Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

SolarWinds — Vulnerabilities & Security Advisories 166

Browse all 166 CVE security advisories affecting SolarWinds. AI-powered Chinese analysis, POCs, and references for each vulnerability.

SolarWinds provides IT management and monitoring software, primarily serving enterprise networks through its Orion platform. Historically, its applications have exhibited vulnerabilities typical of complex enterprise suites, including remote code execution, cross-site scripting, and privilege escalation flaws. These weaknesses often stem from intricate integration points and legacy codebases. The most significant security incident occurred in 2020, when a supply chain attack compromised the software’s update mechanism, allowing threat actors to insert malicious code into legitimate updates. This breach affected numerous government agencies and private corporations, exposing sensitive data and compromising network integrity. The incident highlighted critical risks in software supply chains and led to widespread scrutiny of the company’s development and security practices. Consequently, SolarWinds has implemented stricter security controls and transparency measures to restore trust and mitigate future risks associated with its widely deployed infrastructure tools.

Found 18 results / 166Clear Filters
CVE IDTitleCVSSSeverityPublished
CVE-2022-36965 Stored and DOM XSS in QoE Applications: Orion Platform — Orion Platform 6.1 Medium2022-09-30
CVE-2022-36961 Orion Platform SQL Injection Privilege Escalation Vulnerability — Orion PlatformCWE-89 8.8 High2022-09-30
CVE-2021-35244 Unrestricted File Upload Causing Remote Code Execution: Orion Platform 2020.2.6 — Orion Platform 6.8 Medium2021-12-20
CVE-2021-35217 Insecure Deserialization of untrusted data causing Remote code execution vulnerability. — Orion Platform 8.9 High2021-09-08
CVE-2021-35215 ActionPluginBaseView Deserialization of Untrusted Data RCE — Orion PlatformCWE-502 8.9 High2021-09-01
CVE-2021-35238 Stored XSS through URL POST parameter in CreateExternalWebsite Vulnerability — Orion PlatformCWE-79 4.8 Medium2021-09-01
CVE-2021-35212 Blind SQL injection Vulnerability — Orion Platform 8.9 High2021-08-31
CVE-2021-35213 Orion User setting Improper Access Control Privilege Escalation Vulnerability — Orion PlatformCWE-284 8.9 High2021-08-31
CVE-2021-35240 Stored XSS via Help Server settings — Orion PlatformCWE-79 6.5 Medium2021-08-31
CVE-2021-35239 Stored XSS in Maps text box hyperlink Vulnerability — Orion PlatformCWE-79 7.5 High2021-08-31
CVE-2021-35222 Resource.aspx Reflected Cross-Site Scripting Vulnerability — Orion PlatformCWE-79 8.0 High2021-08-31
CVE-2021-35221 ImportAlert Improper Access Control Tampering Vulnerability — Orion PlatformCWE-284 6.3 Medium2021-08-31
CVE-2021-35220 EmailWebPage Command Injection RCE — Orion Platform 8.1 High2021-08-31
CVE-2021-35219 ExportToPdfCmd Arbitrary File Read Information Disclosure Vulnerability — Orion Platform 6.0 Medium2021-08-31
CVE-2021-27258 Solarwinds Orion Platform 安全漏洞 — Orion PlatformCWE-284 9.8 -2021-04-14
CVE-2020-27871 Solarwinds SolarWinds Orion Platform 路径遍历漏洞 — Orion PlatformCWE-22 8.8 -2021-02-10
CVE-2020-27870 Solarwinds SolarWinds Orion Platform 路径遍历漏洞 — Orion PlatformCWE-22 6.5 -2021-02-10
CVE-2020-10148 SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands — Orion PlatformCWE-288 9.8 -2020-12-29

This page lists every published CVE security advisory associated with SolarWinds. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.