Devolutions records
177 published records for vendor devolutions.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 1.1%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-284 Improper Access Control19
- CWE-863 Incorrect Authorization17
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor14
- CWE-862 Missing Authorization12
- CWE-287 Improper Authentication8
- CWE-295 Improper Certificate Validation6
The weakness classes this vendor ships most often: where to look.
CWEAll records
177 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2024-6057No exploit | Improper authentication in the vault password feature in Devolutions Remote Desktop Manager 2024.1.31.0 and earlier allows an attacker that devolutions · remote desktop manager · CWE-287 | Critical9.8 | — | 0.9% | Jun 17, 2024 |
39Monitor | CVE-2024-2921No exploit | Improper access control in PAM vault permissions in Devolutions Server 2024.1.10.0 and earlier allows an authenticated user with access to tdevolutions · devolutions server · CWE-306 | Critical9.8 | — | 0.8% | Mar 26, 2024 |
39Monitor | CVE-2023-6593No exploit | Client side permission bypass in Devolutions Remote Desktop Manager 2023.3.4.0 and earlier on iOS allows an attacker that has access to thdevolutions · remote desktop manager · CWE-732 | Critical9.8 | — | 0.7% | Dec 12, 2023 |
39Monitor | CVE-2023-4373No exploit | Inadequate validation of permissions when employing remote tools and macros within Devolutions Remote Desktop Manager versions 2023.2.19 andevolutions · remote desktop manager · CWE-287 | Critical9.8 | — | 0.7% | Aug 21, 2023 |
39Monitor | CVE-2026-3224No exploit | Authentication bypass in the Microsoft Entra ID (Azure AD) authentication mode in Devolutions Server 2025.3.15.0 and earlier allows an unautdevolutions · devolutions server · CWE-287 | Critical9.8 | — | 0.6% | Mar 3, 2026 |
39Monitor | CVE-2026-3204No exploit | Improper input validation in the error message page in Devolutions Server 2025.3.16 and earlier allows remote attackers to spoof the displadevolutions · devolutions server · CWE-20 | Critical9.8 | — | 0.6% | Mar 3, 2026 |
39Monitor | CVE-2023-5765No exploit | Improper access control in the password analyzer feature in Devolutions Remote Desktop Manager 2023.2.33 and earlier on Windows allows an atdevolutions · remote desktop manager | Critical9.8 | — | 0.6% | Nov 1, 2023 |
39Monitor | CVE-2023-5766No exploit | A remote code execution vulnerability in Remote Desktop Manager 2023.2.33 and earlier on Windows allows an attacker to remotely execute codevolutions · remote desktop manager | Critical9.8 | — | 0.6% | Nov 1, 2023 |
39Monitor | CVE-2026-3130No exploit | Improper Enforcement of Behavioral Controls in Devolutions Server 2025.3.15 and earlier allows an authenticated attacker with the delete perdevolutions · devolutions server · CWE-841 | Critical9.8 | — | 0.5% | Mar 3, 2026 |
39Monitor | CVE-2026-2590No exploit | Improper enforcement of the Disable password saving in vaults setting in the connection entry component in Devolutions Remote Desktop Manadevolutions · remote desktop manager · CWE-20 | Critical9.8 | — | 0.5% | Mar 3, 2026 |
39Monitor | CVE-2026-0610No exploit | SQL Injection vulnerability in remote-sessions in Devolutions Server.This issue affects Devolutions Server 2025.3.1 through 2025.3.12devolutions · devolutions server · CWE-89 | Critical9.8 | — | 0.3% | Jan 19, 2026 |
38Monitor | CVE-2025-6523No exploit | Use of weak credentials in emergency authentication component in Devolutions Server allows an unauthenticated attacker to bypass authenticatdevolutions · devolutions server · CWE-1391 | Critical9.5 | — | 0.4% | Jul 22, 2025 |
36Monitor | CVE-2021-42098No exploit | An incomplete permission check on entries in Devolutions Remote Desktop Manager before 2021.2.16 allows attackers to bypass permissions via devolutions · remote desktop manager · CWE-276 | High8.8 | — | 1.8% | Oct 18, 2021 |
36Monitor | CVE-2021-23921No exploit | An issue was discovered in Devolutions Server before 2020.3.devolutions · devolutions server | Critical9.1 | — | 1.0% | Apr 1, 2021 |
36Monitor | CVE-2025-11957No exploit | Improper authorization in the temporary access workflow of Devolutions Server 2025.2.12.0 and earlier allows an authenticated basic user to devolutions · devolutions server · CWE-639 | Critical9.0 | — | 0.3% | Oct 22, 2025 |
