connectwise kayıtları
connectwise üreticisine ait 39 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 5 · %12,8
- Silahlaştırılmış
- 5 · %12,8
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %10,3
- Yayından KEV’e ortanca
- 38 gün
Tekrar eden sınıflar
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')4
- CWE-494 Download of Code Without Integrity Check3
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-319 Cleartext Transmission of Sensitive Information3
- CWE-201 Insertion of Sensitive Information Into Sent Data2
- CWE-352 Cross-Site Request Forgery (CSRF)2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
39 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
100Hemen | CVE-2024-1709Silahlaştırılmış | Authentication bypass using an alternate path or channelconnectwise · screenconnect · CWE-288 | Kritik10,0 | KEV | %100,0 | 21 Şub 2024 |
95Hemen | CVE-2017-18362Silahlaştırılmış | ConnectWise ManagedITSync integration through 2017 for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct acconnectwise · manageditsync · CWE-89 | Kritik9,8 | KEV | %86,8 | 5 Şub 2019 |
92Hemen | CVE-2024-1708Silahlaştırılmış | Improper limitation of a pathname to a restricted directory (“path traversal”)connectwise · screenconnect · CWE-22 | Yüksek8,4 | KEV | %95,4 | 21 Şub 2024 |
69Bu hafta | CVE-2026-84869Silahlaştırılmış | ScreenConnect Client: Guest-to-Host File Execution via File-Transfer Actionsconnectwise · screenconnect · CWE-269 | Kritik9,9 | KEV | %0,9 | 8 Eyl 2026 |
59Planlayın | CVE-2025-3935Silahlaştırılmış | ScreenConnect Exposure to ASP.NET ViewState Code Injectionconnectwise · screenconnect · CWE-502 | Yüksek7,2 | KEV | %3,5 | 25 Nis 2025 |
39İzleyin | CVE-2020-15027İstismar yok | ConnectWise Automate through 2020.x has insufficient validation on certain authentication paths, allowing authentication bypass via a seriesconnectwise · automate · CWE-287 | Kritik9,8 | — | %1,3 | 16 Tem 2020 |
39İzleyin | CVE-2019-16517İstismar yok | An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185.connectwise · control · CWE-346 | Kritik9,8 | — | %1,3 | 23 Oca 2020 |
39İzleyin | CVE-2021-35066İstismar yok | An XXE vulnerability exists in ConnectWise Automate before 2021.0.6.132.connectwise · automate · CWE-611 | Kritik9,8 | — | %1,1 | 21 Haz 2021 |
39İzleyin | CVE-2023-25718İstismar yok | In ConnectWise Control through 22.9.10032 (formerly known as ScreenConnect), after an executable file is signed, additional instructions canconnectwise · control · CWE-347 | Kritik9,8 | — | %0,7 | 13 Şub 2023 |
36İzleyin | CVE-2020-14159İstismar yok | By using an Automate API in ConnectWise Automate before 2020.5.178, a remote authenticated user could execute commands and/or modifications connectwise · automate api · CWE-89 | Yüksek8,8 | — | %1,9 | 15 Haz 2020 |
36İzleyin | CVE-2025-14265İstismar yok | Improper server-side validation in ScreenConnect extension frameworkconnectwise · screenconnect · CWE-494 | Kritik9,1 | — | %0,4 | 11 Ara 2025 |
35İzleyin | CVE-2020-15838İstismar yok | The Agent Update System in ConnectWise Automate before 2020.8 allows Privilege Escalation because the _LTUPDATE folder has weak permissions.connectwise · automate · CWE-732 | Yüksek8,8 | — | %1,2 | 9 Eki 2020 |
35İzleyin | CVE-2023-25719İstismar yok | ConnectWise Control before 22.9.10032 (formerly known as ScreenConnect) fails to validate user-supplied parameters such as the Bin/ConnectWiconnectwise · control · CWE-74 | Yüksek8,8 | — | %1,1 | 13 Şub 2023 |
