solarwinds
320 tracked vulnerabilities.
CVE-2026-28298
MEDIUM
SolarWinds Observability Self-Hosted Stored Cross-Site Scripting Vulnerability
Mar 26, 2026
CVSS 5.9
EPSS 0.00
CVE-2026-28297
MEDIUM
SolarWinds Observability Self-Hosted Stored Cross-Site Scripting Vulnerability
Mar 26, 2026
CVSS 6.1
EPSS 0.00
CVE-2025-40541
CRITICAL
SolarWinds Serv-U < 15.5.4 - Authenticated Insecure Direct Object Reference
Feb 24, 2026
CVSS 9.1
EPSS 0.00
CVE-2025-40540
CRITICAL
SolarWinds Serv-U < 15.5.4 - Authenticated Remote Code Execution via Type Confusion
Feb 24, 2026
CVSS 9.1
EPSS 0.00
CVE-2025-40539
CRITICAL
SolarWinds Serv-U < 15.5.4 - Authenticated Remote Code Execution via Type Confusion
Feb 24, 2026
CVSS 9.1
EPSS 0.00
CVE-2025-40538
CRITICAL
SolarWinds Serv-U < 15.5.4 - Authenticated Privilege Escalation via Admin User Creation
Feb 24, 2026
CVSS 9.1
EPSS 0.00
CVE-2025-40554
CRITICAL
NUCLEI
SolarWinds Web Help Desk < 2026.1 - Authentication Bypass
Jan 28, 2026
CVSS 9.8
EPSS 0.07
CVE-2025-40553
CRITICAL
SolarWinds Web Help Desk < 2026.1 - Unauthenticated Remote Code Execution via Untrusted Data Deserialization
Jan 28, 2026
CVSS 9.8
EPSS 0.17
CVE-2025-40552
CRITICAL
NUCLEI
SolarWinds Web Help Desk < 2026.1 - Authentication Bypass
Jan 28, 2026
CVSS 9.8
EPSS 0.09
CVE-2025-40551
CRITICAL
KEVNUCLEI
SolarWinds Web Help Desk < 2026.1 - Unauthenticated Remote Code Execution via Untrusted Data Deserialization
Jan 28, 2026
CVSS 9.8
EPSS 0.87
CVE-2025-40537
HIGH
SolarWinds Web Help Desk < 2026.1 - Use of Hard-coded Credentials
Jan 28, 2026
CVSS 7.5
EPSS 0.00
CVE-2025-40536
HIGH
KEVNUCLEI
SolarWinds Web Help Desk unauthenticated RCE
Jan 28, 2026
CVSS 8.1
EPSS 0.69
CVE-2025-40549
CRITICAL
SolarWinds Serv-U < 15.5.3 - Authenticated Path Traversal
Nov 18, 2025
CVSS 9.1
EPSS 0.00
CVE-2025-40548
CRITICAL
SolarWinds Serv-U < 15.5.3 - Authenticated Privilege Escalation
Nov 18, 2025
CVSS 9.1
EPSS 0.00
CVE-2025-40547
CRITICAL
SolarWinds Serv-U < 15.5.3 - Authenticated Remote Code Execution
Nov 18, 2025
CVSS 9.1
EPSS 0.00
CVE-2025-40545
MEDIUM
SolarWinds Observability Self-Hosted < 2025.4.1 - Authenticated Open Redirect via Unsanitized URL
Nov 18, 2025
CVSS 4.8
EPSS 0.00
CVE-2025-26391
MEDIUM
SolarWinds Observability Self-Hosted < 2025.4.1 - Authenticated Stored Cross-Site Scripting in User-Created URL Fields
Nov 18, 2025
CVSS 5.4
EPSS 0.00
CVE-2025-26392
MEDIUM
SolarWinds Observability Self-Hosted < 2025.4 - Authenticated SQL Injection
Oct 21, 2025
CVSS 5.4
EPSS 0.00
CVE-2025-26399
CRITICAL
KEV
SolarWinds Web Help Desk < 12.8.6 - Unauthenticated Remote Code Execution via AjaxProxy Deserialization
Sep 23, 2025
CVSS 9.8
EPSS 0.27
CVE-2025-26398
MEDIUM
SolarWinds Database Performance Analyzer < 2025.3 - Use of Hard-coded Cryptographic Key
Aug 12, 2025
CVSS 5.6
EPSS 0.00
CVE-2025-26400
MEDIUM
SolarWinds Web Help Desk < 12.8.7 - XML External Entity Injection
Jul 29, 2025
CVSS 5.3
EPSS 0.00
CVE-2025-26397
HIGH
SolarWinds Observability Self-Hosted < 2025.2.1 - Privilege Escalation via Untrusted Deserialization
Jul 24, 2025
CVSS 7.8
EPSS 0.00
CVE-2025-26395
HIGH
SolarWinds Observability Self-Hosted < 2025.2 - Authenticated Stored Cross-Site Scripting via URL Field
Jun 10, 2025
CVSS 7.1
EPSS 0.00
CVE-2025-26394
MEDIUM
SolarWinds Observability Self-Hosted < 2025.2 - Authenticated Open Redirect
Jun 10, 2025
CVSS 4.8
EPSS 0.00
CVE-2025-26396
HIGH
SolarWinds Dameware - Privilege Escalation
Jun 02, 2025
CVSS 7.8
EPSS 0.00
Products
orion_platform 49
serv-u 39
access_rights_manager 32
solarwinds_platform 27
serv-u_file_server 20
web_help_desk 20
serv-u_ftp_server 11
database_performance_analyzer 10
n-central 9
orion_network_performance_monitor 9
network_performance_monitor 8
observability_self-hosted 8
dameware_mini_remote_control 7
network_configuration_manager 7
tftp_server 6
webhelpdesk 6
kiwi_syslog_server 5
log_and_event_manager 5
orion_web_performance_monitor 4
security_event_manager 4
log_\&_event_manager 3
patch_manager 3
server_and_application_monitor 3
storage_manager 3
virtualization_manager 3
SolarWinds Observability Self-Hosted 2
ftp_voyager 2
kiwi_cattools 2
netpath 2
serv-u_mft_server 2
Quick Filters