devolutions kayıtları
devolutions üreticisine ait 177 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %1,1
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-284 Improper Access Control19
- CWE-863 Incorrect Authorization17
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor14
- CWE-862 Missing Authorization12
- CWE-287 Improper Authentication8
- CWE-295 Improper Certificate Validation6
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
177 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2024-6057İstismar yok | Improper authentication in the vault password feature in Devolutions Remote Desktop Manager 2024.1.31.0 and earlier allows an attacker that devolutions · remote desktop manager · CWE-287 | Kritik9,8 | — | %0,9 | 17 Haz 2024 |
39İzleyin | CVE-2024-2921İstismar yok | Improper access control in PAM vault permissions in Devolutions Server 2024.1.10.0 and earlier allows an authenticated user with access to tdevolutions · devolutions server · CWE-306 | Kritik9,8 | — | %0,8 | 26 Mar 2024 |
39İzleyin | CVE-2023-6593İstismar yok | Client side permission bypass in Devolutions Remote Desktop Manager 2023.3.4.0 and earlier on iOS allows an attacker that has access to thdevolutions · remote desktop manager · CWE-732 | Kritik9,8 | — | %0,7 | 12 Ara 2023 |
39İzleyin | CVE-2023-4373İstismar yok | Inadequate validation of permissions when employing remote tools and macros within Devolutions Remote Desktop Manager versions 2023.2.19 andevolutions · remote desktop manager · CWE-287 | Kritik9,8 | — | %0,7 | 21 Ağu 2023 |
39İzleyin | CVE-2026-3224İstismar yok | Authentication bypass in the Microsoft Entra ID (Azure AD) authentication mode in Devolutions Server 2025.3.15.0 and earlier allows an unautdevolutions · devolutions server · CWE-287 | Kritik9,8 | — | %0,6 | 3 Mar 2026 |
39İzleyin | CVE-2026-3204İstismar yok | Improper input validation in the error message page in Devolutions Server 2025.3.16 and earlier allows remote attackers to spoof the displadevolutions · devolutions server · CWE-20 | Kritik9,8 | — | %0,6 | 3 Mar 2026 |
39İzleyin | CVE-2023-5765İstismar yok | Improper access control in the password analyzer feature in Devolutions Remote Desktop Manager 2023.2.33 and earlier on Windows allows an atdevolutions · remote desktop manager | Kritik9,8 | — | %0,6 | 1 Kas 2023 |
39İzleyin | CVE-2023-5766İstismar yok | A remote code execution vulnerability in Remote Desktop Manager 2023.2.33 and earlier on Windows allows an attacker to remotely execute codevolutions · remote desktop manager | Kritik9,8 | — | %0,6 | 1 Kas 2023 |
39İzleyin | CVE-2026-3130İstismar yok | Improper Enforcement of Behavioral Controls in Devolutions Server 2025.3.15 and earlier allows an authenticated attacker with the delete perdevolutions · devolutions server · CWE-841 | Kritik9,8 | — | %0,5 | 3 Mar 2026 |
39İzleyin | CVE-2026-2590İstismar yok | Improper enforcement of the Disable password saving in vaults setting in the connection entry component in Devolutions Remote Desktop Manadevolutions · remote desktop manager · CWE-20 | Kritik9,8 | — | %0,5 | 3 Mar 2026 |
39İzleyin | CVE-2026-0610İstismar yok | SQL Injection vulnerability in remote-sessions in Devolutions Server.This issue affects Devolutions Server 2025.3.1 through 2025.3.12devolutions · devolutions server · CWE-89 | Kritik9,8 | — | %0,3 | 19 Oca 2026 |
38İzleyin | CVE-2025-6523İstismar yok | Use of weak credentials in emergency authentication component in Devolutions Server allows an unauthenticated attacker to bypass authenticatdevolutions · devolutions server · CWE-1391 | Kritik9,5 | — | %0,4 | 22 Tem 2025 |
36İzleyin | CVE-2021-42098İstismar yok | An incomplete permission check on entries in Devolutions Remote Desktop Manager before 2021.2.16 allows attackers to bypass permissions via devolutions · remote desktop manager · CWE-276 | Yüksek8,8 | — | %1,8 | 18 Eki 2021 |
36İzleyin | CVE-2021-23921İstismar yok | An issue was discovered in Devolutions Server before 2020.3.devolutions · devolutions server | Kritik9,1 | — | %1,0 | 1 Nis 2021 |
36İzleyin | CVE-2025-11957İstismar yok | Improper authorization in the temporary access workflow of Devolutions Server 2025.2.12.0 and earlier allows an authenticated basic user to devolutions · devolutions server · CWE-639 | Kritik9,0 | — | %0,3 | 22 Eki 2025 |