35İzleyin | CVE-2019-16513İstismar yok | An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185.connectwise · control · CWE-352 | Yüksek8,8 | — | %1,0 | 23 Oca 2020 |
35İzleyin | CVE-2017-11726İstismar yok | services/system_io/actionprocessor/System.rails in ConnectWise Manage 2017.5 is vulnerable to Cross-Site Request Forgery (CSRF), as demonstrconnectwise · manage · CWE-352 | Yüksek8,8 | — | %0,5 | 31 Tem 2017 |
35İzleyin | CVE-2026-9089İstismar yok | The ConnectWise Automate™ Agent does not fully verify the authenticity of components obtained during plugin loading and self-update operatioconnectwise · automate · CWE-494 | Yüksek8,8 | — | %0,2 | 21 May 2026 |
32İzleyin | CVE-2023-47257İstismar yok | ConnectWise ScreenConnect through 23.8.4 allows man-in-the-middle attackers to achieve remote code execution via crafted messages.connectwise · automate · CWE-94 | Yüksek8,1 | — | %1,0 | 1 Şub 2024 |
30İzleyin | CVE-2021-32582İstismar yok | An issue was discovered in ConnectWise Automate before 2021.5.connectwise · connectwise automate · CWE-89 | Yüksek7,5 | — | %1,1 | 17 Haz 2021 |
30İzleyin | CVE-2020-15008İstismar yok | A SQLi exists in the probe code of all Connectwise Automate versions before 2020.7 or 2019.12.connectwise · connectwise automate · CWE-89 | Yüksek7,5 | — | %0,9 | 7 Tem 2020 |
30İzleyin | CVE-2025-11493İstismar yok | Self-Update Verification Mechanism Process in ConnectWise Automateconnectwise · automate · CWE-494 | Yüksek7,5 | — | %0,2 | 16 Eki 2025 |
30İzleyin | CVE-2025-11492Kavram kanıtı | HTTP Configuration and Encryption in Transitconnectwise · automate · CWE-319 | Yüksek7,5 | — | %0,2 | 16 Eki 2025 |
29İzleyin | CVE-2019-16514İstismar yok | An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185.connectwise · control · CWE-434 | Yüksek7,2 | — | %4,2 | 23 Oca 2020 |
28İzleyin | CVE-2026-6066İstismar yok | Unencrypted Client‑Server Communication in ConnectWise Automate™ Solution Centerconnectwise · automate · CWE-319 | Yüksek7,1 | — | %0,1 | 20 Nis 2026 |
27İzleyin | CVE-2019-16516Kavram kanıtı | An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185.connectwise · control · CWE-203 | Orta5,3 | — | %19,1 | 23 Oca 2020 |
27İzleyin | CVE-2019-16515İstismar yok | An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185.connectwise · control | Orta6,5 | — | %1,7 | 23 Oca 2020 |
- CVE-2024-1709100Hemen
Authentication bypass using an alternate path or channel
KritikCVSS 10,0KEVSilahlaştırılmışEPSS %100connectwise · screenconnect21 Şub 2024
- CVE-2017-1836295Hemen
ConnectWise ManagedITSync integration through 2017 for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct ac
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %87connectwise · manageditsync5 Şub 2019
- CVE-2024-170892Hemen
Improper limitation of a pathname to a restricted directory (“path traversal”)
YüksekCVSS 8,4KEVSilahlaştırılmışEPSS %95connectwise · screenconnect21 Şub 2024
- CVE-2026-8486969Bu hafta
ScreenConnect Client: Guest-to-Host File Execution via File-Transfer Actions
KritikCVSS 9,9KEVSilahlaştırılmışEPSS %1connectwise · screenconnect8 Eyl 2026
- CVE-2025-393559Planlayın
ScreenConnect Exposure to ASP.NET ViewState Code Injection
YüksekCVSS 7,2KEVSilahlaştırılmışEPSS %4connectwise · screenconnect25 Nis 2025
- CVE-2020-1502739İzleyin
ConnectWise Automate through 2020.x has insufficient validation on certain authentication paths, allowing authentication bypass via a series
KritikCVSS 9,8İstismar yokEPSS %1connectwise · automate16 Tem 2020
- CVE-2019-1651739İzleyin
An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185.
