Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2744▼ 71 respecto a la semana anterior
Críticas / altas1416▲ 184 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)106▼ 394 respecto a la semana anterior
20 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.4) | 0.84% | — | Solarwinds Network Performance Monitor | 21/10/2021 | 17/6/2026 | Each authenticated Orion Platform user in a MSP (Managed Service Provider) environment can view and browse all NetPath Services from all that MSP's customers. This can lead to any user having a limited insight into other customer's infrastructure and potential data cross-contamination. | |
| Modificada | Crítica (9.8) | 94% | — | Solarwinds Network Performance Monitor | 21/5/2021 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of SolarWinds Network Performance Monitor 2020.2.1. Authentication is not required to exploit this vulnerability. The specific flaw exists within the SolarWinds.Serialization library. The issue results from the lack of… | |
| Modificada | Alta (8.8) | 5.3% | — | Solarwinds Network Performance Monitor | 12/2/2021 | 17/6/2026 | This vulnerability allows remote attackers to escalate privileges on affected installations of SolarWinds Network Performance Monitor 2020 HF1, NPM: 2020.2. Authentication is required to exploit this vulnerability. The specific flaw exists within the WriteToFile method. The issue results from the lack of proper… | |
| Modificada | Media (5.4) | 1.1% | — | Solarwinds Orion Network Performance MonitorSolarwinds Orion WEB Performance Monitor | 24/6/2020 | 17/6/2026 | Solarwinds Orion (with Web Console WPM 2019.4.1, and Orion Platform HF4 or NPM HF2 2019.4) allows XSS via a name of an alert definition. | |
| Modificada | Media (5.4) | 1.1% | — | Solarwinds Orion Network Performance MonitorSolarwinds Orion WEB Performance Monitor | 24/6/2020 | 17/6/2026 | Solarwinds Orion (with Web Console WPM 2019.4.1, and Orion Platform HF4 or NPM HF2 2019.4) allows XSS via a Responsible Team. | |
| Modificada | Alta (8.8) | 14% | — | Solarwinds Orion Network Performance MonitorSolarwinds Orion WEB Performance Monitor | 24/6/2020 | 17/6/2026 | Solarwinds Orion (with Web Console WPM 2019.4.1, and Orion Platform HF4 or NPM HF2 2019.4) allows remote attackers to execute arbitrary code via a defined event. | |
| Modificada | Media (5.5) | 0.47% | — | Solarwinds NetpathSolarwinds Network Performance MonitorSolarwinds Orion Platform | 4/5/2020 | 17/6/2026 | SolarWinds Orion Platform 2018.4 HF3 (NPM 12.4, NetPath 1.1.4) is vulnerable to Information Leakage, because of improper error handling with stack traces, as demonstrated by discovering a full pathname upon a 500 Internal Server Error via the api2/swis/query?lang=en-us&swAlertOnError=false query parameter. | |
| Modificada | Media (4.8) | 1.1% | — | Solarwinds NetpathSolarwinds Network Performance MonitorSolarwinds Orion Platform | 25/2/2020 | 17/6/2026 | SolarWinds Orion Platform 2018.4 HF3 (NPM 12.4, NetPath 1.1.4) allows Stored HTML Injection by administrators via the Web Console Settings screen. | |
| Modificada | Media (5.4) | 1.4% | — | Solarwinds Network Performance Monitor Orion Platform 2018 NetpathSolarwinds Network Performance Monitor Orion Platform 2018 NPM | 17/2/2020 | 17/6/2026 | SolarWinds Network Performance Monitor (Orion Platform 2018, NPM 12.3, NetPath 1.1.3) allows XSS by authenticated users via a crafted onerror attribute of a VIDEO element in an action for an ALERT. | |
| Modificada | Alta (8.8) | 1.7% | — | Solarwinds Network Performance Monitor | 16/7/2019 | 17/6/2026 | SolarWinds Network Performance Monitor 12.3 allows SQL Injection via the /api/ActiveAlertsOnThisEntity/GetActiveAlerts TriggeringObjectEntityNames parameter. | |