35İzleyin | CVE-2022-33996İstismar yok | Incorrect permission management in Devolutions Server before 2022.2 allows a new user with a preexisting username to inherit the permissionsdevolutions · devolutions server · CWE-276 | Yüksek8,8 | — | %1,1 | 7 Tem 2022 |
35İzleyin | CVE-2023-0953İstismar yok | Insufficient input sanitization in the documentation feature of Devolutions Server 2022.3.12 and earlier allows an authenticated attacker todevolutions · devolutions server · CWE-89 | Yüksek8,8 | — | %1,0 | 1 Mar 2023 |
35İzleyin | CVE-2022-4287İstismar yok | Authentication bypass in local application lock feature in Devolutions Remote Desktop Manager 2022.3.26 and earlier on Windows allows malicdevolutions · remote desktop manager | Yüksek8,8 | — | %1,0 | 21 Ara 2022 |
35İzleyin | CVE-2023-0951İstismar yok | Improper access controls on some API endpoints in Devolutions Server 2022.3.12 and earlier could allow a standard privileged user to perfordevolutions · devolutions server | Yüksek8,8 | — | %1,0 | 1 Mar 2023 |
35İzleyin | CVE-2024-2915İstismar yok | Improper access control in PAM JIT elevation in Devolutions Server 2024.1.6 and earlier allows an attacker with access to the PAM JIT elevatdevolutions · devolutions server · CWE-863 | Yüksek8,8 | — | %0,6 | 26 Mar 2024 |
35İzleyin | CVE-2025-12485İstismar yok | Improper privilege management during pre-MFA cookie handling in Devolutions Server allows a low-privileged authenticated user to impersonatedevolutions · devolutions server · CWE-269 | Yüksek8,8 | — | %0,6 | 6 Kas 2025 |
35İzleyin | CVE-2025-13757İstismar yok | SQL Injection vulnerability in last usage logs in Devolutions Server.This issue affects Devolutions Server: through 2025.2.20, through 2025.devolutions · devolutions server · CWE-89 | Yüksek8,8 | — | %0,6 | 27 Kas 2025 |
35İzleyin | CVE-2022-3641İstismar yok | Elevation of privilege in the Azure SQL Data Source in Devolutions Remote Desktop Manager 2022.3.13 to 2022.3.24 allows an authenticated usedevolutions · remote desktop manager · CWE-269 | Yüksek8,8 | — | %0,6 | 12 Ara 2022 |
35İzleyin | CVE-2026-16801İstismar yok | Improper control of generation of code ('Code Injection') in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier devolutions · powershell universal · CWE-94 | Yüksek8,8 | — | %0,5 | 24 Tem 2026 |
35İzleyin | CVE-2026-16800İstismar yok | Improper control of generation of code ('Code Injection') in the schedule feature in Devolutions PowerShell Universal 2026.2.2 and earlier adevolutions · powershell universal · CWE-94 | Yüksek8,8 | — | %0,5 | 24 Tem 2026 |
- CVE-2024-605739İzleyin
Improper authentication in the vault password feature in Devolutions Remote Desktop Manager 2024.1.31.0 and earlier allows an attacker that
KritikCVSS 9,8İstismar yokEPSS %1devolutions · remote desktop manager17 Haz 2024
- CVE-2024-292139İzleyin
Improper access control in PAM vault permissions in Devolutions Server 2024.1.10.0 and earlier allows an authenticated user with access to t
KritikCVSS 9,8İstismar yokEPSS %1devolutions · devolutions server26 Mar 2024
- CVE-2023-659339İzleyin
Client side permission bypass in Devolutions Remote Desktop Manager 2023.3.4.0 and earlier on iOS allows an attacker that has access to th
KritikCVSS 9,8İstismar yokEPSS %1devolutions · remote desktop manager12 Ara 2023
- CVE-2023-437339İzleyin
Inadequate validation of permissions when employing remote tools and macros within Devolutions Remote Desktop Manager versions 2023.2.19 an
KritikCVSS 9,8İstismar yokEPSS %1devolutions · remote desktop manager21 Ağu 2023
- CVE-2026-322439İzleyin
Authentication bypass in the Microsoft Entra ID (Azure AD) authentication mode in Devolutions Server 2025.3.15.0 and earlier allows an unaut
KritikCVSS 9,8İstismar yokEPSS %1devolutions · devolutions server3 Mar 2026
- CVE-2026-320439İzleyin
Improper input validation in the error message page in Devolutions Server 2025.3.16 and earlier allows remote attackers to spoof the displa
KritikCVSS 9,8İstismar yokEPSS %1devolutions · devolutions server3 Mar 2026
- CVE-2023-576539İzleyin
Improper access control in the password analyzer feature in Devolutions Remote Desktop Manager 2023.2.33 and earlier on Windows allows an at
KritikCVSS 9,8İstismar yokEPSS %1devolutions · remote desktop manager1 Kas 2023
