Database Performance Analyzer
Vendor:
First CVE: Aug 14, 2019 · Active for 6 years
10
Total CVEs
More Total CVEs than 88% of tracked products
1.7
Avg CVEs / Year
Higher CVE frequency than 59% of tracked products
6.2
Avg CVSS
Higher Avg CVSS than 24% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Database Performance Analyzer over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 14, 2019
6 years ago
Most Recent CVE
Aug 12, 2025
347 days ago
CVE Severity & Scoring
Database Performance Analyzer10 CVEs
80%
20%
All CVEs352,427 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local1 (10.0%)
Network9 (90.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (80.0%)
High2 (20.0%)
Unknown0 (0.0%)
User Interaction
None4 (40.0%)
Unknown0 (0.0%)
Required6 (60.0%)
Privileges Required
Low3 (30.0%)
High1 (10.0%)
None6 (60.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-19386MEDIUM SolarWinds Database Performance Analyzer 11.1.457 contains an instance of Reflected XSS in its idcStateError component, where the page parameter is reflected into the HREF of the ' | Aug 14, 2019 | 6.1 | 32 | NO | YES |
CVE-2022-38112HIGH In DPA 2022.4 and older releases, generated heap memory dumps contain sensitive information in cleartext.
| Jan 20, 2023 | 7.5 | 25 | NO | NO |
CVE-2023-23837HIGH No exception handling vulnerability which revealed sensitive or excessive information to users.
| Apr 25, 2023 | 7.5 | 23 | NO | NO |
CVE-2021-35229MEDIUM Cross-site scripting vulnerability is present in Database Performance Monitor 2022.1.7779 and previous versions when using a complex SQL query | Apr 21, 2022 | 6.1 | 23 | NO | NO |
CVE-2025-26398MEDIUM SolarWinds Database Performance Analyzer was found to contain a hard-coded cryptographic key. If exploited, this vulnerability could lead to a machine-in-the-middle (MITM) attack a | Aug 12, 2025 | 6.4 | 22 | NO | NO |
CVE-2023-23838MEDIUM Directory traversal and file enumeration vulnerability which allowed users to enumerate to different folders of the server.
| Apr 25, 2023 | 6.5 | 22 | NO | NO |
CVE-2023-33231MEDIUM XSS attack was possible in DPA 2023.2 due to insufficient input validation | Jul 18, 2023 | 6.1 | 20 | NO | NO |
CVE-2022-38110MEDIUM In Database Performance Analyzer (DPA) 2022.4 and older releases, certain URL vectors are susceptible to authenticated reflected cross-site scripting.
| Jan 20, 2023 | 5.4 | 20 | NO | NO |
CVE-2018-16243MEDIUM SolarWinds Database Performance Analyzer (DPA) 11.1.468 and 12.0.3074 have several persistent XSS vulnerabilities, related to logViewer.iwc, centralManage.cen, userAdministration.i | Dec 15, 2020 | 5.4 | 19 | NO | NO |
CVE-2021-35228MEDIUM This vulnerability occurred due to missing input sanitization for one of the output fields that is extracted from headers on specific section of page causing a reflective cross sit | Oct 21, 2021 | 4.7 | 18 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (10 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
10.0% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (10 CVEs).
Media Mentions
Signals from CVEs in this product scope (10 CVEs).
Top CNAs Publishing CVEs For Database Performance Analyzer
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2021.3.7388 | 1 | 4.7 | 0.6% | 0 | 0 |
| 12.0.3074 | 1 | 5.4 | 1.4% | 0 | 0 |
| 11.1.468 | 1 | 5.4 | 1.4% | 0 | 0 |
| 11.1.457 | 1 | 6.1 | 9.0% | 0 | 1 |