Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

SolarWinds — Vulnerabilities & Security Advisories 166

Browse all 166 CVE security advisories affecting SolarWinds. AI-powered Chinese analysis, POCs, and references for each vulnerability.

SolarWinds provides IT management and monitoring software, primarily serving enterprise networks through its Orion platform. Historically, its applications have exhibited vulnerabilities typical of complex enterprise suites, including remote code execution, cross-site scripting, and privilege escalation flaws. These weaknesses often stem from intricate integration points and legacy codebases. The most significant security incident occurred in 2020, when a supply chain attack compromised the software’s update mechanism, allowing threat actors to insert malicious code into legitimate updates. This breach affected numerous government agencies and private corporations, exposing sensitive data and compromising network integrity. The incident highlighted critical risks in software supply chains and led to widespread scrutiny of the company’s development and security practices. Consequently, SolarWinds has implemented stricter security controls and transparency measures to restore trust and mitigate future risks associated with its widely deployed infrastructure tools.

Found 15 results / 166Clear Filters
CVE IDTitleCVSSSeverityPublished
CVE-2025-40541 SolarWinds Serv-U Insecure Direct Object Reference (IDOR) Remote Code Execution Vulnerability — Serv-UCWE-704 9.1 Critical2026-02-24
CVE-2025-40540 SolarWinds Serv-U Type Confusion Remote Code Execution Vulnerability — Serv-UCWE-704 9.1 Critical2026-02-24
CVE-2025-40539 SolarWinds Serv-U Type Confusion Remote Code Execution Vulnerability — Serv-UCWE-704 9.1 Critical2026-02-24
CVE-2025-40538 SolarWinds Serv-U Broken Access Control Remote Code Execution Vulnerability — Serv-UCWE-269 9.1 Critical2026-02-24
CVE-2025-40549 SolarWinds Serv-U Path Restriction Bypass Vulnerability — Serv-UCWE-22 9.1 Critical2025-11-18
CVE-2025-40548 SolarWinds Serv-U Broken Access Control - Remote Code Execution Vulnerability — Serv-UCWE-269 9.1 Critical2025-11-18
CVE-2025-40547 SolarWinds Serv-U Logic Abuse - Remote Code Execution Vulnerability — Serv-UCWE-116 9.1 Critical2025-11-18
CVE-2024-45712 SolarWinds Serv-U Client-Side Cross-Site Scripting Vulnerability — Serv-UCWE-79 2.6 Low2025-04-15
CVE-2024-45711 SolarWinds Serv-U FTP Service Directory Traversal Remote Code Execution Vulnerability — Serv-UCWE-22 7.5 High2024-10-16
CVE-2024-45714 SolarWinds Serv-U Stored XSS Vulnerability — Serv-UCWE-79 4.8 Medium2024-10-16
CVE-2023-40053 HTML injection Vulnerability in Serv-U 15.4 — Serv-UCWE-20 5.0 Medium2023-12-06
CVE-2021-35249 Domain Admin Broken Access Control — Serv-UCWE-284 4.3 Medium2022-05-17
CVE-2021-35250 Directory Transversal Vulnerability in Serv-U 15.3 — Serv-UCWE-22 7.5 High2022-04-25
CVE-2021-35247 Improper Input Validation Vulnerability in Serv-U — Serv-UCWE-20 4.3 Medium2022-01-07
CVE-2021-35223 Execute Command Function Allows Remote Code Execution (RCE)Vulnerability — Serv-UCWE-20 8.5 High2021-08-31

This page lists every published CVE security advisory associated with SolarWinds. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.