CVE-2026-28322
- EPSS 0.22%
- Veröffentlicht 30.06.2026 22:15:40
- Zuletzt bearbeitet 02.07.2026 05:16:40
SolarWinds Database Performance Analyzer was found to be affected by a stored cross-site scripting vulnerability, which when exploited, can lead to unintended script execution.
CVE-2025-26398
- EPSS 0.19%
- Veröffentlicht 12.08.2025 08:10:54
- Zuletzt bearbeitet 17.11.2025 16:10:05
SolarWinds Database Performance Analyzer was found to contain a hard-coded cryptographic key. If exploited, this vulnerability could lead to a machine-in-the-middle (MITM) attack against users. This vulnerability requires additional software not inst...
CVE-2023-33231
- EPSS 0.5%
- Veröffentlicht 18.07.2023 17:15:11
- Zuletzt bearbeitet 21.11.2024 08:05:12
XSS attack was possible in DPA 2023.2 due to insufficient input validation
CVE-2023-23837
- EPSS 0.81%
- Veröffentlicht 25.04.2023 18:15:09
- Zuletzt bearbeitet 04.02.2025 17:15:11
No exception handling vulnerability which revealed sensitive or excessive information to users.
CVE-2023-23838
- EPSS 1.27%
- Veröffentlicht 25.04.2023 18:15:09
- Zuletzt bearbeitet 04.02.2025 17:15:11
Directory traversal and file enumeration vulnerability which allowed users to enumerate to different folders of the server.
CVE-2022-38110
- EPSS 0.4%
- Veröffentlicht 20.01.2023 18:15:10
- Zuletzt bearbeitet 21.11.2024 07:15:48
In Database Performance Analyzer (DPA) 2022.4 and older releases, certain URL vectors are susceptible to authenticated reflected cross-site scripting.
CVE-2022-38112
- EPSS 0.42%
- Veröffentlicht 20.01.2023 18:15:10
- Zuletzt bearbeitet 21.11.2024 07:15:49
In DPA 2022.4 and older releases, generated heap memory dumps contain sensitive information in cleartext.
CVE-2021-35229
- EPSS 3.14%
- Veröffentlicht 21.04.2022 19:15:08
- Zuletzt bearbeitet 21.11.2024 06:12:06
Cross-site scripting vulnerability is present in Database Performance Monitor 2022.1.7779 and previous versions when using a complex SQL query
CVE-2021-35228
- EPSS 0.58%
- Veröffentlicht 21.10.2021 18:15:10
- Zuletzt bearbeitet 21.11.2024 06:12:06
This vulnerability occurred due to missing input sanitization for one of the output fields that is extracted from headers on specific section of page causing a reflective cross site scripting attack. An attacker would need to perform a Man in the Mid...
CVE-2018-16243
- EPSS 1.36%
- Veröffentlicht 15.12.2020 23:15:12
- Zuletzt bearbeitet 21.11.2024 03:52:21
SolarWinds Database Performance Analyzer (DPA) 11.1.468 and 12.0.3074 have several persistent XSS vulnerabilities, related to logViewer.iwc, centralManage.cen, userAdministration.iwc, database.iwc, alertManagement.iwc, eventAnnotations.iwc, and centr...