Записи Devolutions
177 опубликованных записей вендора devolutions.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 1,1 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-284 Improper Access Control19
- CWE-863 Incorrect Authorization17
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor14
- CWE-862 Missing Authorization12
- CWE-287 Improper Authentication8
- CWE-295 Improper Certificate Validation6
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
177 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2024-6057Эксплойта нет | Improper authentication in the vault password feature in Devolutions Remote Desktop Manager 2024.1.31.0 and earlier allows an attacker that devolutions · remote desktop manager · CWE-287 | Критическая9,8 | — | 0,9 % | 17 июн. 2024 г. |
39Наблюдать | CVE-2024-2921Эксплойта нет | Improper access control in PAM vault permissions in Devolutions Server 2024.1.10.0 and earlier allows an authenticated user with access to tdevolutions · devolutions server · CWE-306 | Критическая9,8 | — | 0,8 % | 26 мар. 2024 г. |
39Наблюдать | CVE-2023-6593Эксплойта нет | Client side permission bypass in Devolutions Remote Desktop Manager 2023.3.4.0 and earlier on iOS allows an attacker that has access to thdevolutions · remote desktop manager · CWE-732 | Критическая9,8 | — | 0,7 % | 12 дек. 2023 г. |
39Наблюдать | CVE-2023-4373Эксплойта нет | Inadequate validation of permissions when employing remote tools and macros within Devolutions Remote Desktop Manager versions 2023.2.19 andevolutions · remote desktop manager · CWE-287 | Критическая9,8 | — | 0,7 % | 21 авг. 2023 г. |
39Наблюдать | CVE-2026-3224Эксплойта нет | Authentication bypass in the Microsoft Entra ID (Azure AD) authentication mode in Devolutions Server 2025.3.15.0 and earlier allows an unautdevolutions · devolutions server · CWE-287 | Критическая9,8 | — | 0,7 % | 3 мар. 2026 г. |
39Наблюдать | CVE-2026-3204Эксплойта нет | Improper input validation in the error message page in Devolutions Server 2025.3.16 and earlier allows remote attackers to spoof the displadevolutions · devolutions server · CWE-20 | Критическая9,8 | — | 0,6 % | 3 мар. 2026 г. |
39Наблюдать | CVE-2023-5765Эксплойта нет | Improper access control in the password analyzer feature in Devolutions Remote Desktop Manager 2023.2.33 and earlier on Windows allows an atdevolutions · remote desktop manager | Критическая9,8 | — | 0,6 % | 1 нояб. 2023 г. |
39Наблюдать | CVE-2023-5766Эксплойта нет | A remote code execution vulnerability in Remote Desktop Manager 2023.2.33 and earlier on Windows allows an attacker to remotely execute codevolutions · remote desktop manager | Критическая9,8 | — | 0,6 % | 1 нояб. 2023 г. |
39Наблюдать | CVE-2026-3130Эксплойта нет | Improper Enforcement of Behavioral Controls in Devolutions Server 2025.3.15 and earlier allows an authenticated attacker with the delete perdevolutions · devolutions server · CWE-841 | Критическая9,8 | — | 0,5 % | 3 мар. 2026 г. |
39Наблюдать | CVE-2026-2590Эксплойта нет | Improper enforcement of the Disable password saving in vaults setting in the connection entry component in Devolutions Remote Desktop Manadevolutions · remote desktop manager · CWE-20 | Критическая9,8 | — | 0,5 % | 3 мар. 2026 г. |
39Наблюдать | CVE-2026-0610Эксплойта нет | SQL Injection vulnerability in remote-sessions in Devolutions Server.This issue affects Devolutions Server 2025.3.1 through 2025.3.12devolutions · devolutions server · CWE-89 | Критическая9,8 | — | 0,3 % | 19 янв. 2026 г. |
38Наблюдать | CVE-2025-6523Эксплойта нет | Use of weak credentials in emergency authentication component in Devolutions Server allows an unauthenticated attacker to bypass authenticatdevolutions · devolutions server · CWE-1391 | Критическая9,5 | — | 0,4 % | 22 июл. 2025 г. |
36Наблюдать | CVE-2021-42098Эксплойта нет | An incomplete permission check on entries in Devolutions Remote Desktop Manager before 2021.2.16 allows attackers to bypass permissions via devolutions · remote desktop manager · CWE-276 | Высокая8,8 | — | 1,8 % | 18 окт. 2021 г. |
36Наблюдать | CVE-2021-23921Эксплойта нет | An issue was discovered in Devolutions Server before 2020.3.devolutions · devolutions server | Критическая9,1 | — | 1,0 % | 1 апр. 2021 г. |
