SolarWinds / Webhelpdesk
8 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2024-28987 KEV | SolarWinds Web Help Desk Hardcoded Credential Vulnerability | CRITICAL | 9.1 | Aug 21, 2024 |
| CVE-2024-28986 KEV | SolarWinds Web Help Desk Java Deserialization Remote Code Execution Vulnerability | CRITICAL | 9.8 | Aug 13, 2024 |
| CVE-2021-35254 | Authenticated Remote Code Execution in WebHelpDesk 12.7.8 | HIGH | 8.8 | Mar 25, 2022 |
| CVE-2021-35232 | Hard credentials discovered in SolarWinds Web Help Desk which allows to execute Arbitrary Hibernate Queries | MEDIUM | 6.8 | Dec 27, 2021 |
| CVE-2019-16959 | SolarWinds Web Help Desk 12.7.0 allows CSV Injection, also known as Formula Injection, via a file attached to a ticket. | MEDIUM | 6.5 | Dec 21, 2020 |
| CVE-2019-16955 | SolarWinds Web Help Desk 12.7.0 allows XSS via an uploaded SVG document in a request. | MEDIUM | 5.4 | Dec 18, 2020 |
| CVE-2019-16957 | SolarWinds Web Help Desk 12.7.0 allows XSS via the First Name field of a User Account. | MEDIUM | 5.4 | Dec 18, 2020 |
| CVE-2019-20002 | Formula Injection exists in the export feature in SolarWinds WebHelpDesk 12.7.1 via a value (provided by a low-privileged user in the Subject field of a help r… | HIGH | 7.8 | Apr 27, 2020 |
Showing 1 to 8 of 8 CVEs