Fixed Intel

CVE Tracker

Track known exploited vulnerabilities, CISA KEV alerts, and linked threat intelligence.

1,542

Total CVEs

1,542

CISA KEV

35

Known Exploits

9.3

Avg CVSS Score

Severity Distribution

HIGH 1542

Showing 10 of 10 CVEs matching "SolarWinds" · HIGH

CVE-2025-26399KEV
High

SolarWinds Web Help Desk contain a deserialization of untrusted data vulnerability in AjaxProxy that could allow an attacker to run commands on the host machine.

SolarWindsEPSS 28.8%
CVE-2025-40536KEV
High

SolarWinds Web Help Desk contains a security control bypass vulnerability that could allow an unauthenticated attacker to gain access to certain restricted functionality.

SolarWindsEPSS 69.1%
CVE-2025-40551KEV
High

SolarWinds Web Help Desk contains a deserialization of untrusted data vulnerability that could lead to remote code execution, which would allow an attacker to run commands on the host machine. This could be exploited without authentication.

SolarWindsEPSS 80.6%
CVE-2024-28987KEV
High

SolarWinds Web Help Desk contains a hardcoded credential vulnerability that could allow a remote, unauthenticated user to access internal functionality and modify data.

SolarWindsEPSS 94.2%
CVE-2024-28986KEV
High

SolarWinds Web Help Desk contains a deserialization of untrusted data vulnerability that could allow for remote code execution.

SolarWindsEPSS 78.4%
CVE-2024-28995KEV
High

SolarWinds Serv-U contains a path traversal vulnerability that allows an attacker access to read sensitive files on the host machine.

SolarWindsEPSS 94.4%
CVE-2021-35247KEV
High

SolarWinds Serv-U versions 15.2.5 and earlier contain an improper input validation vulnerability that allows attackers to build and send queries without sanitization.

SolarWindsEPSS 3.0%
CVE-2021-35211KEV
High

SolarWinds Serv-U contains an unspecified memory escape vulnerability which can allow for remote code execution.

SolarWindsEPSS 94.3%
CVE-2016-3643KEV
High

SolarWinds Virtualization Manager allows for privilege escalation through leveraging a misconfiguration of sudo.

SolarWindsEPSS 5.4%
CVE-2020-10148KEV
High

SolarWinds Orion API contains an authentication bypass vulnerability that could allow a remote attacker to execute API commands.

SolarWindsEPSS 94.3%