Network Configuration Manager
11 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Network Configuration Manager, a product in the enterprise software space. Use it to gauge the current risk picture and drill into individual advisories.
Network Configuration Manager CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 1 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 11 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical1
- High6
- Medium4
Latest CVEs
The 11 most recently published vulnerabilities affecting Network Configuration Manager.
- CVE-2025-41437Reflected XSS4.3
- CVE-2023-47211A directory traversal vulnerability exists in the uploadMib functionality of ManageEngine OpManager 12.7.258. A specially crafted HTTP request can lead to arbitrary file creation. An attacker can s...9.1
- CVE-2023-40055SolarWinds Network Configuration Manager Directory Traversal Remote Code Execution Vulnerability8.0
- CVE-2023-40054SolarWinds Network Configuration Manager Directory Traversal Remote Code Execution Vulnerability8.0
- CVE-2023-33228SolarWinds Network Configuration Manager Sensitive Information Disclosure Vulnerability4.5
- CVE-2023-33227Directory Traversal Remote Code Execution Vulnerability8.0
- CVE-2023-33226Directory Traversal Remote Code Execution Vulnerability8.0
- CVE-2023-23842SolarWinds Network Configuration Manager Directory Traversal Vulnerability7.2
- CVE-2021-35226Hashed Credential Exposure Vulnerability6.5
- CVE-2022-37024Zoho ManageEngine OpManager, OpManager Plus, OpManager MSP, Network Configuration Manager, NetFlow Analyzer, and OpUtils before 2022-07-29 through 2022-07-30 ( 125658, 126003, 126105, and 126120) a...8.8
- CVE-2014-3459Heap-based buffer overflow in SolarWinds Network Configuration Manager (NCM) before 7.3 allows remote attackers to execute arbitrary code via the PEstrarg1 property.6.8
Product grouping is registry-driven, with AI assist and human review. How it works