Vulnerabilities > Solarwinds > Critical

DATE CVE VULNERABILITY TITLE RISK
2024-02-15 CVE-2024-23479 Path Traversal vulnerability in Solarwinds Access Rights Manager
SolarWinds Access Rights Manager (ARM) was found to be susceptible to a Directory Traversal Remote Code Execution Vulnerability.
low complexity
solarwinds CWE-22
critical
9.6
2024-02-15 CVE-2024-23477 Path Traversal vulnerability in Solarwinds Access Rights Manager
The SolarWinds Access Rights Manager (ARM) was found to be susceptible to a Directory Traversal Remote Code Execution Vulnerability.
low complexity
solarwinds CWE-22
critical
9.6
2024-02-15 CVE-2024-23476 Path Traversal vulnerability in Solarwinds Access Rights Manager
The SolarWinds Access Rights Manager (ARM) was found to be susceptible to a Directory Traversal Remote Code Execution Vulnerability.
low complexity
solarwinds CWE-22
critical
9.6
2024-02-15 CVE-2023-40057 Deserialization of Untrusted Data vulnerability in Solarwinds Access Rights Manager
The SolarWinds Access Rights Manager was found to be susceptible to a Remote Code Execution Vulnerability.
low complexity
solarwinds CWE-502
critical
9.0
2023-10-19 CVE-2023-35187 Path Traversal vulnerability in Solarwinds Access Rights Manager
The SolarWinds Access Rights Manager was susceptible to a Directory Traversal Remote Code Vulnerability.
network
low complexity
solarwinds CWE-22
critical
9.8
2023-10-19 CVE-2023-35184 Deserialization of Untrusted Data vulnerability in Solarwinds Access Rights Manager
The SolarWinds Access Rights Manager was susceptible to Remote Code Execution Vulnerability.
network
low complexity
solarwinds CWE-502
critical
9.8
2023-10-19 CVE-2023-35182 Deserialization of Untrusted Data vulnerability in Solarwinds Access Rights Manager
The SolarWinds Access Rights Manager was susceptible to Remote Code Execution Vulnerability.
network
low complexity
solarwinds CWE-502
critical
9.8
2021-09-01 CVE-2021-35216 Deserialization of Untrusted Data vulnerability in Solarwinds Patch Manager
Insecure Deserialization of untrusted data remote code execution vulnerability was discovered in Patch Manager Orion Platform Integration module.
network
low complexity
solarwinds CWE-502
critical
9.0
2021-08-31 CVE-2021-35212 SQL Injection vulnerability in Solarwinds Orion Platform
An SQL injection Privilege Escalation Vulnerability was discovered in the Orion Platform reported by the ZDI Team.
network
low complexity
solarwinds CWE-89
critical
9.0
2021-07-14 CVE-2021-35211 Out-of-bounds Write vulnerability in Solarwinds Serv-U
Microsoft discovered a remote code execution (RCE) vulnerability in the SolarWinds Serv-U product utilizing a Remote Memory Escape Vulnerability.
network
low complexity
solarwinds CWE-787
critical
10.0