SolarWinds

First CVE: Jul 14, 2021Active for: 5 years
199
CVEs Published
More CVEs Published than 79% of tracked CNAs
33.2
Avg CVEs / Year
More Avg CVEs / Year than 78% of tracked CNAs
7.4
Avg CVSS Score
Higher Avg CVSS Score than 62% of tracked CNAs
4.5%
In CISA KEV
Higher KEV Rate than 96% of tracked CNAs

Self-Reporting Analysis

Of all the CVEs published by SolarWinds as a CNA, 89.9% affect products that SolarWinds develops as a vendor.

89.9%
10.1%
Self-reported: 179Third-party: 20

Of all the CVEs published that affect products developed by SolarWinds, 56.1% are self-published by SolarWinds as a CNA.

56.1%
43.9%
Self-published: 179Published by other CNAs: 140

Trends Over Time

The number and severity of CVEs published by SolarWinds over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 14, 2021
5 years ago
Most Recent CVE
Jul 21, 2026
3 days ago

Top CVEs

All CVEs published by SolarWinds as a CNA, regardless of affected vendor or product.

199 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, which would allow an attacker to r
Jan 28, 20269.898YESYES
SolarWinds Web Help Desk was found to be susceptible to a security control bypass vulnerability that if exploited, could allow an unauthenticated attacker to gain access to certain
Jan 28, 20269.898YESYES
The SolarWinds Web Help Desk (WHD) software is affected by a hardcoded credential vulnerability, allowing remote unauthenticated user to access internal functionality and modify da
Aug 21, 20249.198YESYES
SolarWinds Serv-U was susceptible to a directory transversal vulnerability that would allow access to read sensitive files on the host machine.
Jun 6, 20247.598YESYES
SolarWinds Web Help Desk was found to be susceptible to a Java Deserialization Remote Code Execution vulnerability that, if exploited, would allow an attacker to run commands on th
Aug 13, 20249.897YESYES
SolarWinds Web Help Desk was found to be susceptible to an unauthenticated AjaxProxy deserialization remote code execution vulnerability that, if exploited, would allow an attacker
Sep 23, 20259.896YESNO
Microsoft discovered a remote code execution (RCE) vulnerability in the SolarWinds Serv-U product utilizing a Remote Memory Escape Vulnerability. If exploited, a threat actor may b
Jul 14, 202110.095YESNO
The SolarWinds Security Event Manager was susceptible to Remote Code Execution Vulnerability. This vulnerability allows an unauthenticated user to abuse SolarWinds’ service, result
Mar 1, 20248.885NOYES
SolarWinds Serv-U is susceptible to specially crafted POST requests that crash the Serv-U service without authentication using Content-Encoding: deflate. Mitigation steps are provi
Jun 4, 20267.582YESNO
SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that, if exploited, could allow an attacker to invoke specific actions within Web Hel
Jan 28, 20269.879NOYES

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA199 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local18 (9.0%)
Network136 (68.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network45 (22.6%)
Attack Complexity
Low189 (95.0%)
High10 (5.0%)
Unknown0 (0.0%)
User Interaction
None169 (84.9%)
Unknown0 (0.0%)
Required30 (15.1%)
Privileges Required
Low72 (36.2%)
High60 (30.2%)
None67 (33.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (199 CVEs).

CISA KEV
9 CVEs
4.5% of CVEs· 96th percentile
Metasploit
5 CVEs
2.5% of CVEs· 93rd percentile
Nuclei
9 CVEs
4.5% of CVEs· 92nd percentile
ExploitDB
2 CVEs
1.0% of CVEs· 82nd percentile

Social Chatter

An overview of all social media posts that mention a CVE ID published by SolarWinds as a CNA.

Media Mentions

Media articles that mention a CVE ID published by SolarWinds as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs