connectwise records
39 published records for vendor connectwise.
Researcher profile
- Entered KEV
- 5 · 12.8%
- Weaponized
- 5 · 12.8%
- Pre-auth RCE
- 1
- With a fix record
- 10.3%
- Median publish → KEV
- 38 days
Recurring classes
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')4
- CWE-494 Download of Code Without Integrity Check3
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-319 Cleartext Transmission of Sensitive Information3
- CWE-201 Insertion of Sensitive Information Into Sent Data2
- CWE-352 Cross-Site Request Forgery (CSRF)2
The weakness classes this vendor ships most often: where to look.
CWEAll records
39 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
100Now | CVE-2024-1709Weaponized | Authentication bypass using an alternate path or channelconnectwise · screenconnect · CWE-288 | Critical10.0 | KEV | 100.0% | Feb 21, 2024 |
95Now | CVE-2017-18362Weaponized | ConnectWise ManagedITSync integration through 2017 for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct acconnectwise · manageditsync · CWE-89 | Critical9.8 | KEV | 86.8% | Feb 5, 2019 |
92Now | CVE-2024-1708Weaponized | Improper limitation of a pathname to a restricted directory (“path traversal”)connectwise · screenconnect · CWE-22 | High8.4 | KEV | 95.4% | Feb 21, 2024 |
69This week | CVE-2026-84869Weaponized | ScreenConnect Client: Guest-to-Host File Execution via File-Transfer Actionsconnectwise · screenconnect · CWE-269 | Critical9.9 | KEV | 0.9% | Sep 8, 2026 |
59Plan | CVE-2025-3935Weaponized | ScreenConnect Exposure to ASP.NET ViewState Code Injectionconnectwise · screenconnect · CWE-502 | High7.2 | KEV | 3.5% | Apr 25, 2025 |
39Monitor | CVE-2020-15027No exploit | ConnectWise Automate through 2020.x has insufficient validation on certain authentication paths, allowing authentication bypass via a seriesconnectwise · automate · CWE-287 | Critical9.8 | — | 1.3% | Jul 16, 2020 |
39Monitor | CVE-2019-16517No exploit | An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185.connectwise · control · CWE-346 | Critical9.8 | — | 1.3% | Jan 23, 2020 |
39Monitor | CVE-2021-35066No exploit | An XXE vulnerability exists in ConnectWise Automate before 2021.0.6.132.connectwise · automate · CWE-611 | Critical9.8 | — | 1.1% | Jun 21, 2021 |
39Monitor | CVE-2023-25718No exploit | In ConnectWise Control through 22.9.10032 (formerly known as ScreenConnect), after an executable file is signed, additional instructions canconnectwise · control · CWE-347 | Critical9.8 | — | 0.7% | Feb 13, 2023 |
36Monitor | CVE-2020-14159No exploit | By using an Automate API in ConnectWise Automate before 2020.5.178, a remote authenticated user could execute commands and/or modifications connectwise · automate api · CWE-89 | High8.8 | — | 1.9% | Jun 15, 2020 |
36Monitor | CVE-2025-14265No exploit | Improper server-side validation in ScreenConnect extension frameworkconnectwise · screenconnect · CWE-494 | Critical9.1 | — | 0.4% | Dec 11, 2025 |
35Monitor | CVE-2020-15838No exploit | The Agent Update System in ConnectWise Automate before 2020.8 allows Privilege Escalation because the _LTUPDATE folder has weak permissions.connectwise · automate · CWE-732 | High8.8 | — | 1.2% | Oct 9, 2020 |
35Monitor | CVE-2023-25719No exploit | ConnectWise Control before 22.9.10032 (formerly known as ScreenConnect) fails to validate user-supplied parameters such as the Bin/ConnectWiconnectwise · control · CWE-74 | High8.8 | — | 1.1% | Feb 13, 2023 |
