solarwinds database_performance_analyzer の CVE(10 件)

CVE 件数: 10 CPE versions: View versions table

概要

本ページは solarwinds database_performance_analyzer に影響する公開済み CVE(NVD の CPE 経由で関連付け)を列挙します。各行に深刻度指標・概要・公開日が含まれます。

表示中 110 / 10 CVE 件数
«« 先頭 « 前へ 1 / 1 次へ »
CVE 概要 ソース CVSS 最大値 EPSS(%) 公開 更新
CVE-2025-26398 SolarWinds Database Performance Analyzer was found to contain a hard-coded cryptographic key. If exploited, this vulnerability could lead to a machine-in-the-middle (MITM) attack against users. This vulnerability requires additional software not installed by default, local access to the server and administrator level privileges on the host. [email protected] 5.6 0.17% 2025-08-12 2025-11-17
CVE-2023-33231 XSS attack was possible in DPA 2023.2 due to insufficient input validation [email protected] 6.1 0.49% 2023-07-18 2024-11-21
CVE-2023-23838 Directory traversal and file enumeration vulnerability which allowed users to enumerate to different folders of the server. [email protected] 6.5 1.27% 2023-04-25 2025-02-04
CVE-2023-23837 No exception handling vulnerability which revealed sensitive or excessive information to users. [email protected] 7.5 0.81% 2023-04-25 2025-02-04
CVE-2022-38112 In DPA 2022.4 and older releases, generated heap memory dumps contain sensitive information in cleartext. [email protected] 7.5 0.41% 2023-01-20 2024-11-21
CVE-2022-38110 In Database Performance Analyzer (DPA) 2022.4 and older releases, certain URL vectors are susceptible to authenticated reflected cross-site scripting. [email protected] 5.4 0.40% 2023-01-20 2024-11-21
CVE-2021-35229 Cross-site scripting vulnerability is present in Database Performance Monitor 2022.1.7779 and previous versions when using a complex SQL query [email protected] 6.8 2.98% 2022-04-21 2024-11-21
CVE-2021-35228 This vulnerability occurred due to missing input sanitization for one of the output fields that is extracted from headers on specific section of page causing a reflective cross site scripting attack. An attacker would need to perform a Man in the Middle attack in order to change header for a remote victim. [email protected] 5.5 0.56% 2021-10-21 2024-11-21
CVE-2018-16243 SolarWinds Database Performance Analyzer (DPA) 11.1.468 and 12.0.3074 have several persistent XSS vulnerabilities, related to logViewer.iwc, centralManage.cen, userAdministration.iwc, database.iwc, alertManagement.iwc, eventAnnotations.iwc, and central.cen. [email protected] 5.4 1.36% 2020-12-15 2024-11-21
CVE-2018-19386 SolarWinds Database Performance Analyzer 11.1.457 contains an instance of Reflected XSS in its idcStateError component, where the page parameter is reflected into the HREF of the 'Try Again' Button on the page, aka a /iwc/idcStateError.iwc?page= URI. [email protected] 6.1 9.08% 2019-08-14 2024-11-21
«« 先頭 « 前へ 1 / 1 次へ »
cvelogic Threat Intelligence