Vulnerabilities
Vulnerable Software
Security Vulnerabilities
HCL IEM was affected with X-Content-Type-Options Header Missing. It may enable attackers to perform SSL stripping or man-in-the-middle attacks and intercept sensitive data.
CVSS Score
3.1
EPSS Score
0.001
Published
2026-07-21
HCL IEM was affected with the Anti Clickjacking XFrame Options Header Missing. It may allow attackers to embed the application in malicious pages and induce unauthorized user actions.
CVSS Score
3.1
EPSS Score
0.001
Published
2026-07-21
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation. This issue requires domain administrator access. The impact is lower in Windows deployments.
CVSS Score
9.1
EPSS Score
0.003
Published
2026-07-21
SolarWinds Serv-U is affected by a broken access control vulnerability that could allow arbitrary file read and write, which can then be used to escalate privileges and execute code as root. A domain administrator access is required, and the impact is lower in Windows installations.
CVSS Score
9.1
EPSS Score
0.004
Published
2026-07-21
SolarWinds Serv-U is affected by a privilege escalation vulnerability. This would elevate a group’s access to system administrator and allow code execution as root. The impact is lower in Windows deployments.
CVSS Score
9.1
EPSS Score
0.004
Published
2026-07-21
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to SMTP hijacking leading to arbitrary account takeover. The impact is lower in Windows deployments.
CVSS Score
9.1
EPSS Score
0.003
Published
2026-07-21
SolarWinds Serv-U is affected by an insecure direct object reference vulnerability that leads to an account takeover. User authentication is required. The impact is lower in Windows deployments.
CVSS Score
9.1
EPSS Score
0.004
Published
2026-07-21
SolarWinds Serv-U was found to be affected by a stored cross-site scripting vulnerability that could lead to session hijacking or information disclosure from an administrator account.
CVSS Score
6.2
EPSS Score
0.003
Published
2026-07-21
SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation to a system administrator with the ability to execute commands as the root user. This issue requires a domain account with administrator access. The impact is lower in Windows deployments.
CVSS Score
9.1
EPSS Score
0.013
Published
2026-07-21
SolarWinds Serv-U is affected by a remote code execution vulnerability that, when exploited, can allow the arbitrary execution of code remotely as root. The impact is lower in Windows deployments.
CVSS Score
9.1
EPSS Score
0.005
Published
2026-07-21


Contact Us

Shodan ® - All rights reserved