Known Vulnerabilities for products from Solarwinds

Listed below are 20 of the newest known vulnerabilities associated with the vendor "Solarwinds".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2026-28318 json SolarWinds Serv-U is susceptible to specially crafted POST requests that crash the Serv-U service without authentication usin... Not Provided 2026-06-04 2026-06-05
CVE-2026-28299 json SolarWinds Web Help Desk is found to be affected by a denial-of-service vulnerability, which when exploited, could cause the ... Not Provided 2026-06-02 2026-06-04
CVE-2026-28298 json SolarWinds Observability Self-Hosted was found to be affected by a stored cross-site scripting vulnerability, which when expl... Not Provided 2026-03-26 2026-03-31
CVE-2026-28297 json SolarWinds Observability Self-Hosted was found to be affected by a stored cross-site scripting vulnerability, which when expl... Not Provided 2026-03-26 2026-03-31
CVE-2023-40062 json SolarWinds Platform Incomplete List of Disallowed Inputs Remote Code Execution Vulnerability. If executed, this vulnerability... 8.8 - HIGH 2023-11-01 2023-11-09
CVE-2023-40061 json  Insecure job execution mechanism vulnerability. This vulnerability can lead to other attacks as a result. 9.8 - CRITICAL 2023-11-01 2023-11-09
CVE-2023-40060 json A vulnerability has been identified within Serv-U 15.4 and 15.4 Hotfix 1 that, if exploited, allows an actor to bypass multi-... 7.2 - HIGH 2023-09-07 2023-09-14
CVE-2023-40058 json ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... 6.5 - MEDIUM 2023-12-21 2024-02-02
CVE-2023-40056 json ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... 8.8 - HIGH 2023-11-28 2023-12-04
CVE-2023-40055 json ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... 8.8 - HIGH 2023-11-09 2023-11-17
CVE-2023-40054 json ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... 8.8 - HIGH 2023-11-09 2023-11-17
CVE-2023-35187 json The SolarWinds Access Rights Manager was susceptible to a Directory Traversal Remote Code Vulnerability. This vulnerability a... 9.8 - CRITICAL 2023-10-19 2023-10-25
CVE-2023-35186 json The SolarWinds Access Rights Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows an aut... 8.8 - HIGH 2023-10-19 2023-10-25
CVE-2023-35185 json The SolarWinds Access Rights Manager was susceptible to a Directory Traversal Remote Code Vulnerability using SYSTEM privileg... 7.2 - HIGH 2023-10-19 2023-10-25
CVE-2023-35184 json The SolarWinds Access Rights Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows an una... 9.8 - CRITICAL 2023-10-19 2023-10-25
CVE-2023-35183 json The SolarWinds Access Rights Manager was susceptible to Privilege Escalation Vulnerability. This vulnerability allows authent... 7.8 - HIGH 2023-10-19 2023-10-25
CVE-2023-35182 json The SolarWinds Access Rights Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability can be abused... 9.8 - CRITICAL 2023-10-19 2023-10-25
CVE-2023-35181 json The SolarWinds Access Rights Manager was susceptible to Privilege Escalation Vulnerability. This vulnerability allows users t... 7.8 - HIGH 2023-10-19 2023-10-25
CVE-2023-35180 json The SolarWinds Access Rights Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows authen... 8.8 - HIGH 2023-10-19 2023-10-25
CVE-2023-35179 json A vulnerability has been identified within Serv-U 15.4 that, if exploited, allows an actor to bypass multi-factor/two-factor... 7.2 - HIGH 2023-08-11 2023-09-14

Known software with vulnerabilities from Solarwinds

Type Vendor Product Version
ApplicationSolarwindsAdvanced Monitoring Agent-
ApplicationSolarwindsAdvanced Subnet Calculator9.1
ApplicationSolarwindsCollector2.2.1.0
ApplicationSolarwindsDameware12.1
ApplicationSolarwindsDameware Mini Remote Control12.0
ApplicationSolarwindsDameware Mini Remote Control Client Agent Service6.9.0.0
ApplicationSolarwindsDameware Remote Support10.0
ApplicationSolarwindsDamewire Mini Remote Control10.0
ApplicationSolarwindsDatabase Performance Analyzer11.1.457
ApplicationSolarwindsEngineers Editionsolarwinds_engineers_edition
ApplicationSolarwindsExchange Monitor1.0.1.30
ApplicationSolarwindsFirewall Security Manager6.6.5
ApplicationSolarwindsFtp Voyager16.2.0
ApplicationSolarwindsInformation Service2.5.1
ApplicationSolarwindsIntegrated Virtual Infrastructure Monitor1.1.674.0
ApplicationSolarwindsIpmonitor10.0.1368.1
ApplicationSolarwindsIp Address Manager Web Interface3.0
ApplicationSolarwindsJob Engine1.5.2.0
ApplicationSolarwindsKiwi Cattools3.6.0__\(service_edition\)
ApplicationSolarwindsLog And Event Manager6.1
© CVE.report 2026 |

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report