CVE-2024-29003
- EPSS 0.07%
- Veröffentlicht 18.04.2024 10:15:08
- Zuletzt bearbeitet 10.02.2025 22:43:26
The SolarWinds Platform was susceptible to a XSS vulnerability that affects the maps section of the user interface. This vulnerability requires authentication and requires user interaction.
CVE-2024-29001
- EPSS 0.06%
- Veröffentlicht 18.04.2024 09:15:11
- Zuletzt bearbeitet 10.02.2025 22:42:27
A SolarWinds Platform SWQL Injection Vulnerability was identified in the user interface. This vulnerability requires authentication and user interaction to be exploited.
CVE-2024-28076
- EPSS 0.03%
- Veröffentlicht 18.04.2024 09:15:11
- Zuletzt bearbeitet 10.02.2025 22:41:22
The SolarWinds Platform was susceptible to a Arbitrary Open Redirection Vulnerability. A potential attacker can redirect to different domain when using URL parameter with relative entry in the correct format
- EPSS 0.87%
- Veröffentlicht 06.02.2024 16:15:51
- Zuletzt bearbeitet 21.11.2024 08:36:57
SQL Injection Remote Code Execution Vulnerability was found using an update statement in the SolarWinds Platform. This vulnerability requires user authentication to be exploited
- EPSS 1%
- Veröffentlicht 06.02.2024 16:15:51
- Zuletzt bearbeitet 21.11.2024 08:08:07
SQL Injection Remote Code Execution Vulnerability was found using a create statement in the SolarWinds Platform. This vulnerability requires user authentication to be exploited.
CVE-2023-40056
- EPSS 0.1%
- Veröffentlicht 28.11.2023 18:15:07
- Zuletzt bearbeitet 21.11.2024 08:18:37
SQL Injection Remote Code Vulnerability was found in the SolarWinds Platform. This vulnerability can be exploited with a low privileged account.
CVE-2023-40062
- EPSS 2.41%
- Veröffentlicht 01.11.2023 16:15:08
- Zuletzt bearbeitet 21.11.2024 08:18:37
SolarWinds Platform Incomplete List of Disallowed Inputs Remote Code Execution Vulnerability. If executed, this vulnerability would allow a low-privileged user to execute commands with SYSTEM privileges.
CVE-2023-40061
- EPSS 0.08%
- Veröffentlicht 01.11.2023 16:15:08
- Zuletzt bearbeitet 21.11.2024 08:18:37
Insecure job execution mechanism vulnerability. This vulnerability can lead to other attacks as a result.
CVE-2023-3622
- EPSS 0.07%
- Veröffentlicht 26.07.2023 15:15:10
- Zuletzt bearbeitet 21.11.2024 08:17:41
Access Control Bypass Vulnerability in the SolarWinds Platform that allows an underprivileged user to read arbitrary resource
CVE-2023-33229
- EPSS 0.8%
- Veröffentlicht 26.07.2023 15:15:10
- Zuletzt bearbeitet 21.11.2024 08:05:11
The SolarWinds Platform was susceptible to the Incorrect Input Neutralization Vulnerability. This vulnerability allows a remote adversary with a valid SolarWinds Platform account to append URL parameters to inject passive HTML.