KritikCVSS 9,8İstismar yokEPSS %1connectwise · control23 Oca 2020
- CVE-2021-3506639İzleyin
An XXE vulnerability exists in ConnectWise Automate before 2021.0.6.132.
KritikCVSS 9,8İstismar yokEPSS %1connectwise · automate21 Haz 2021
- CVE-2023-2571839İzleyin
In ConnectWise Control through 22.9.10032 (formerly known as ScreenConnect), after an executable file is signed, additional instructions can
KritikCVSS 9,8İstismar yokEPSS %1connectwise · control13 Şub 2023
- CVE-2020-1415936İzleyin
By using an Automate API in ConnectWise Automate before 2020.5.178, a remote authenticated user could execute commands and/or modifications
YüksekCVSS 8,8İstismar yokEPSS %2connectwise · automate api15 Haz 2020
- CVE-2025-1426536İzleyin
Improper server-side validation in ScreenConnect extension framework
KritikCVSS 9,1İstismar yokEPSS %0connectwise · screenconnect11 Ara 2025
- CVE-2020-1583835İzleyin
The Agent Update System in ConnectWise Automate before 2020.8 allows Privilege Escalation because the _LTUPDATE folder has weak permissions.
YüksekCVSS 8,8İstismar yokEPSS %1connectwise · automate9 Eki 2020
- CVE-2023-2571935İzleyin
ConnectWise Control before 22.9.10032 (formerly known as ScreenConnect) fails to validate user-supplied parameters such as the Bin/ConnectWi
YüksekCVSS 8,8İstismar yokEPSS %1connectwise · control13 Şub 2023
- CVE-2019-1651335İzleyin
An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185.
YüksekCVSS 8,8İstismar yokEPSS %1connectwise · control23 Oca 2020
- CVE-2017-1172635İzleyin
services/system_io/actionprocessor/System.rails in ConnectWise Manage 2017.5 is vulnerable to Cross-Site Request Forgery (CSRF), as demonstr
YüksekCVSS 8,8İstismar yokEPSS %0connectwise · manage31 Tem 2017
- CVE-2026-908935İzleyin
The ConnectWise Automate™ Agent does not fully verify the authenticity of components obtained during plugin loading and self-update operatio
YüksekCVSS 8,8İstismar yokEPSS %0connectwise · automate21 May 2026
- CVE-2023-4725732İzleyin
ConnectWise ScreenConnect through 23.8.4 allows man-in-the-middle attackers to achieve remote code execution via crafted messages.
YüksekCVSS 8,1İstismar yokEPSS %1connectwise · automate1 Şub 2024
- CVE-2021-3258230İzleyin
An issue was discovered in ConnectWise Automate before 2021.5.
YüksekCVSS 7,5İstismar yokEPSS %1connectwise · connectwise automate17 Haz 2021
- CVE-2020-1500830İzleyin
A SQLi exists in the probe code of all Connectwise Automate versions before 2020.7 or 2019.12.
YüksekCVSS 7,5İstismar yokEPSS %1connectwise · connectwise automate7 Tem 2020
- CVE-2025-1149330İzleyin
Self-Update Verification Mechanism Process in ConnectWise Automate
YüksekCVSS 7,5İstismar yokEPSS %0connectwise · automate16 Eki 2025
- CVE-2025-1149230İzleyin
HTTP Configuration and Encryption in Transit
YüksekCVSS 7,5Kavram kanıtıEPSS %0connectwise · automate16 Eki 2025
- CVE-2019-1651429İzleyin
An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185.
YüksekCVSS 7,2İstismar yokEPSS %4connectwise · control23 Oca 2020
- CVE-2026-606628İzleyin
Unencrypted Client‑Server Communication in ConnectWise Automate™ Solution Center
YüksekCVSS 7,1İstismar yokEPSS %0connectwise · automate20 Nis 2026
- CVE-2019-1651627İzleyin
An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185.
OrtaCVSS 5,3Kavram kanıtıEPSS %19connectwise · control23 Oca 2020
- CVE-2019-1651527İzleyin
An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185.
OrtaCVSS 6,5İstismar yokEPSS %2connectwise · control23 Oca 2020