35Monitor | CVE-2019-16513No exploit | An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185.connectwise · control · CWE-352 | High8.8 | — | 1.0% | Jan 23, 2020 |
35Monitor | CVE-2017-11726No exploit | services/system_io/actionprocessor/System.rails in ConnectWise Manage 2017.5 is vulnerable to Cross-Site Request Forgery (CSRF), as demonstrconnectwise · manage · CWE-352 | High8.8 | — | 0.5% | Jul 31, 2017 |
35Monitor | CVE-2026-9089No exploit | The ConnectWise Automate™ Agent does not fully verify the authenticity of components obtained during plugin loading and self-update operatioconnectwise · automate · CWE-494 | High8.8 | — | 0.2% | May 21, 2026 |
32Monitor | CVE-2023-47257No exploit | ConnectWise ScreenConnect through 23.8.4 allows man-in-the-middle attackers to achieve remote code execution via crafted messages.connectwise · automate · CWE-94 | High8.1 | — | 1.0% | Feb 1, 2024 |
30Monitor | CVE-2021-32582No exploit | An issue was discovered in ConnectWise Automate before 2021.5.connectwise · connectwise automate · CWE-89 | High7.5 | — | 1.1% | Jun 17, 2021 |
30Monitor | CVE-2020-15008No exploit | A SQLi exists in the probe code of all Connectwise Automate versions before 2020.7 or 2019.12.connectwise · connectwise automate · CWE-89 | High7.5 | — | 0.9% | Jul 7, 2020 |
30Monitor | CVE-2025-11493No exploit | Self-Update Verification Mechanism Process in ConnectWise Automateconnectwise · automate · CWE-494 | High7.5 | — | 0.2% | Oct 16, 2025 |
30Monitor | CVE-2025-11492Proof of concept | HTTP Configuration and Encryption in Transitconnectwise · automate · CWE-319 | High7.5 | — | 0.2% | Oct 16, 2025 |
29Monitor | CVE-2019-16514No exploit | An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185.connectwise · control · CWE-434 | High7.2 | — | 4.2% | Jan 23, 2020 |
28Monitor | CVE-2026-6066No exploit | Unencrypted Client‑Server Communication in ConnectWise Automate™ Solution Centerconnectwise · automate · CWE-319 | High7.1 | — | 0.1% | Apr 20, 2026 |
27Monitor | CVE-2019-16516Proof of concept | An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185.connectwise · control · CWE-203 | Medium5.3 | — | 19.1% | Jan 23, 2020 |
27Monitor | CVE-2019-16515No exploit | An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185.connectwise · control | Medium6.5 | — | 1.7% | Jan 23, 2020 |
- CVE-2024-1709100Now
Authentication bypass using an alternate path or channel
CriticalCVSS 10.0KEVWeaponizedEPSS 100%connectwise · screenconnectFeb 21, 2024
- CVE-2017-1836295Now
ConnectWise ManagedITSync integration through 2017 for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct ac
CriticalCVSS 9.8KEVWeaponizedEPSS 87%connectwise · manageditsyncFeb 5, 2019
- CVE-2024-170892Now
Improper limitation of a pathname to a restricted directory (“path traversal”)
HighCVSS 8.4KEVWeaponizedEPSS 95%connectwise · screenconnectFeb 21, 2024
- CVE-2026-8486969This week
ScreenConnect Client: Guest-to-Host File Execution via File-Transfer Actions
CriticalCVSS 9.9KEVWeaponizedEPSS 1%connectwise · screenconnectSep 8, 2026
- CVE-2025-393559Plan
ScreenConnect Exposure to ASP.NET ViewState Code Injection
HighCVSS 7.2KEVWeaponizedEPSS 4%connectwise · screenconnectApr 25, 2025
- CVE-2020-1502739Monitor
ConnectWise Automate through 2020.x has insufficient validation on certain authentication paths, allowing authentication bypass via a series
CriticalCVSS 9.8No exploitEPSS 1%connectwise · automateJul 16, 2020
- CVE-2019-1651739Monitor
An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185.
