v2
The AuthenticationFilter class in SolarWinds Storage Manager allows remote attackers to upload and execute arbitrary scripts via unspecified vectors.