Vulnerabilities > Solarwinds > Critical

DATE CVE VULNERABILITY TITLE RISK
2021-07-14 CVE-2021-35211 Out-of-bounds Write vulnerability in Solarwinds Serv-U
Microsoft discovered a remote code execution (RCE) vulnerability in the SolarWinds Serv-U product utilizing a Remote Memory Escape Vulnerability.
network
low complexity
solarwinds CWE-787
critical
10.0
2021-07-13 CVE-2021-31217 Incorrect Default Permissions vulnerability in Solarwinds Dameware Mini Remote Control 12.0.1.200
In SolarWinds DameWare Mini Remote Control Server 12.0.1.200, insecure file permissions allow file deletion as SYSTEM.
network
low complexity
solarwinds CWE-276
critical
9.1
2021-05-21 CVE-2021-31474 Unspecified vulnerability in Solarwinds Network Performance Monitor 2020.2.1/2020.2.4
This vulnerability allows remote attackers to execute arbitrary code on affected installations of SolarWinds Network Performance Monitor 2020.2.1.
network
low complexity
solarwinds
critical
9.8
2021-04-14 CVE-2021-27258 Unspecified vulnerability in Solarwinds Orion Platform 2020.2
This vulnerability allows remote attackers to execute escalate privileges on affected installations of SolarWinds Orion Platform 2020.2.
network
low complexity
solarwinds
critical
9.8
2021-02-03 CVE-2021-25274 Deserialization of Untrusted Data vulnerability in Solarwinds Orion Platform
The Collector Service in SolarWinds Orion Platform before 2020.2.4 uses MSMQ (Microsoft Message Queue) and doesn't set permissions on its private queues.
network
low complexity
solarwinds CWE-502
critical
9.8
2021-02-03 CVE-2020-35481 Unspecified vulnerability in Solarwinds Serv-U
SolarWinds Serv-U before 15.2.2 allows Unauthenticated Macro Injection.
network
low complexity
solarwinds
critical
9.8
2020-12-29 CVE-2020-10148 Improper Authentication vulnerability in Solarwinds Orion Platform 2019.4/2020.2/2020.2.1
The SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands.
network
low complexity
solarwinds CWE-287
critical
9.8
2020-09-17 CVE-2020-13169 Cross-site Scripting vulnerability in Solarwinds Orion Platform
Stored XSS (Cross-Site Scripting) exists in the SolarWinds Orion Platform before before 2020.2.1 on multiple forms and pages.
network
low complexity
solarwinds CWE-79
critical
9.0
2020-07-05 CVE-2020-15543 Improper Input Validation vulnerability in Solarwinds Serv-U FTP Server
SolarWinds Serv-U FTP server before 15.2.1 does not validate an argument path.
network
low complexity
solarwinds CWE-20
critical
9.8
2020-07-05 CVE-2020-15542 Unspecified vulnerability in Solarwinds Serv-U FTP Server
SolarWinds Serv-U FTP server before 15.2.1 mishandles the CHMOD command.
network
low complexity
solarwinds
critical
9.8