İçeriğe atla
Noroxi

connectwise kayıtları

connectwise üreticisine ait 39 yayımlanmış kayıt.

Tüm kayıtlar

39 kayıt
  • Authentication bypass using an alternate path or channel

    KritikCVSS 10,0KEVSilahlaştırılmışEPSS %100

    connectwise · screenconnect21 Şub 2024

  • ConnectWise ManagedITSync integration through 2017 for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct ac

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %87

    connectwise · manageditsync5 Şub 2019

  • Improper limitation of a pathname to a restricted directory (“path traversal”)

    YüksekCVSS 8,4KEVSilahlaştırılmışEPSS %95

    connectwise · screenconnect21 Şub 2024

  • CVE-2026-84869
    69Bu hafta

    ScreenConnect Client: Guest-to-Host File Execution via File-Transfer Actions

    KritikCVSS 9,9KEVSilahlaştırılmışEPSS %1

    connectwise · screenconnect8 Eyl 2026

  • CVE-2025-3935
    59Planlayın

    ScreenConnect Exposure to ASP.NET ViewState Code Injection

    YüksekCVSS 7,2KEVSilahlaştırılmışEPSS %4

    connectwise · screenconnect25 Nis 2025

  • CVE-2020-15027
    39İzleyin

    ConnectWise Automate through 2020.x has insufficient validation on certain authentication paths, allowing authentication bypass via a series

    KritikCVSS 9,8İstismar yokEPSS %1

    connectwise · automate16 Tem 2020

  • CVE-2019-16517
    39İzleyin

    An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185.

    KritikCVSS 9,8İstismar yokEPSS %1

    connectwise · control23 Oca 2020

  • CVE-2021-35066
    39İzleyin

    An XXE vulnerability exists in ConnectWise Automate before 2021.0.6.132.

    KritikCVSS 9,8İstismar yokEPSS %1

    connectwise · automate21 Haz 2021

  • CVE-2023-25718
    39İzleyin

    In ConnectWise Control through 22.9.10032 (formerly known as ScreenConnect), after an executable file is signed, additional instructions can

    KritikCVSS 9,8İstismar yokEPSS %1

    connectwise · control13 Şub 2023

  • CVE-2020-14159
    36İzleyin

    By using an Automate API in ConnectWise Automate before 2020.5.178, a remote authenticated user could execute commands and/or modifications

    YüksekCVSS 8,8İstismar yokEPSS %2

    connectwise · automate api15 Haz 2020

  • CVE-2025-14265
    36İzleyin

    Improper server-side validation in ScreenConnect extension framework

    KritikCVSS 9,1İstismar yokEPSS %0

    connectwise · screenconnect11 Ara 2025

  • CVE-2020-15838
    35İzleyin

    The Agent Update System in ConnectWise Automate before 2020.8 allows Privilege Escalation because the _LTUPDATE folder has weak permissions.

    YüksekCVSS 8,8İstismar yokEPSS %1

    connectwise · automate9 Eki 2020

  • CVE-2023-25719
    35İzleyin

    ConnectWise Control before 22.9.10032 (formerly known as ScreenConnect) fails to validate user-supplied parameters such as the Bin/ConnectWi

    YüksekCVSS 8,8İstismar yokEPSS %1

    connectwise · control13 Şub 2023

  • CVE-2019-16513
    35İzleyin

    An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185.

    YüksekCVSS 8,8İstismar yokEPSS %1

    connectwise · control23 Oca 2020

  • CVE-2017-11726
    35İzleyin

    services/system_io/actionprocessor/System.rails in ConnectWise Manage 2017.5 is vulnerable to Cross-Site Request Forgery (CSRF), as demonstr

    YüksekCVSS 8,8İstismar yokEPSS %0

    connectwise · manage31 Tem 2017

  • CVE-2026-9089
    35İzleyin

    The ConnectWise Automate™ Agent does not fully verify the authenticity of components obtained during plugin loading and self-update operatio

    YüksekCVSS 8,8İstismar yokEPSS %0

    connectwise · automate21 May 2026

  • CVE-2023-47257
    32İzleyin

    ConnectWise ScreenConnect through 23.8.4 allows man-in-the-middle attackers to achieve remote code execution via crafted messages.

    YüksekCVSS 8,1İstismar yokEPSS %1

    connectwise · automate1 Şub 2024

  • CVE-2021-32582
    30İzleyin

    An issue was discovered in ConnectWise Automate before 2021.5.

    YüksekCVSS 7,5İstismar yokEPSS %1

    connectwise · connectwise automate17 Haz 2021

  • CVE-2020-15008
    30İzleyin

    A SQLi exists in the probe code of all Connectwise Automate versions before 2020.7 or 2019.12.

    YüksekCVSS 7,5İstismar yokEPSS %1

    connectwise · connectwise automate7 Tem 2020

  • CVE-2025-11493
    30İzleyin

    Self-Update Verification Mechanism Process in ConnectWise Automate

    YüksekCVSS 7,5İstismar yokEPSS %0

    connectwise · automate16 Eki 2025

  • CVE-2025-11492
    30İzleyin

    HTTP Configuration and Encryption in Transit

    YüksekCVSS 7,5Kavram kanıtıEPSS %0

    connectwise · automate16 Eki 2025

  • CVE-2019-16514
    29İzleyin

    An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185.

    YüksekCVSS 7,2İstismar yokEPSS %4

    connectwise · control23 Oca 2020

  • CVE-2026-6066
    28İzleyin

    Unencrypted Client‑Server Communication in ConnectWise Automate™ Solution Center

    YüksekCVSS 7,1İstismar yokEPSS %0

    connectwise · automate20 Nis 2026

  • CVE-2019-16516
    27İzleyin

    An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185.

    OrtaCVSS 5,3Kavram kanıtıEPSS %19

    connectwise · control23 Oca 2020

  • CVE-2019-16515
    27İzleyin

    An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185.

    OrtaCVSS 6,5İstismar yokEPSS %2

    connectwise · control23 Oca 2020