361,800
Total CVEs
26,223
Critical
85,816
High
1,626
CISA KEV
0
This Week
81 results · Page 2/4
Insecure Deserialization of untrusted data remote code execution vulnerability was discovered in Patch Manager Orion Platform Integration module. An Authenticated Attacker with network access via HTTP can compromise this vulnerability can result in Remote Code Execution.
solarwinds
Insecure deserialization leading to Remote Code Execution was detected in the Orion Platform version 2020.2.5. Authentication is required to exploit this vulnerability.
solarwinds
User with Orion Platform Admin Rights could store XSS through URL POST parameter in CreateExternalWebsite website.
solarwinds
An SQL injection Privilege Escalation Vulnerability was discovered in the Orion Platform reported by the ZDI Team. A blind Boolean SQL injection which could lead to full read/write over the Orion database content including the Orion certificate for any authenticated user.
solarwinds