35Monitor | CVE-2022-33996No exploit | Incorrect permission management in Devolutions Server before 2022.2 allows a new user with a preexisting username to inherit the permissionsdevolutions · devolutions server · CWE-276 | High8.8 | — | 1.1% | Jul 7, 2022 |
35Monitor | CVE-2023-0953No exploit | Insufficient input sanitization in the documentation feature of Devolutions Server 2022.3.12 and earlier allows an authenticated attacker todevolutions · devolutions server · CWE-89 | High8.8 | — | 1.0% | Mar 1, 2023 |
35Monitor | CVE-2022-4287No exploit | Authentication bypass in local application lock feature in Devolutions Remote Desktop Manager 2022.3.26 and earlier on Windows allows malicdevolutions · remote desktop manager | High8.8 | — | 1.0% | Dec 21, 2022 |
35Monitor | CVE-2023-0951No exploit | Improper access controls on some API endpoints in Devolutions Server 2022.3.12 and earlier could allow a standard privileged user to perfordevolutions · devolutions server | High8.8 | — | 1.0% | Mar 1, 2023 |
35Monitor | CVE-2024-2915No exploit | Improper access control in PAM JIT elevation in Devolutions Server 2024.1.6 and earlier allows an attacker with access to the PAM JIT elevatdevolutions · devolutions server · CWE-863 | High8.8 | — | 0.6% | Mar 26, 2024 |
35Monitor | CVE-2025-12485No exploit | Improper privilege management during pre-MFA cookie handling in Devolutions Server allows a low-privileged authenticated user to impersonatedevolutions · devolutions server · CWE-269 | High8.8 | — | 0.6% | Nov 6, 2025 |
35Monitor | CVE-2025-13757No exploit | SQL Injection vulnerability in last usage logs in Devolutions Server.This issue affects Devolutions Server: through 2025.2.20, through 2025.devolutions · devolutions server · CWE-89 | High8.8 | — | 0.6% | Nov 27, 2025 |
35Monitor | CVE-2022-3641No exploit | Elevation of privilege in the Azure SQL Data Source in Devolutions Remote Desktop Manager 2022.3.13 to 2022.3.24 allows an authenticated usedevolutions · remote desktop manager · CWE-269 | High8.8 | — | 0.6% | Dec 12, 2022 |
35Monitor | CVE-2026-16801No exploit | Improper control of generation of code ('Code Injection') in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier devolutions · powershell universal · CWE-94 | High8.8 | — | 0.5% | Jul 24, 2026 |
35Monitor | CVE-2026-16800No exploit | Improper control of generation of code ('Code Injection') in the schedule feature in Devolutions PowerShell Universal 2026.2.2 and earlier adevolutions · powershell universal · CWE-94 | High8.8 | — | 0.5% | Jul 24, 2026 |
- CVE-2024-605739Monitor
Improper authentication in the vault password feature in Devolutions Remote Desktop Manager 2024.1.31.0 and earlier allows an attacker that
CriticalCVSS 9.8No exploitEPSS 1%devolutions · remote desktop managerJun 17, 2024
- CVE-2024-292139Monitor
Improper access control in PAM vault permissions in Devolutions Server 2024.1.10.0 and earlier allows an authenticated user with access to t
CriticalCVSS 9.8No exploitEPSS 1%devolutions · devolutions serverMar 26, 2024
- CVE-2023-659339Monitor
Client side permission bypass in Devolutions Remote Desktop Manager 2023.3.4.0 and earlier on iOS allows an attacker that has access to th
CriticalCVSS 9.8No exploitEPSS 1%devolutions · remote desktop managerDec 12, 2023
- CVE-2023-437339Monitor
Inadequate validation of permissions when employing remote tools and macros within Devolutions Remote Desktop Manager versions 2023.2.19 an
CriticalCVSS 9.8No exploitEPSS 1%devolutions · remote desktop managerAug 21, 2023
- CVE-2026-322439Monitor
Authentication bypass in the Microsoft Entra ID (Azure AD) authentication mode in Devolutions Server 2025.3.15.0 and earlier allows an unaut
CriticalCVSS 9.8No exploitEPSS 1%devolutions · devolutions serverMar 3, 2026
- CVE-2026-320439Monitor
Improper input validation in the error message page in Devolutions Server 2025.3.16 and earlier allows remote attackers to spoof the displa
CriticalCVSS 9.8No exploitEPSS 1%devolutions · devolutions serverMar 3, 2026
- CVE-2023-576539Monitor
Improper access control in the password analyzer feature in Devolutions Remote Desktop Manager 2023.2.33 and earlier on Windows allows an at
