Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

SolarWinds — Vulnerabilities & Security Advisories 189

Browse all 189 CVE security advisories affecting SolarWinds. AI-powered Chinese analysis, POCs, and references for each vulnerability.

SolarWinds provides IT management and monitoring software, primarily serving enterprise networks through its Orion platform. Historically, its applications have exhibited vulnerabilities typical of complex enterprise suites, including remote code execution, cross-site scripting, and privilege escalation flaws. These weaknesses often stem from intricate integration points and legacy codebases. The most significant security incident occurred in 2020, when a supply chain attack compromised the software’s update mechanism, allowing threat actors to insert malicious code into legitimate updates. This breach affected numerous government agencies and private corporations, exposing sensitive data and compromising network integrity. The incident highlighted critical risks in software supply chains and led to widespread scrutiny of the company’s development and security practices. Consequently, SolarWinds has implemented stricter security controls and transparency measures to restore trust and mitigate future risks associated with its widely deployed infrastructure tools.

Found 18 results / 189 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2022-36965 Stored and DOM XSS in QoE Applications: Orion Platform — Orion Platform 6.1 Medium 2022-09-30
CVE-2022-36961 Orion Platform SQL Injection Privilege Escalation Vulnerability — Orion Platform CWE-89 8.8 High 2022-09-30
CVE-2021-35244 Unrestricted File Upload Causing Remote Code Execution: Orion Platform 2020.2.6 — Orion Platform 6.8 Medium 2021-12-20
CVE-2021-35217 Insecure Deserialization of untrusted data causing Remote code execution vulnerability. — Orion Platform 8.9 High 2021-09-08
CVE-2021-35215 ActionPluginBaseView Deserialization of Untrusted Data RCE — Orion Platform CWE-502 8.9 High 2021-09-01
CVE-2021-35238 Stored XSS through URL POST parameter in CreateExternalWebsite Vulnerability — Orion Platform CWE-79 4.8 Medium 2021-09-01
CVE-2021-35212 Blind SQL injection Vulnerability — Orion Platform 8.9 High 2021-08-31
CVE-2021-35213 Orion User setting Improper Access Control Privilege Escalation Vulnerability — Orion Platform CWE-284 8.9 High 2021-08-31
CVE-2021-35240 Stored XSS via Help Server settings — Orion Platform CWE-79 6.5 Medium 2021-08-31
CVE-2021-35239 Stored XSS in Maps text box hyperlink Vulnerability — Orion Platform CWE-79 7.5 High 2021-08-31
CVE-2021-35222 Resource.aspx Reflected Cross-Site Scripting Vulnerability — Orion Platform CWE-79 8.0 High 2021-08-31
CVE-2021-35221 ImportAlert Improper Access Control Tampering Vulnerability — Orion Platform CWE-284 6.3 Medium 2021-08-31
CVE-2021-35220 EmailWebPage Command Injection RCE — Orion Platform 8.1 High 2021-08-31
CVE-2021-35219 ExportToPdfCmd Arbitrary File Read Information Disclosure Vulnerability — Orion Platform 6.0 Medium 2021-08-31
CVE-2021-27258 Solarwinds Orion Platform 安全漏洞 — Orion Platform CWE-284 9.8 - 2021-04-14
CVE-2020-27871 Solarwinds SolarWinds Orion Platform 路径遍历漏洞 — Orion Platform CWE-22 8.8 - 2021-02-10
CVE-2020-27870 Solarwinds SolarWinds Orion Platform 路径遍历漏洞 — Orion Platform CWE-22 6.5 - 2021-02-10
CVE-2020-10148 SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands — Orion Platform CWE-288 9.8 - 2020-12-29

This page lists every published CVE security advisory associated with SolarWinds. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.