Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

SolarWinds — Vulnerabilities & Security Advisories 189

Browse all 189 CVE security advisories affecting SolarWinds. AI-powered Chinese analysis, POCs, and references for each vulnerability.

SolarWinds provides IT management and monitoring software, primarily serving enterprise networks through its Orion platform. Historically, its applications have exhibited vulnerabilities typical of complex enterprise suites, including remote code execution, cross-site scripting, and privilege escalation flaws. These weaknesses often stem from intricate integration points and legacy codebases. The most significant security incident occurred in 2020, when a supply chain attack compromised the software’s update mechanism, allowing threat actors to insert malicious code into legitimate updates. This breach affected numerous government agencies and private corporations, exposing sensitive data and compromising network integrity. The incident highlighted critical risks in software supply chains and led to widespread scrutiny of the company’s development and security practices. Consequently, SolarWinds has implemented stricter security controls and transparency measures to restore trust and mitigate future risks associated with its widely deployed infrastructure tools.

CVE ID Title CVSS Severity Published
CVE-2021-35244 Unrestricted File Upload Causing Remote Code Execution: Orion Platform 2020.2.6 — Orion Platform 6.8 Medium 2021-12-20
CVE-2021-35248 Unrestricted access to Orion.UserSettings SWIS entity for low-privilege users — Orion CWE-732 6.8 Medium 2021-12-20
CVE-2021-35242 A valid CSRF token is present in response to an invalid request — Serv-U Server CWE-352 8.3 High 2021-12-06
CVE-2021-35245 Broken Access Control Vulnerability for SolarWinds Serv-U — Serv-U FTP CWE-284 8.4 High 2021-12-06
CVE-2021-35237 Clickjacking Vulnerability — Kiwi Syslog Server CWE-1021 5.0 Medium 2021-10-29
CVE-2021-35236 Missing Secure Flag From SSL Cookie — Kiwi Syslog Server CWE-614 3.1 Low 2021-10-27
CVE-2021-35235 ASP.NET Debug Feature Enabled — Kiwi Syslog Server CWE-11 5.3 Medium 2021-10-27
CVE-2021-35233 HTTP TRACK & TRACE Methods Enabled — Kiwi Syslog Server CWE-16 5.3 Medium 2021-10-27
CVE-2021-35231 Unquoted Path (SMB Login) Vulnerability — Kiwi Syslog Server CWE-428 6.7 Medium 2021-10-25
CVE-2021-35230 Unquoted Path Vulnerability (SMB Login) in Kiwi CatTools — Kiwi CatTools CWE-22 6.7 Medium 2021-10-22
CVE-2021-35228 Reflected cross site scripting affecting SolarWinds: DPA 2021.3.7388 — SolarWinds 5.5 Medium 2021-10-21
CVE-2021-35227 Insecure Web Configuration for RabbitMQ Management Plugin in SolarWinds ARM — Access Rights Manager CWE-79 4.7 Medium 2021-10-21
CVE-2021-35225 Netpath Horizontal Privilege Escalation Vulnerability: NPM 2020.2.5 — NPM 5.0 Medium 2021-10-21
CVE-2021-35214 Session Management Vulnerability — Pingdom 4.8 Medium 2021-10-12
CVE-2021-35217 Insecure Deserialization of untrusted data causing Remote code execution vulnerability. — Orion Platform 8.9 High 2021-09-08
CVE-2021-35218 Chart Endpoint Deserialization of Untrusted Data Remote Code Execution Vulnerability — Patch Manager CWE-502 8.9 High 2021-09-01
CVE-2021-35216 Deserialization of Untrusted Data in Resource Controls Remote Code Execution — Patch Manager CWE-502 8.9 High 2021-09-01
CVE-2021-35215 ActionPluginBaseView Deserialization of Untrusted Data RCE — Orion Platform CWE-502 8.9 High 2021-09-01
CVE-2021-35238 Stored XSS through URL POST parameter in CreateExternalWebsite Vulnerability — Orion Platform CWE-79 4.8 Medium 2021-09-01
CVE-2021-35212 Blind SQL injection Vulnerability — Orion Platform 8.9 High 2021-08-31
CVE-2021-35223 Execute Command Function Allows Remote Code Execution (RCE)Vulnerability — Serv-U CWE-20 8.5 High 2021-08-31
CVE-2021-35213 Orion User setting Improper Access Control Privilege Escalation Vulnerability — Orion Platform CWE-284 8.9 High 2021-08-31
CVE-2021-35240 Stored XSS via Help Server settings — Orion Platform CWE-79 6.5 Medium 2021-08-31
CVE-2021-35239 Stored XSS in Maps text box hyperlink Vulnerability — Orion Platform CWE-79 7.5 High 2021-08-31
CVE-2021-35222 Resource.aspx Reflected Cross-Site Scripting Vulnerability — Orion Platform CWE-79 8.0 High 2021-08-31
CVE-2021-35221 ImportAlert Improper Access Control Tampering Vulnerability — Orion Platform CWE-284 6.3 Medium 2021-08-31
CVE-2021-35220 EmailWebPage Command Injection RCE — Orion Platform 8.1 High 2021-08-31
CVE-2021-35219 ExportToPdfCmd Arbitrary File Read Information Disclosure Vulnerability — Orion Platform 6.0 Medium 2021-08-31
CVE-2021-32076 Access Restriction bypass vulnerability via referrer spoof - Business Logic Bypass — Web Help Desk CWE-290 5.3 Medium 2021-08-26
CVE-2021-35211 Serv-U Remote Memory Escape Vulnerability — Serv-U Managed File Transfer Server and Serv-U Secured FTP 9.0 Critical 2021-07-14

This page lists every published CVE security advisory associated with SolarWinds. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.