CriticalCVSS 9.8No exploitEPSS 1%devolutions · remote desktop managerNov 1, 2023
- CVE-2023-576639Monitor
A remote code execution vulnerability in Remote Desktop Manager 2023.2.33 and earlier on Windows allows an attacker to remotely execute co
CriticalCVSS 9.8No exploitEPSS 1%devolutions · remote desktop managerNov 1, 2023
- CVE-2026-313039Monitor
Improper Enforcement of Behavioral Controls in Devolutions Server 2025.3.15 and earlier allows an authenticated attacker with the delete per
CriticalCVSS 9.8No exploitEPSS 1%devolutions · devolutions serverMar 3, 2026
- CVE-2026-259039Monitor
Improper enforcement of the Disable password saving in vaults setting in the connection entry component in Devolutions Remote Desktop Mana
CriticalCVSS 9.8No exploitEPSS 0%devolutions · remote desktop managerMar 3, 2026
- CVE-2026-061039Monitor
SQL Injection vulnerability in remote-sessions in Devolutions Server.This issue affects Devolutions Server 2025.3.1 through 2025.3.12
CriticalCVSS 9.8No exploitEPSS 0%devolutions · devolutions serverJan 19, 2026
- CVE-2025-652338Monitor
Use of weak credentials in emergency authentication component in Devolutions Server allows an unauthenticated attacker to bypass authenticat
CriticalCVSS 9.5No exploitEPSS 0%devolutions · devolutions serverJul 22, 2025
- CVE-2021-4209836Monitor
An incomplete permission check on entries in Devolutions Remote Desktop Manager before 2021.2.16 allows attackers to bypass permissions via
HighCVSS 8.8No exploitEPSS 2%devolutions · remote desktop managerOct 18, 2021
- CVE-2021-2392136Monitor
An issue was discovered in Devolutions Server before 2020.3.
CriticalCVSS 9.1No exploitEPSS 1%devolutions · devolutions serverApr 1, 2021
- CVE-2025-1195736Monitor
Improper authorization in the temporary access workflow of Devolutions Server 2025.2.12.0 and earlier allows an authenticated basic user to
CriticalCVSS 9.0No exploitEPSS 0%devolutions · devolutions serverOct 22, 2025
- CVE-2022-3399635Monitor
Incorrect permission management in Devolutions Server before 2022.2 allows a new user with a preexisting username to inherit the permissions
HighCVSS 8.8No exploitEPSS 1%devolutions · devolutions serverJul 7, 2022
- CVE-2023-095335Monitor
Insufficient input sanitization in the documentation feature of Devolutions Server 2022.3.12 and earlier allows an authenticated attacker to
HighCVSS 8.8No exploitEPSS 1%devolutions · devolutions serverMar 1, 2023
- CVE-2022-428735Monitor
Authentication bypass in local application lock feature in Devolutions Remote Desktop Manager 2022.3.26 and earlier on Windows allows malic
HighCVSS 8.8No exploitEPSS 1%devolutions · remote desktop managerDec 21, 2022
- CVE-2023-095135Monitor
Improper access controls on some API endpoints in Devolutions Server 2022.3.12 and earlier could allow a standard privileged user to perfor
HighCVSS 8.8No exploitEPSS 1%devolutions · devolutions serverMar 1, 2023
- CVE-2024-291535Monitor
Improper access control in PAM JIT elevation in Devolutions Server 2024.1.6 and earlier allows an attacker with access to the PAM JIT elevat
HighCVSS 8.8No exploitEPSS 1%devolutions · devolutions serverMar 26, 2024
- CVE-2025-1248535Monitor
Improper privilege management during pre-MFA cookie handling in Devolutions Server allows a low-privileged authenticated user to impersonate
HighCVSS 8.8No exploitEPSS 1%devolutions · devolutions serverNov 6, 2025
- CVE-2025-1375735Monitor
SQL Injection vulnerability in last usage logs in Devolutions Server.This issue affects Devolutions Server: through 2025.2.20, through 2025.
HighCVSS 8.8No exploitEPSS 1%devolutions · devolutions serverNov 27, 2025
- CVE-2022-364135Monitor
Elevation of privilege in the Azure SQL Data Source in Devolutions Remote Desktop Manager 2022.3.13 to 2022.3.24 allows an authenticated use
HighCVSS 8.8No exploitEPSS 1%devolutions · remote desktop managerDec 12, 2022
- CVE-2026-1680135Monitor
Improper control of generation of code ('Code Injection') in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier
HighCVSS 8.8No exploitEPSS 1%devolutions · powershell universalJul 24, 2026
- CVE-2026-1680035Monitor
Improper control of generation of code ('Code Injection') in the schedule feature in Devolutions PowerShell Universal 2026.2.2 and earlier a
HighCVSS 8.8No exploitEPSS 1%devolutions · powershell universalJul 24, 2026