Skip to content
Noroxi

Devolutions records

177 published records for vendor devolutions.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
2
With a fix record
1.1%
Median publish → KEV
No record has entered KEV

All records

177 records
  • CVE-2024-6057
    39Monitor

    Improper authentication in the vault password feature in Devolutions Remote Desktop Manager 2024.1.31.0 and earlier allows an attacker that

    CriticalCVSS 9.8No exploitEPSS 1%

    devolutions · remote desktop managerJun 17, 2024

  • CVE-2024-2921
    39Monitor

    Improper access control in PAM vault permissions in Devolutions Server 2024.1.10.0 and earlier allows an authenticated user with access to t

    CriticalCVSS 9.8No exploitEPSS 1%

    devolutions · devolutions serverMar 26, 2024

  • CVE-2023-6593
    39Monitor

    Client side permission bypass in Devolutions Remote Desktop Manager 2023.3.4.0 and earlier on iOS allows an attacker that has access to th

    CriticalCVSS 9.8No exploitEPSS 1%

    devolutions · remote desktop managerDec 12, 2023

  • CVE-2023-4373
    39Monitor

    Inadequate validation of permissions when employing remote tools and macros within Devolutions Remote Desktop Manager versions 2023.2.19 an

    CriticalCVSS 9.8No exploitEPSS 1%

    devolutions · remote desktop managerAug 21, 2023

  • CVE-2026-3224
    39Monitor

    Authentication bypass in the Microsoft Entra ID (Azure AD) authentication mode in Devolutions Server 2025.3.15.0 and earlier allows an unaut

    CriticalCVSS 9.8No exploitEPSS 1%

    devolutions · devolutions serverMar 3, 2026

  • CVE-2026-3204
    39Monitor

    Improper input validation in the error message page in Devolutions Server 2025.3.16 and earlier allows remote attackers to spoof the displa

    CriticalCVSS 9.8No exploitEPSS 1%

    devolutions · devolutions serverMar 3, 2026

  • CVE-2023-5765
    39Monitor

    Improper access control in the password analyzer feature in Devolutions Remote Desktop Manager 2023.2.33 and earlier on Windows allows an at

    CriticalCVSS 9.8No exploitEPSS 1%

    devolutions · remote desktop managerNov 1, 2023

  • CVE-2023-5766
    39Monitor

    A remote code execution vulnerability in Remote Desktop Manager 2023.2.33 and earlier on Windows allows an attacker to remotely execute co

    CriticalCVSS 9.8No exploitEPSS 1%

    devolutions · remote desktop managerNov 1, 2023

  • CVE-2026-3130
    39Monitor

    Improper Enforcement of Behavioral Controls in Devolutions Server 2025.3.15 and earlier allows an authenticated attacker with the delete per

    CriticalCVSS 9.8No exploitEPSS 1%

    devolutions · devolutions serverMar 3, 2026

  • CVE-2026-2590
    39Monitor

    Improper enforcement of the Disable password saving in vaults setting in the connection entry component in Devolutions Remote Desktop Mana

    CriticalCVSS 9.8No exploitEPSS 0%

    devolutions · remote desktop managerMar 3, 2026

  • CVE-2026-0610
    39Monitor

    SQL Injection vulnerability in remote-sessions in Devolutions Server.This issue affects Devolutions Server 2025.3.1 through 2025.3.12

    CriticalCVSS 9.8No exploitEPSS 0%

    devolutions · devolutions serverJan 19, 2026

  • CVE-2025-6523
    38Monitor

    Use of weak credentials in emergency authentication component in Devolutions Server allows an unauthenticated attacker to bypass authenticat

    CriticalCVSS 9.5No exploitEPSS 0%

    devolutions · devolutions serverJul 22, 2025

  • An incomplete permission check on entries in Devolutions Remote Desktop Manager before 2021.2.16 allows attackers to bypass permissions via

    HighCVSS 8.8No exploitEPSS 2%

    devolutions · remote desktop managerOct 18, 2021

  • An issue was discovered in Devolutions Server before 2020.3.

    CriticalCVSS 9.1No exploitEPSS 1%

    devolutions · devolutions serverApr 1, 2021

  • Improper authorization in the temporary access workflow of Devolutions Server 2025.2.12.0 and earlier allows an authenticated basic user to

    CriticalCVSS 9.0No exploitEPSS 0%

    devolutions · devolutions serverOct 22, 2025

  • Incorrect permission management in Devolutions Server before 2022.2 allows a new user with a preexisting username to inherit the permissions

    HighCVSS 8.8No exploitEPSS 1%

    devolutions · devolutions serverJul 7, 2022

  • CVE-2023-0953
    35Monitor

    Insufficient input sanitization in the documentation feature of Devolutions Server 2022.3.12 and earlier allows an authenticated attacker to

    HighCVSS 8.8No exploitEPSS 1%

    devolutions · devolutions serverMar 1, 2023

  • CVE-2022-4287
    35Monitor

    Authentication bypass in local application lock feature in Devolutions Remote Desktop Manager  2022.3.26 and earlier on Windows allows malic

    HighCVSS 8.8No exploitEPSS 1%

    devolutions · remote desktop managerDec 21, 2022

  • CVE-2023-0951
    35Monitor

    Improper access controls on some API endpoints in Devolutions Server 2022.3.12 and earlier could allow a standard privileged user to perfor

    HighCVSS 8.8No exploitEPSS 1%

    devolutions · devolutions serverMar 1, 2023

  • CVE-2024-2915
    35Monitor

    Improper access control in PAM JIT elevation in Devolutions Server 2024.1.6 and earlier allows an attacker with access to the PAM JIT elevat

    HighCVSS 8.8No exploitEPSS 1%

    devolutions · devolutions serverMar 26, 2024

  • Improper privilege management during pre-MFA cookie handling in Devolutions Server allows a low-privileged authenticated user to impersonate

    HighCVSS 8.8No exploitEPSS 1%

    devolutions · devolutions serverNov 6, 2025

  • SQL Injection vulnerability in last usage logs in Devolutions Server.This issue affects Devolutions Server: through 2025.2.20, through 2025.

    HighCVSS 8.8No exploitEPSS 1%

    devolutions · devolutions serverNov 27, 2025

  • CVE-2022-3641
    35Monitor

    Elevation of privilege in the Azure SQL Data Source in Devolutions Remote Desktop Manager 2022.3.13 to 2022.3.24 allows an authenticated use

    HighCVSS 8.8No exploitEPSS 1%

    devolutions · remote desktop managerDec 12, 2022

  • Improper control of generation of code ('Code Injection') in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier

    HighCVSS 8.8No exploitEPSS 1%

    devolutions · powershell universalJul 24, 2026

  • Improper control of generation of code ('Code Injection') in the schedule feature in Devolutions PowerShell Universal 2026.2.2 and earlier a

    HighCVSS 8.8No exploitEPSS 1%

    devolutions · powershell universalJul 24, 2026