CVE-2025-40549
- EPSS 1.07%
- Veröffentlicht 18.11.2025 08:41:24
- Zuletzt bearbeitet 02.12.2025 16:37:16
A Path Restriction Bypass vulnerability exists in Serv-U that when abused, could give a malicious actor with access to admin privileges the ability to execute code on a directory. This issue requires administrative privileges to abuse. On Windows s...
CVE-2025-40548
- EPSS 0.7%
- Veröffentlicht 18.11.2025 08:38:19
- Zuletzt bearbeitet 02.12.2025 16:36:36
A missing validation process exists in Serv U when abused, could give a malicious actor with access to admin privileges the ability to execute code. This issue requires administrative privileges to abuse. On Windows deployments, the risk is scored ...
CVE-2025-40547
- EPSS 0.89%
- Veröffentlicht 18.11.2025 08:35:03
- Zuletzt bearbeitet 02.12.2025 16:36:27
A logic error vulnerability exists in Serv-U which when abused could give a malicious actor with access to admin privileges the ability to execute code. This issue requires administrative privileges to abuse. On Windows deployments, the risk is sco...
CVE-2024-45712
- EPSS 0.36%
- Veröffentlicht 15.04.2025 08:39:23
- Zuletzt bearbeitet 18.11.2025 21:45:38
SolarWinds Serv-U is vulnerable to a client-side cross-site scripting (XSS) vulnerability. The vulnerability can only be performed by an authenticated account, on the local machine, from the local browser session. Therefore the risk is very low.
CVE-2024-45714
- EPSS 0.84%
- Veröffentlicht 16.10.2024 08:15:06
- Zuletzt bearbeitet 30.10.2024 20:33:59
Application is vulnerable to Cross Site Scripting (XSS) an authenticated attacker with users’ permissions can modify a variable with a payload.
CVE-2024-45711
- EPSS 6.29%
- Veröffentlicht 16.10.2024 08:15:06
- Zuletzt bearbeitet 17.10.2024 20:17:29
SolarWinds Serv-U is vulnerable to a directory traversal vulnerability where remote code execution is possible depending on privileges given to the authenticated user. This issue requires a user to be authenticated and this is present when softwar...
CVE-2024-28995
- EPSS 99.61%
- Veröffentlicht 06.06.2024 09:15:14
- Zuletzt bearbeitet 26.02.2026 15:04:20
SolarWinds Serv-U was susceptible to a directory transversal vulnerability that would allow access to read sensitive files on the host machine.
CVE-2024-28072
- EPSS 0.64%
- Veröffentlicht 03.05.2024 08:15:07
- Zuletzt bearbeitet 25.02.2025 17:12:45
A highly privileged account can overwrite arbitrary files on the system with log output. The log file path tags were not sanitized properly.
CVE-2024-28073
- EPSS 1.12%
- Veröffentlicht 17.04.2024 17:15:14
- Zuletzt bearbeitet 10.02.2025 22:38:47
SolarWinds Serv-U was found to be susceptible to a Directory Traversal Remote Code Vulnerability. This vulnerability requires a highly privileged account to be exploited.
- EPSS 0.83%
- Veröffentlicht 06.12.2023 04:15:07
- Zuletzt bearbeitet 21.11.2024 08:18:36
A vulnerability has been identified within Serv-U 15.4 that allows an authenticated actor to insert content on the file share function feature of Serv-U, which could be used maliciously.