36Наблюдать | CVE-2025-11957Эксплойта нет | Improper authorization in the temporary access workflow of Devolutions Server 2025.2.12.0 and earlier allows an authenticated basic user to devolutions · devolutions server · CWE-639 | Критическая9,0 | — | 0,3 % | 22 окт. 2025 г. |
35Наблюдать | CVE-2022-33996Эксплойта нет | Incorrect permission management in Devolutions Server before 2022.2 allows a new user with a preexisting username to inherit the permissionsdevolutions · devolutions server · CWE-276 | Высокая8,8 | — | 1,1 % | 7 июл. 2022 г. |
35Наблюдать | CVE-2022-4287Эксплойта нет | Authentication bypass in local application lock feature in Devolutions Remote Desktop Manager 2022.3.26 and earlier on Windows allows malicdevolutions · remote desktop manager | Высокая8,8 | — | 1,0 % | 21 дек. 2022 г. |
35Наблюдать | CVE-2023-0953Эксплойта нет | Insufficient input sanitization in the documentation feature of Devolutions Server 2022.3.12 and earlier allows an authenticated attacker todevolutions · devolutions server · CWE-89 | Высокая8,8 | — | 1,0 % | 1 мар. 2023 г. |
35Наблюдать | CVE-2023-0951Эксплойта нет | Improper access controls on some API endpoints in Devolutions Server 2022.3.12 and earlier could allow a standard privileged user to perfordevolutions · devolutions server | Высокая8,8 | — | 1,0 % | 1 мар. 2023 г. |
35Наблюдать | CVE-2024-2915Эксплойта нет | Improper access control in PAM JIT elevation in Devolutions Server 2024.1.6 and earlier allows an attacker with access to the PAM JIT elevatdevolutions · devolutions server · CWE-863 | Высокая8,8 | — | 0,6 % | 26 мар. 2024 г. |
35Наблюдать | CVE-2025-12485Эксплойта нет | Improper privilege management during pre-MFA cookie handling in Devolutions Server allows a low-privileged authenticated user to impersonatedevolutions · devolutions server · CWE-269 | Высокая8,8 | — | 0,6 % | 6 нояб. 2025 г. |
35Наблюдать | CVE-2025-13757Эксплойта нет | SQL Injection vulnerability in last usage logs in Devolutions Server.This issue affects Devolutions Server: through 2025.2.20, through 2025.devolutions · devolutions server · CWE-89 | Высокая8,8 | — | 0,6 % | 27 нояб. 2025 г. |
35Наблюдать | CVE-2022-3641Эксплойта нет | Elevation of privilege in the Azure SQL Data Source in Devolutions Remote Desktop Manager 2022.3.13 to 2022.3.24 allows an authenticated usedevolutions · remote desktop manager · CWE-269 | Высокая8,8 | — | 0,6 % | 12 дек. 2022 г. |
35Наблюдать | CVE-2026-16801Эксплойта нет | Improper control of generation of code ('Code Injection') in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier devolutions · powershell universal · CWE-94 | Высокая8,8 | — | 0,5 % | 24 июл. 2026 г. |
35Наблюдать | CVE-2026-16800Эксплойта нет | Improper control of generation of code ('Code Injection') in the schedule feature in Devolutions PowerShell Universal 2026.2.2 and earlier adevolutions · powershell universal · CWE-94 | Высокая8,8 | — | 0,5 % | 24 июл. 2026 г. |
- CVE-2024-605739Наблюдать
Improper authentication in the vault password feature in Devolutions Remote Desktop Manager 2024.1.31.0 and earlier allows an attacker that
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %devolutions · remote desktop manager17 июн. 2024 г.
- CVE-2024-292139Наблюдать
Improper access control in PAM vault permissions in Devolutions Server 2024.1.10.0 and earlier allows an authenticated user with access to t
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %devolutions · devolutions server26 мар. 2024 г.
- CVE-2023-659339Наблюдать
Client side permission bypass in Devolutions Remote Desktop Manager 2023.3.4.0 and earlier on iOS allows an attacker that has access to th
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %devolutions · remote desktop manager12 дек. 2023 г.
- CVE-2023-437339Наблюдать
Inadequate validation of permissions when employing remote tools and macros within Devolutions Remote Desktop Manager versions 2023.2.19 an
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %devolutions · remote desktop manager21 авг. 2023 г.
- CVE-2026-322439Наблюдать
Authentication bypass in the Microsoft Entra ID (Azure AD) authentication mode in Devolutions Server 2025.3.15.0 and earlier allows an unaut
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %devolutions · devolutions server3 мар. 2026 г.