CriticalCVSS 9.8No exploitEPSS 1%connectwise · controlJan 23, 2020
- CVE-2021-3506639Monitor
An XXE vulnerability exists in ConnectWise Automate before 2021.0.6.132.
CriticalCVSS 9.8No exploitEPSS 1%connectwise · automateJun 21, 2021
- CVE-2023-2571839Monitor
In ConnectWise Control through 22.9.10032 (formerly known as ScreenConnect), after an executable file is signed, additional instructions can
CriticalCVSS 9.8No exploitEPSS 1%connectwise · controlFeb 13, 2023
- CVE-2020-1415936Monitor
By using an Automate API in ConnectWise Automate before 2020.5.178, a remote authenticated user could execute commands and/or modifications
HighCVSS 8.8No exploitEPSS 2%connectwise · automate apiJun 15, 2020
- CVE-2025-1426536Monitor
Improper server-side validation in ScreenConnect extension framework
CriticalCVSS 9.1No exploitEPSS 0%connectwise · screenconnectDec 11, 2025
- CVE-2020-1583835Monitor
The Agent Update System in ConnectWise Automate before 2020.8 allows Privilege Escalation because the _LTUPDATE folder has weak permissions.
HighCVSS 8.8No exploitEPSS 1%connectwise · automateOct 9, 2020
- CVE-2023-2571935Monitor
ConnectWise Control before 22.9.10032 (formerly known as ScreenConnect) fails to validate user-supplied parameters such as the Bin/ConnectWi
HighCVSS 8.8No exploitEPSS 1%connectwise · controlFeb 13, 2023
- CVE-2019-1651335Monitor
An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185.
HighCVSS 8.8No exploitEPSS 1%connectwise · controlJan 23, 2020
- CVE-2017-1172635Monitor
services/system_io/actionprocessor/System.rails in ConnectWise Manage 2017.5 is vulnerable to Cross-Site Request Forgery (CSRF), as demonstr
HighCVSS 8.8No exploitEPSS 0%connectwise · manageJul 31, 2017
- CVE-2026-908935Monitor
The ConnectWise Automate™ Agent does not fully verify the authenticity of components obtained during plugin loading and self-update operatio
HighCVSS 8.8No exploitEPSS 0%connectwise · automateMay 21, 2026
- CVE-2023-4725732Monitor
ConnectWise ScreenConnect through 23.8.4 allows man-in-the-middle attackers to achieve remote code execution via crafted messages.
HighCVSS 8.1No exploitEPSS 1%connectwise · automateFeb 1, 2024
- CVE-2021-3258230Monitor
An issue was discovered in ConnectWise Automate before 2021.5.
HighCVSS 7.5No exploitEPSS 1%connectwise · connectwise automateJun 17, 2021
- CVE-2020-1500830Monitor
A SQLi exists in the probe code of all Connectwise Automate versions before 2020.7 or 2019.12.
HighCVSS 7.5No exploitEPSS 1%connectwise · connectwise automateJul 7, 2020
- CVE-2025-1149330Monitor
Self-Update Verification Mechanism Process in ConnectWise Automate
HighCVSS 7.5No exploitEPSS 0%connectwise · automateOct 16, 2025
- CVE-2025-1149230Monitor
HTTP Configuration and Encryption in Transit
HighCVSS 7.5Proof of conceptEPSS 0%connectwise · automateOct 16, 2025
- CVE-2019-1651429Monitor
An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185.
HighCVSS 7.2No exploitEPSS 4%connectwise · controlJan 23, 2020
- CVE-2026-606628Monitor
Unencrypted Client‑Server Communication in ConnectWise Automate™ Solution Center
HighCVSS 7.1No exploitEPSS 0%connectwise · automateApr 20, 2026
- CVE-2019-1651627Monitor
An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185.
MediumCVSS 5.3Proof of conceptEPSS 19%connectwise · controlJan 23, 2020
- CVE-2019-1651527Monitor
An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185.
MediumCVSS 6.5No exploitEPSS 2%connectwise · controlJan 23, 2020