← Back

Solarwinds

solarwinds

317 CVEs • 57 products

Products (57)

Click to collapse
Toggle
Serv U
serv-u
Web Help Desk
web_help_desk
N Central
n-central
Tftp Server
tftp_server
Webhelpdesk
webhelpdesk
Patch Manager
patch_manager
Ftp Voyager
ftp_voyager
Netpath
netpath
Kiwi Cattools
kiwi_cattools
Dameware
dameware
Help Desk
help_desk
Pingdom
pingdom
Sql Sentry
sql_sentry
Dynamips
dynamips

CVEs (317)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Solarwinds
1Access Rights Manager
Feb 26, 2025
May 14, 2024
N/A· v4
8.0 HIGH· v3
N/A· v2
The SolarWinds Access Rights Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows an authenticated user to abuse SolarWinds service resulting in remote code execution. We thank Tren...Show more
The SolarWinds Access Rights Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows an authenticated user to abuse SolarWinds service resulting in remote code execution. We thank Trend Micro Zero Day Initiative (ZDI) for its ongoing partnership in coordinating with SolarWinds on responsible disclosure of this and other potential vulnerabilities. Show less
1Solarwinds
1Access Rights Manager
Feb 10, 2025
May 14, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The SolarWinds Access Rights Manager was found to contain a hard-coded credential authentication bypass vulnerability. If exploited, this vulnerability allows access to the RabbitMQ management console. We thank Trend M...Show more
The SolarWinds Access Rights Manager was found to contain a hard-coded credential authentication bypass vulnerability. If exploited, this vulnerability allows access to the RabbitMQ management console. We thank Trend Micro Zero Day Initiative (ZDI) for its ongoing partnership in coordinating with SolarWinds on responsible disclosure of this and other potential vulnerabilities. Show less
1Solarwinds
1Serv U
Feb 25, 2025
May 3, 2024
N/A· v4
4.9 MEDIUM· v3
N/A· v2
A highly privileged account can overwrite arbitrary files on the system with log output. The log file path tags were not sanitized properly.
1Solarwinds
1Solarwinds Platform
Feb 26, 2025
Apr 18, 2024
N/A· v4
4.8 MEDIUM· v3
N/A· v2
The SolarWinds Platform was susceptible to a XSS vulnerability that affects the maps section of the user interface. This vulnerability requires authentication and requires user interaction.
1Solarwinds
1Solarwinds Platform
Feb 26, 2025
Apr 18, 2024
N/A· v4
7.4 HIGH· v3
N/A· v2
A SolarWinds Platform SWQL Injection Vulnerability was identified in the user interface. This vulnerability requires authentication and user interaction to be exploited.
1Solarwinds
1Solarwinds Platform
Feb 26, 2025
Apr 18, 2024
N/A· v4
3.8 LOW· v3
N/A· v2
The SolarWinds Platform was susceptible to a Arbitrary Open Redirection Vulnerability. A potential attacker can redirect to different domain when using URL parameter with relative entry in the correct format
1Solarwinds
1Serv U
Feb 10, 2025
Apr 17, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
SolarWinds Serv-U was found to be susceptible to a Directory Traversal Remote Code Vulnerability. This vulnerability requires a highly privileged account to be exploited.
1Solarwinds
1Security Event Manager
Feb 26, 2025
Mar 1, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
The SolarWinds Security Event Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows an unauthenticated user to abuse SolarWinds’ service, resulting in remote code execution.
1Solarwinds
1Access Rights Manager
Nov 21, 2024
Feb 15, 2024
N/A· v4
9.6 CRITICAL· v3
N/A· v2
SolarWinds Access Rights Manager (ARM) was found to be susceptible to a Directory Traversal Remote Code Execution Vulnerability. If exploited, this vulnerability allows an unauthenticated user to achieve a Remote Code Ex...Show more
SolarWinds Access Rights Manager (ARM) was found to be susceptible to a Directory Traversal Remote Code Execution Vulnerability. If exploited, this vulnerability allows an unauthenticated user to achieve a Remote Code Execution. Show less
1Solarwinds
1Access Rights Manager
Nov 21, 2024
Feb 15, 2024
N/A· v4
8.0 HIGH· v3
N/A· v2
SolarWinds Access Rights Manager (ARM) was found to be susceptible to a Remote Code Execution Vulnerability. If exploited, this vulnerability allows an authenticated user to abuse a SolarWinds service, resulting in remot...Show more