- CVE-2026-320439Наблюдать
Improper input validation in the error message page in Devolutions Server 2025.3.16 and earlier allows remote attackers to spoof the displa
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %devolutions · devolutions server3 мар. 2026 г.
- CVE-2023-576539Наблюдать
Improper access control in the password analyzer feature in Devolutions Remote Desktop Manager 2023.2.33 and earlier on Windows allows an at
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %devolutions · remote desktop manager1 нояб. 2023 г.
- CVE-2023-576639Наблюдать
A remote code execution vulnerability in Remote Desktop Manager 2023.2.33 and earlier on Windows allows an attacker to remotely execute co
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %devolutions · remote desktop manager1 нояб. 2023 г.
- CVE-2026-313039Наблюдать
Improper Enforcement of Behavioral Controls in Devolutions Server 2025.3.15 and earlier allows an authenticated attacker with the delete per
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %devolutions · devolutions server3 мар. 2026 г.
- CVE-2026-259039Наблюдать
Improper enforcement of the Disable password saving in vaults setting in the connection entry component in Devolutions Remote Desktop Mana
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %devolutions · remote desktop manager3 мар. 2026 г.
- CVE-2026-061039Наблюдать
SQL Injection vulnerability in remote-sessions in Devolutions Server.This issue affects Devolutions Server 2025.3.1 through 2025.3.12
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %devolutions · devolutions server19 янв. 2026 г.
- CVE-2025-652338Наблюдать
Use of weak credentials in emergency authentication component in Devolutions Server allows an unauthenticated attacker to bypass authenticat
КритическаяCVSS 9,5Эксплойта нетEPSS 0 %devolutions · devolutions server22 июл. 2025 г.
- CVE-2021-4209836Наблюдать
An incomplete permission check on entries in Devolutions Remote Desktop Manager before 2021.2.16 allows attackers to bypass permissions via
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %devolutions · remote desktop manager18 окт. 2021 г.
- CVE-2021-2392136Наблюдать
An issue was discovered in Devolutions Server before 2020.3.
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %devolutions · devolutions server1 апр. 2021 г.
- CVE-2025-1195736Наблюдать
Improper authorization in the temporary access workflow of Devolutions Server 2025.2.12.0 and earlier allows an authenticated basic user to
КритическаяCVSS 9,0Эксплойта нетEPSS 0 %devolutions · devolutions server22 окт. 2025 г.
- CVE-2022-3399635Наблюдать
Incorrect permission management in Devolutions Server before 2022.2 allows a new user with a preexisting username to inherit the permissions
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %devolutions · devolutions server7 июл. 2022 г.
- CVE-2022-428735Наблюдать
Authentication bypass in local application lock feature in Devolutions Remote Desktop Manager 2022.3.26 and earlier on Windows allows malic
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %devolutions · remote desktop manager21 дек. 2022 г.
- CVE-2023-095335Наблюдать
Insufficient input sanitization in the documentation feature of Devolutions Server 2022.3.12 and earlier allows an authenticated attacker to
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %devolutions · devolutions server1 мар. 2023 г.
- CVE-2023-095135Наблюдать
Improper access controls on some API endpoints in Devolutions Server 2022.3.12 and earlier could allow a standard privileged user to perfor
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %devolutions · devolutions server1 мар. 2023 г.
- CVE-2024-291535Наблюдать
Improper access control in PAM JIT elevation in Devolutions Server 2024.1.6 and earlier allows an attacker with access to the PAM JIT elevat
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %devolutions · devolutions server26 мар. 2024 г.
- CVE-2025-1248535Наблюдать
Improper privilege management during pre-MFA cookie handling in Devolutions Server allows a low-privileged authenticated user to impersonate
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %devolutions · devolutions server6 нояб. 2025 г.
- CVE-2025-1375735Наблюдать
SQL Injection vulnerability in last usage logs in Devolutions Server.This issue affects Devolutions Server: through 2025.2.20, through 2025.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %devolutions · devolutions server27 нояб. 2025 г.
- CVE-2022-364135Наблюдать
Elevation of privilege in the Azure SQL Data Source in Devolutions Remote Desktop Manager 2022.3.13 to 2022.3.24 allows an authenticated use
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %devolutions · remote desktop manager12 дек. 2022 г.
- CVE-2026-1680135Наблюдать
Improper control of generation of code ('Code Injection') in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %devolutions · powershell universal24 июл. 2026 г.
- CVE-2026-1680035Наблюдать
Improper control of generation of code ('Code Injection') in the schedule feature in Devolutions PowerShell Universal 2026.2.2 and earlier a
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %devolutions · powershell universal24 июл. 2026 г.