| Modificada | Crítica (9.8) | 36% | — | Solarwinds Orion Network Performance Monitor | 18/2/2019 | 17/6/2026 | SolarWinds Orion NPM before 12.4 suffers from a SYSTEM remote code execution vulnerability in the OrionModuleEngine service. This service establishes a NetTcpBinding endpoint that allows remote, unauthenticated clients to connect and call publicly exposed methods. The InvokeActionMethod method may be abused by an… | |
| Modificada | Media (4.9) | 2.4% | — | Solarwinds Network Performance Monitor | 3/10/2017 | 17/6/2026 | The 'Upload logo from external path' function of SolarWinds Network Performance Monitor version 12.0.15300.90 allows remote attackers to cause a denial of service (permanent display of a "Cannot exit above the top directory" error message throughout the entire web application) via a ".." in the path field. In other… | |
| Modificada | Media (4.8) | 2.8% | — | Solarwinds Network Performance Monitor | 3/10/2017 | 17/6/2026 | Persistent cross-site scripting (XSS) in the Add Node function of SolarWinds Network Performance Monitor version 12.0.15300.90 allows remote attackers to introduce arbitrary JavaScript into various vulnerable parameters. | |
| Modificada | Alta (7.5) | 48% | — | Solarwinds Orion IP Address ManagerSolarwinds Orion Netflow Traffic AnalyzerSolarwinds Orion Network Configuration ManagerSolarwinds Orion Network Performance Monitor+4 | 10/3/2015 | 17/6/2026 | Multiple SQL injection vulnerabilities in the Manage Accounts page in the AccountManagement.asmx service in the Solarwinds Orion Platform 2015.1, as used in Network Performance Monitor (NPM) before 11.5, NetFlow Traffic Analyzer (NTA) before 4.1, Network Configuration Manager (NCM) before 7.3.2, IP Address Manager… | |
| Modificada | Media (4.3) | 7.2% | — | Solarwinds IP Address Manager WEB InterfaceSolarwinds Orion Network Performance Monitor | 31/10/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in IPAMSummaryView.aspx in the IPAM web interface before 3.0-HotFix1 in SolarWinds Orion Network Performance Monitor might allow remote attackers to inject arbitrary web script or HTML via the "Search for an IP address" field. | |
| Modificada | Media (6.8) | 6.0% | — | Solarwinds Orion Network Performance Monitor | 12/8/2012 | 16/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in SolarWinds Orion Network Performance Monitor (NPM) before 10.3.1 allow remote attackers to hijack the authentication of administrators for requests that (1) create user accounts via CreateUserStepContainer actions to Admin/Accounts/Add/OrionAccount.aspx or… | |
| Modificada | Media (4.3) | 10% | — | Solarwinds Orion Network Performance Monitor | 12/8/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in SolarWinds Orion Network Performance Monitor (NPM) before 10.3.1 allow remote attackers to inject arbitrary web script or HTML via the (1) syslocation, (2) syscontact, or (3) sysName field of an snmpd.conf file. | |
| Modificada | Media (4.3) | 5.1% | — | Solarwinds Orion Network Performance Monitor | 24/8/2011 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in SolarWinds Orion Network Performance Monitor (NPM) 10.1 allow remote attackers to inject arbitrary web script or HTML via the (1) Title parameter to MapView.aspx; NetObject parameter to (2) NodeDetails.aspx and (3) InterfaceDetails.aspx; and the (4) ChartName… | |
| Modificada | Alta (10) | 8.5% | — | Ciscoworks Internetwork Performance Monitor | 21/1/2010 | 16/6/2026 | Buffer overflow in Cisco CiscoWorks Internetwork Performance Monitor (IPM) 2.6 and earlier on Windows, as distributed in CiscoWorks LAN Management Solution (LMS), allows remote attackers to execute arbitrary code via a malformed getProcessName CORBA General Inter-ORB Protocol (GIOP) request, related to a "third-party… | |
| Modificada | Alta (10) | 21% | — | Ciscoworks Internetwork Performance Monitor | 14/3/2008 | 16/6/2026 | Cisco CiscoWorks Internetwork Performance Monitor (IPM) 2.6 creates a process that executes a command shell and listens on a randomly chosen TCP port, which allows remote attackers to execute arbitrary commands. |