Перейти к содержимому
Noroxi

Записи Devolutions

177 опубликованных записей вендора devolutions.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
2
С записью об исправлении
1,1 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

177 записей
  • CVE-2024-6057
    39Наблюдать

    Improper authentication in the vault password feature in Devolutions Remote Desktop Manager 2024.1.31.0 and earlier allows an attacker that

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    devolutions · remote desktop manager17 июн. 2024 г.

  • CVE-2024-2921
    39Наблюдать

    Improper access control in PAM vault permissions in Devolutions Server 2024.1.10.0 and earlier allows an authenticated user with access to t

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    devolutions · devolutions server26 мар. 2024 г.

  • CVE-2023-6593
    39Наблюдать

    Client side permission bypass in Devolutions Remote Desktop Manager 2023.3.4.0 and earlier on iOS allows an attacker that has access to th

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    devolutions · remote desktop manager12 дек. 2023 г.

  • CVE-2023-4373
    39Наблюдать

    Inadequate validation of permissions when employing remote tools and macros within Devolutions Remote Desktop Manager versions 2023.2.19 an

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    devolutions · remote desktop manager21 авг. 2023 г.

  • CVE-2026-3224
    39Наблюдать

    Authentication bypass in the Microsoft Entra ID (Azure AD) authentication mode in Devolutions Server 2025.3.15.0 and earlier allows an unaut

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    devolutions · devolutions server3 мар. 2026 г.

  • CVE-2026-3204
    39Наблюдать

    Improper input validation in the error message page in Devolutions Server 2025.3.16 and earlier allows remote attackers to spoof the displa

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    devolutions · devolutions server3 мар. 2026 г.

  • CVE-2023-5765
    39Наблюдать

    Improper access control in the password analyzer feature in Devolutions Remote Desktop Manager 2023.2.33 and earlier on Windows allows an at

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    devolutions · remote desktop manager1 нояб. 2023 г.

  • CVE-2023-5766
    39Наблюдать

    A remote code execution vulnerability in Remote Desktop Manager 2023.2.33 and earlier on Windows allows an attacker to remotely execute co

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    devolutions · remote desktop manager1 нояб. 2023 г.

  • CVE-2026-3130
    39Наблюдать

    Improper Enforcement of Behavioral Controls in Devolutions Server 2025.3.15 and earlier allows an authenticated attacker with the delete per

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    devolutions · devolutions server3 мар. 2026 г.

  • CVE-2026-2590
    39Наблюдать

    Improper enforcement of the Disable password saving in vaults setting in the connection entry component in Devolutions Remote Desktop Mana

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    devolutions · remote desktop manager3 мар. 2026 г.

  • CVE-2026-0610
    39Наблюдать

    SQL Injection vulnerability in remote-sessions in Devolutions Server.This issue affects Devolutions Server 2025.3.1 through 2025.3.12

    КритическаяCVSS 9,8Эксплойта нетEPSS 0 %

    devolutions · devolutions server19 янв. 2026 г.

  • CVE-2025-6523
    38Наблюдать

    Use of weak credentials in emergency authentication component in Devolutions Server allows an unauthenticated attacker to bypass authenticat

    КритическаяCVSS 9,5Эксплойта нетEPSS 0 %

    devolutions · devolutions server22 июл. 2025 г.

  • CVE-2021-42098
    36Наблюдать

    An incomplete permission check on entries in Devolutions Remote Desktop Manager before 2021.2.16 allows attackers to bypass permissions via

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    devolutions · remote desktop manager18 окт. 2021 г.

  • CVE-2021-23921
    36Наблюдать

    An issue was discovered in Devolutions Server before 2020.3.

    КритическаяCVSS 9,1Эксплойта нетEPSS 1 %

    devolutions · devolutions server1 апр. 2021 г.

  • CVE-2025-11957
    36Наблюдать

    Improper authorization in the temporary access workflow of Devolutions Server 2025.2.12.0 and earlier allows an authenticated basic user to

    КритическаяCVSS 9,0Эксплойта нетEPSS 0 %

    devolutions · devolutions server22 окт. 2025 г.

  • CVE-2022-33996
    35Наблюдать

    Incorrect permission management in Devolutions Server before 2022.2 allows a new user with a preexisting username to inherit the permissions

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    devolutions · devolutions server7 июл. 2022 г.

  • CVE-2022-4287
    35Наблюдать

    Authentication bypass in local application lock feature in Devolutions Remote Desktop Manager  2022.3.26 and earlier on Windows allows malic

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    devolutions · remote desktop manager21 дек. 2022 г.

  • CVE-2023-0953
    35Наблюдать

    Insufficient input sanitization in the documentation feature of Devolutions Server 2022.3.12 and earlier allows an authenticated attacker to

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    devolutions · devolutions server1 мар. 2023 г.

  • CVE-2023-0951
    35Наблюдать

    Improper access controls on some API endpoints in Devolutions Server 2022.3.12 and earlier could allow a standard privileged user to perfor

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    devolutions · devolutions server1 мар. 2023 г.

  • CVE-2024-2915
    35Наблюдать

    Improper access control in PAM JIT elevation in Devolutions Server 2024.1.6 and earlier allows an attacker with access to the PAM JIT elevat

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    devolutions · devolutions server26 мар. 2024 г.

  • CVE-2025-12485
    35Наблюдать

    Improper privilege management during pre-MFA cookie handling in Devolutions Server allows a low-privileged authenticated user to impersonate

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    devolutions · devolutions server6 нояб. 2025 г.

  • CVE-2025-13757
    35Наблюдать

    SQL Injection vulnerability in last usage logs in Devolutions Server.This issue affects Devolutions Server: through 2025.2.20, through 2025.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    devolutions · devolutions server27 нояб. 2025 г.

  • CVE-2022-3641
    35Наблюдать

    Elevation of privilege in the Azure SQL Data Source in Devolutions Remote Desktop Manager 2022.3.13 to 2022.3.24 allows an authenticated use

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    devolutions · remote desktop manager12 дек. 2022 г.

  • CVE-2026-16801
    35Наблюдать

    Improper control of generation of code ('Code Injection') in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    devolutions · powershell universal24 июл. 2026 г.

  • CVE-2026-16800
    35Наблюдать

    Improper control of generation of code ('Code Injection') in the schedule feature in Devolutions PowerShell Universal 2026.2.2 and earlier a

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    devolutions · powershell universal24 июл. 2026 г.