VendorsSolarwindsserv-uall versions
Vulnerabilities

Solarwinds Serv-U

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

55CVEs
CVE-2020-27994
SolarWinds Serv-U before 15.2.2 allows Authenticated Directory Traversal.
Published 2021-02-03 · Modified
6.5EPSS 0.039
CVE-2018-10241
A denial of service vulnerability in SolarWinds Serv-U before 15.1.6 HFv1 allows an authenticated user to crash the application (with a NULL pointer dereference) via a specially crafted URL beginning with the /Web%20Client/ substring.
Published 2018-05-16 · Modified
6.5EPSS 0.017
CVE-2026-28315
SolarWinds Serv-U Authenticated Stored Cross-site Scripting (XSS) Vulnerability
Published 2026-07-21 · Analyzed
6.2EPSS 0.005
CVE-2020-15575
SolarWinds Serv-U File Server before 15.2.1 allows XSS as demonstrated by Tenable Scan, aka Case Number 00484194.
Published 2020-07-07 · Modified
6.1EPSS 0.015
CVE-2020-15573
SolarWinds Serv-U File Server before 15.2.1 has a "Cross-script vulnerability," aka Case Numbers 00041778 and 00306421.
Published 2020-07-07 · Modified
6.1EPSS 0.015
CVE-2024-28072
Arbitrary File Overwrite Vulnerability
Published 2024-05-03 · Analyzed
5.7EPSS 0.006
CVE-2020-28001
SolarWinds Serv-U before 15.2.2 allows Authenticated Stored XSS.
Published 2021-02-03 · Modified
5.4EPSS 0.038
CVE-2021-32604
Share/IncomingWizard.htm in SolarWinds Serv-U before 15.2.3 mishandles the user-supplied SenderEmail parameter, aka "Share URL XSS."
Published 2021-05-11 · Modified
5.4EPSS 0.017
CVE-2020-35482
SolarWinds Serv-U before 15.2.2 allows authenticated reflected XSS.
Published 2021-02-03 · Modified
5.4EPSS 0.015
CVE-2022-38106
Cross-Site Scripting Vulnerability in Serv-U Web Client
Published 2022-12-16 · Modified
5.4EPSS 0.007
CVE-2024-45712
SolarWinds Serv-U Client-Side Cross-Site Scripting Vulnerability
Published 2025-04-15 · Analyzed
5.4EPSS 0.004
CVE-2021-35247
Improper Input Validation Vulnerability in Serv-U
Published 2022-01-07 · Analyzed
5.3KEVEPSS 0.035
CVE-2023-40053
HTML injection Vulnerability in Serv-U 15.4
Published 2023-12-06 · Modified
5.0EPSS 0.008
CVE-2024-45714
SolarWinds Serv-U Stored XSS Vulnerability
Published 2024-10-16 · Analyzed
4.8EPSS 0.009
CVE-2021-35249
Domain Admin Broken Access Control
Published 2022-05-17 · Modified
4.3EPSS 0.007
← Prev2 / 2