Vulnerabilities > Solarwinds

DATE CVE VULNERABILITY TITLE RISK
2024-07-17 CVE-2024-28993 Path Traversal vulnerability in Solarwinds Access Rights Manager
The SolarWinds Access Rights Manager was susceptible to a Directory Traversal and Information Disclosure Vulnerability.
network
low complexity
solarwinds CWE-22
critical
9.4
2024-06-06 CVE-2024-28995 Path Traversal vulnerability in Solarwinds Serv-U
SolarWinds Serv-U was susceptible to a directory transversal vulnerability that would allow access to read sensitive files on the host machine.
network
low complexity
solarwinds CWE-22
7.5
2024-06-04 CVE-2024-28996 SQL Injection vulnerability in Solarwinds Platform
The SolarWinds Platform was determined to be affected by a SWQL Injection Vulnerability.
network
high complexity
solarwinds CWE-89
8.1
2024-06-04 CVE-2024-28999 Race Condition vulnerability in Solarwinds Platform
The SolarWinds Platform was determined to be affected by a Race Condition Vulnerability affecting the web console.
network
high complexity
solarwinds CWE-362
8.1
2024-06-04 CVE-2024-29004 Cross-site Scripting vulnerability in Solarwinds Platform
The SolarWinds Platform was determined to be affected by a stored cross-site scripting vulnerability affecting the web console.
network
low complexity
solarwinds CWE-79
4.8
2024-02-15 CVE-2023-40057 Deserialization of Untrusted Data vulnerability in Solarwinds Access Rights Manager
The SolarWinds Access Rights Manager was found to be susceptible to a Remote Code Execution Vulnerability.
low complexity
solarwinds CWE-502
critical
9.0
2024-02-15 CVE-2024-23476 Path Traversal vulnerability in Solarwinds Access Rights Manager
The SolarWinds Access Rights Manager (ARM) was found to be susceptible to a Directory Traversal Remote Code Execution Vulnerability.
low complexity
solarwinds CWE-22
critical
9.6
2024-02-15 CVE-2024-23477 Path Traversal vulnerability in Solarwinds Access Rights Manager
The SolarWinds Access Rights Manager (ARM) was found to be susceptible to a Directory Traversal Remote Code Execution Vulnerability.
low complexity
solarwinds CWE-22
critical
9.6
2024-02-15 CVE-2024-23478 Deserialization of Untrusted Data vulnerability in Solarwinds Access Rights Manager
SolarWinds Access Rights Manager (ARM) was found to be susceptible to a Remote Code Execution Vulnerability.
low complexity
solarwinds CWE-502
8.0
2024-02-15 CVE-2024-23479 Path Traversal vulnerability in Solarwinds Access Rights Manager
SolarWinds Access Rights Manager (ARM) was found to be susceptible to a Directory Traversal Remote Code Execution Vulnerability.
low complexity
solarwinds CWE-22
critical
9.6