VendorsSolarwindsdatabase_performance_analyzerall versions
Vulnerabilities

Solarwinds Database Performance Analyzer

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10CVEs
CVE-2023-23837
No Exception Handling Vulnerability: Database Performance Analyzer (DPA) 2023.1
Published 2023-04-25 · Modified
7.5EPSS 0.008
CVE-2022-38112
Sensitive Information Disclosure Vulnerability
Published 2023-01-20 · Modified
7.5EPSS 0.004
CVE-2021-35229
Cross-Site Scripting Vulnerability using SQL Query
Published 2022-04-21 · Modified
6.8EPSS 0.032
CVE-2023-23838
Directory traversal and file enumeration vulnerability: Database Performance Analyzer (DPA) 2023.1
Published 2023-04-25 · Modified
6.5EPSS 0.013
CVE-2025-26398
SolarWinds Database Performance Analyzer Hard-coded Cryptographic Key Vulnerability
Published 2025-08-12 · Analyzed
6.4EPSS 0.002
CVE-2018-19386
SolarWinds Database Performance Analyzer 11.1.457 contains an instance of Reflected XSS in its idcStateError component, where the page parameter is reflected into the HREF of the 'Try Again' Button on the page, aka a /iwc/idcStateError.iwc?page= URI.
Published 2019-08-14 · Modified
6.1EPSS 0.090
CVE-2023-33231
XSS in SolarWinds Database Performance Analyzer 2023.2
Published 2023-07-18 · Modified
6.1EPSS 0.005
CVE-2021-35228
Reflected cross site scripting affecting SolarWinds: DPA 2021.3.7388
Published 2021-10-21 · Modified
5.5EPSS 0.006
CVE-2018-16243
SolarWinds Database Performance Analyzer (DPA) 11.1.468 and 12.0.3074 have several persistent XSS vulnerabilities, related to logViewer.iwc, centralManage.cen, userAdministration.iwc, database.iwc, alertManagement.iwc, eventAnnotations.iwc, and central.cen.
Published 2020-12-15 · Modified
5.4EPSS 0.014
CVE-2022-38110
Reflected Cross-Site Scripting Vulnerability
Published 2023-01-20 · Modified
5.4EPSS 0.004