SolarWinds Access Rights Manager (ARM) was found to be susceptible to a Remote Code Execution Vulnerability. If exploited, this vulnerability allows an authenticated user to abuse a SolarWinds service, resulting in remote code execution. Show less
1Solarwinds
1Access Rights Manager
Nov 21, 2024
Feb 15, 2024
N/A· v4
9.6 CRITICAL· v3
N/A· v2
The SolarWinds Access Rights Manager (ARM) was found to be susceptible to a Directory Traversal Remote Code Execution Vulnerability. If exploited, this vulnerability allows an unauthenticated user to achieve a Remote Cod...Show more
The SolarWinds Access Rights Manager (ARM) was found to be susceptible to a Directory Traversal Remote Code Execution Vulnerability. If exploited, this vulnerability allows an unauthenticated user to achieve a Remote Code Execution. Show less
1Solarwinds
1Access Rights Manager
Nov 21, 2024
Feb 15, 2024
N/A· v4
9.6 CRITICAL· v3
N/A· v2
The SolarWinds Access Rights Manager (ARM) was found to be susceptible to a Directory Traversal Remote Code Execution Vulnerability. If exploited, this vulnerability allows an unauthenticated user to achieve the Remote C...Show more
The SolarWinds Access Rights Manager (ARM) was found to be susceptible to a Directory Traversal Remote Code Execution Vulnerability. If exploited, this vulnerability allows an unauthenticated user to achieve the Remote Code Execution. Show less
1Solarwinds
1Access Rights Manager
Nov 21, 2024
Feb 15, 2024
N/A· v4
9.0 CRITICAL· v3
N/A· v2
The SolarWinds Access Rights Manager was found to be susceptible to a Remote Code Execution Vulnerability. If exploited, this vulnerability allows an authenticated user to abuse a SolarWinds service resulting in remote c...Show more
The SolarWinds Access Rights Manager was found to be susceptible to a Remote Code Execution Vulnerability. If exploited, this vulnerability allows an authenticated user to abuse a SolarWinds service resulting in remote code execution. Show less
1Solarwinds
1Solarwinds Platform
Feb 26, 2025
Feb 6, 2024
N/A· v4
8.0 HIGH· v3
N/A· v2
SQL Injection Remote Code Execution Vulnerability was found using an update statement in the SolarWinds Platform. This vulnerability requires user authentication to be exploited
1Solarwinds
1Solarwinds Platform
Feb 26, 2025
Feb 6, 2024
N/A· v4
8.0 HIGH· v3
N/A· v2
SQL Injection Remote Code Execution Vulnerability was found using a create statement in the SolarWinds Platform. This vulnerability requires user authentication to be exploited.
1Solarwinds
1Access Rights Manager
Nov 21, 2024
Dec 21, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Sensitive data was added to our public-facing knowledgebase that, if exploited, could be used to access components of Access Rights Manager (ARM) if the threat actor is in the same environment.
1Solarwinds
1Serv U
Nov 21, 2024
Dec 6, 2023
N/A· v4
5.0 MEDIUM· v3
N/A· v2
A vulnerability has been identified within Serv-U 15.4 that allows an authenticated actor to insert content on the file share function feature of Serv-U, which could be used maliciously.
1Solarwinds
1Solarwinds Platform
Nov 21, 2024
Nov 28, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
SQL Injection Remote Code Vulnerability was found in the SolarWinds Platform. This vulnerability can be exploited with a low privileged account.
1Solarwinds
1Network Configuration Manager
Nov 21, 2024
Nov 9, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
The Network Configuration Manager was susceptible to a Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows a low-level user to perform the actions with SYSTEM privileges. We found this iss...Show more
The Network Configuration Manager was susceptible to a Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows a low-level user to perform the actions with SYSTEM privileges. We found this issue was not resolved in CVE-2023-33227Show less
1Solarwinds
1Network Configuration Manager
Nov 21, 2024
Nov 9, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
The Network Configuration Manager was susceptible to a Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows a low-level user to perform the actions with SYSTEM privileges. We found this iss...Show more
The Network Configuration Manager was susceptible to a Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows a low-level user to perform the actions with SYSTEM privileges. We found this issue was not resolved in CVE-2023-33226Show less