Webhelpdesk

Vendor:

First CVE: Apr 27, 2020 · Active for 6 years

27
Total CVEs
More Total CVEs than 80% of tracked products
4.5
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
7.4
Avg CVSS
Higher Avg CVSS than 34% of tracked products
18.5%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Webhelpdesk over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 27, 2020
6 years ago
Most Recent CVE
Jun 2, 2026
54 days ago

CVE Severity & Scoring

Webhelpdesk27 CVEs
All CVEs352,719 CVEs
MediumHighCritical
Attack Vector
Local4 (14.8%)
Network23 (85.2%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low26 (96.3%)
High1 (3.7%)
Unknown0 (0.0%)
User Interaction
None20 (74.1%)
Unknown0 (0.0%)
Required7 (25.9%)
Privileges Required
Low13 (48.1%)
High0 (0.0%)
None14 (51.9%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (27 CVEs).

27 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, which would allow an attacker to r
Jan 28, 20269.898YESYES
The SolarWinds Web Help Desk (WHD) software is affected by a hardcoded credential vulnerability, allowing remote unauthenticated user to access internal functionality and modify da
Aug 21, 20249.198YESYES
SolarWinds Web Help Desk was found to be susceptible to a security control bypass vulnerability that if exploited, could allow an unauthenticated attacker to gain access to certain
Jan 28, 20269.897YESYES
SolarWinds Web Help Desk was found to be susceptible to a Java Deserialization Remote Code Execution vulnerability that, if exploited, would allow an attacker to run commands on th
Aug 13, 20249.897YESYES
SolarWinds Web Help Desk was found to be susceptible to an unauthenticated AjaxProxy deserialization remote code execution vulnerability that, if exploited, would allow an attacker
Sep 23, 20259.896YESNO
SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that, if exploited, could allow an attacker to invoke specific actions within Web Hel
Jan 28, 20269.878NOYES
SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that if exploited, would allow a malicious actor to execute actions and methods that
Jan 28, 20269.874NOYES
SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, which would allow an attacker to r
Jan 28, 20269.871NONO
SolarWinds Web Help Desk was found to be susceptible to a Java Deserialization Remote Code Execution vulnerability that, if exploited, would allow an attacker to run commands on th
Sep 1, 20259.856NONO
SolarWinds Web Help Desk is found to be affected by a denial-of-service vulnerability, which when exploited, could cause the Web Help Desk server to crash due to insufficient memor
Jun 2, 20268.236NONO

Exploit Exposure

Signals from CVEs in this product scope (27 CVEs).

CISA KEV
5 CVEs
18.5% of CVEs· Bottom 1%
Metasploit
3 CVEs
11.1% of CVEs· Bottom 1%
Nuclei
6 CVEs
22.2% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (27 CVEs).

Media Mentions

Signals from CVEs in this product scope (27 CVEs).

Top CNAs Publishing CVEs For Webhelpdesk

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
12.8.719.888.3%10
12.8.339.663.5%22
12.7.818.81.0%00
12.7.117.81.3%00
12.7.075.61.5%00