- CVE-2023-576639İzleyin
A remote code execution vulnerability in Remote Desktop Manager 2023.2.33 and earlier on Windows allows an attacker to remotely execute co
KritikCVSS 9,8İstismar yokEPSS %1devolutions · remote desktop manager1 Kas 2023
- CVE-2026-313039İzleyin
Improper Enforcement of Behavioral Controls in Devolutions Server 2025.3.15 and earlier allows an authenticated attacker with the delete per
KritikCVSS 9,8İstismar yokEPSS %1devolutions · devolutions server3 Mar 2026
- CVE-2026-259039İzleyin
Improper enforcement of the Disable password saving in vaults setting in the connection entry component in Devolutions Remote Desktop Mana
KritikCVSS 9,8İstismar yokEPSS %0devolutions · remote desktop manager3 Mar 2026
- CVE-2026-061039İzleyin
SQL Injection vulnerability in remote-sessions in Devolutions Server.This issue affects Devolutions Server 2025.3.1 through 2025.3.12
KritikCVSS 9,8İstismar yokEPSS %0devolutions · devolutions server19 Oca 2026
- CVE-2025-652338İzleyin
Use of weak credentials in emergency authentication component in Devolutions Server allows an unauthenticated attacker to bypass authenticat
KritikCVSS 9,5İstismar yokEPSS %0devolutions · devolutions server22 Tem 2025
- CVE-2021-4209836İzleyin
An incomplete permission check on entries in Devolutions Remote Desktop Manager before 2021.2.16 allows attackers to bypass permissions via
YüksekCVSS 8,8İstismar yokEPSS %2devolutions · remote desktop manager18 Eki 2021
- CVE-2021-2392136İzleyin
An issue was discovered in Devolutions Server before 2020.3.
KritikCVSS 9,1İstismar yokEPSS %1devolutions · devolutions server1 Nis 2021
- CVE-2025-1195736İzleyin
Improper authorization in the temporary access workflow of Devolutions Server 2025.2.12.0 and earlier allows an authenticated basic user to
KritikCVSS 9,0İstismar yokEPSS %0devolutions · devolutions server22 Eki 2025
- CVE-2022-3399635İzleyin
Incorrect permission management in Devolutions Server before 2022.2 allows a new user with a preexisting username to inherit the permissions
YüksekCVSS 8,8İstismar yokEPSS %1devolutions · devolutions server7 Tem 2022
- CVE-2023-095335İzleyin
Insufficient input sanitization in the documentation feature of Devolutions Server 2022.3.12 and earlier allows an authenticated attacker to
YüksekCVSS 8,8İstismar yokEPSS %1devolutions · devolutions server1 Mar 2023
- CVE-2022-428735İzleyin
Authentication bypass in local application lock feature in Devolutions Remote Desktop Manager 2022.3.26 and earlier on Windows allows malic
YüksekCVSS 8,8İstismar yokEPSS %1devolutions · remote desktop manager21 Ara 2022
- CVE-2023-095135İzleyin
Improper access controls on some API endpoints in Devolutions Server 2022.3.12 and earlier could allow a standard privileged user to perfor
YüksekCVSS 8,8İstismar yokEPSS %1devolutions · devolutions server1 Mar 2023
- CVE-2024-291535İzleyin
Improper access control in PAM JIT elevation in Devolutions Server 2024.1.6 and earlier allows an attacker with access to the PAM JIT elevat
YüksekCVSS 8,8İstismar yokEPSS %1devolutions · devolutions server26 Mar 2024
- CVE-2025-1248535İzleyin
Improper privilege management during pre-MFA cookie handling in Devolutions Server allows a low-privileged authenticated user to impersonate
YüksekCVSS 8,8İstismar yokEPSS %1devolutions · devolutions server6 Kas 2025
- CVE-2025-1375735İzleyin
SQL Injection vulnerability in last usage logs in Devolutions Server.This issue affects Devolutions Server: through 2025.2.20, through 2025.
YüksekCVSS 8,8İstismar yokEPSS %1devolutions · devolutions server27 Kas 2025
- CVE-2022-364135İzleyin
Elevation of privilege in the Azure SQL Data Source in Devolutions Remote Desktop Manager 2022.3.13 to 2022.3.24 allows an authenticated use
YüksekCVSS 8,8İstismar yokEPSS %1devolutions · remote desktop manager12 Ara 2022
- CVE-2026-1680135İzleyin
Improper control of generation of code ('Code Injection') in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier
YüksekCVSS 8,8İstismar yokEPSS %1devolutions · powershell universal24 Tem 2026
- CVE-2026-1680035İzleyin
Improper control of generation of code ('Code Injection') in the schedule feature in Devolutions PowerShell Universal 2026.2.2 and earlier a
YüksekCVSS 8,8İstismar yokEPSS %1devolutions · powershell universal24 Tem 2026