Skip to content
Noroxi

connectwise records

39 published records for vendor connectwise.

All records

39 records
  • Authentication bypass using an alternate path or channel

    CriticalCVSS 10.0KEVWeaponizedEPSS 100%

    connectwise · screenconnectFeb 21, 2024

  • ConnectWise ManagedITSync integration through 2017 for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct ac

    CriticalCVSS 9.8KEVWeaponizedEPSS 87%

    connectwise · manageditsyncFeb 5, 2019

  • Improper limitation of a pathname to a restricted directory (“path traversal”)

    HighCVSS 8.4KEVWeaponizedEPSS 95%

    connectwise · screenconnectFeb 21, 2024

  • CVE-2026-84869
    69This week

    ScreenConnect Client: Guest-to-Host File Execution via File-Transfer Actions

    CriticalCVSS 9.9KEVWeaponizedEPSS 1%

    connectwise · screenconnectSep 8, 2026

  • ScreenConnect Exposure to ASP.NET ViewState Code Injection

    HighCVSS 7.2KEVWeaponizedEPSS 4%

    connectwise · screenconnectApr 25, 2025

  • ConnectWise Automate through 2020.x has insufficient validation on certain authentication paths, allowing authentication bypass via a series

    CriticalCVSS 9.8No exploitEPSS 1%

    connectwise · automateJul 16, 2020

  • An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185.

    CriticalCVSS 9.8No exploitEPSS 1%

    connectwise · controlJan 23, 2020

  • An XXE vulnerability exists in ConnectWise Automate before 2021.0.6.132.

    CriticalCVSS 9.8No exploitEPSS 1%

    connectwise · automateJun 21, 2021

  • In ConnectWise Control through 22.9.10032 (formerly known as ScreenConnect), after an executable file is signed, additional instructions can

    CriticalCVSS 9.8No exploitEPSS 1%

    connectwise · controlFeb 13, 2023

  • By using an Automate API in ConnectWise Automate before 2020.5.178, a remote authenticated user could execute commands and/or modifications

    HighCVSS 8.8No exploitEPSS 2%

    connectwise · automate apiJun 15, 2020

  • Improper server-side validation in ScreenConnect extension framework

    CriticalCVSS 9.1No exploitEPSS 0%

    connectwise · screenconnectDec 11, 2025

  • The Agent Update System in ConnectWise Automate before 2020.8 allows Privilege Escalation because the _LTUPDATE folder has weak permissions.

    HighCVSS 8.8No exploitEPSS 1%

    connectwise · automateOct 9, 2020

  • ConnectWise Control before 22.9.10032 (formerly known as ScreenConnect) fails to validate user-supplied parameters such as the Bin/ConnectWi

    HighCVSS 8.8No exploitEPSS 1%

    connectwise · controlFeb 13, 2023

  • An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185.

    HighCVSS 8.8No exploitEPSS 1%

    connectwise · controlJan 23, 2020

  • services/system_io/actionprocessor/System.rails in ConnectWise Manage 2017.5 is vulnerable to Cross-Site Request Forgery (CSRF), as demonstr

    HighCVSS 8.8No exploitEPSS 0%

    connectwise · manageJul 31, 2017

  • CVE-2026-9089
    35Monitor

    The ConnectWise Automate™ Agent does not fully verify the authenticity of components obtained during plugin loading and self-update operatio

    HighCVSS 8.8No exploitEPSS 0%

    connectwise · automateMay 21, 2026

  • ConnectWise ScreenConnect through 23.8.4 allows man-in-the-middle attackers to achieve remote code execution via crafted messages.

    HighCVSS 8.1No exploitEPSS 1%

    connectwise · automateFeb 1, 2024

  • An issue was discovered in ConnectWise Automate before 2021.5.

    HighCVSS 7.5No exploitEPSS 1%

    connectwise · connectwise automateJun 17, 2021

  • A SQLi exists in the probe code of all Connectwise Automate versions before 2020.7 or 2019.12.

    HighCVSS 7.5No exploitEPSS 1%

    connectwise · connectwise automateJul 7, 2020

  • Self-Update Verification Mechanism Process in ConnectWise Automate

    HighCVSS 7.5No exploitEPSS 0%

    connectwise · automateOct 16, 2025

  • HTTP Configuration and Encryption in Transit

    HighCVSS 7.5Proof of conceptEPSS 0%

    connectwise · automateOct 16, 2025

  • An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185.

    HighCVSS 7.2No exploitEPSS 4%

    connectwise · controlJan 23, 2020

  • CVE-2026-6066
    28Monitor

    Unencrypted Client‑Server Communication in ConnectWise Automate™ Solution Center

    HighCVSS 7.1No exploitEPSS 0%

    connectwise · automateApr 20, 2026

  • An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185.

    MediumCVSS 5.3Proof of conceptEPSS 19%

    connectwise · controlJan 23, 2020

  • An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185.

    MediumCVSS 6.5No exploitEPSS 2%

    connectwise · controlJan 23, 2020