İçeriğe atla
Noroxi

devolutions kayıtları

devolutions üreticisine ait 177 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
2
Düzeltme kaydı olan
%1,1
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

177 kayıt
  • CVE-2024-6057
    39İzleyin

    Improper authentication in the vault password feature in Devolutions Remote Desktop Manager 2024.1.31.0 and earlier allows an attacker that

    KritikCVSS 9,8İstismar yokEPSS %1

    devolutions · remote desktop manager17 Haz 2024

  • CVE-2024-2921
    39İzleyin

    Improper access control in PAM vault permissions in Devolutions Server 2024.1.10.0 and earlier allows an authenticated user with access to t

    KritikCVSS 9,8İstismar yokEPSS %1

    devolutions · devolutions server26 Mar 2024

  • CVE-2023-6593
    39İzleyin

    Client side permission bypass in Devolutions Remote Desktop Manager 2023.3.4.0 and earlier on iOS allows an attacker that has access to th

    KritikCVSS 9,8İstismar yokEPSS %1

    devolutions · remote desktop manager12 Ara 2023

  • CVE-2023-4373
    39İzleyin

    Inadequate validation of permissions when employing remote tools and macros within Devolutions Remote Desktop Manager versions 2023.2.19 an

    KritikCVSS 9,8İstismar yokEPSS %1

    devolutions · remote desktop manager21 Ağu 2023

  • CVE-2026-3224
    39İzleyin

    Authentication bypass in the Microsoft Entra ID (Azure AD) authentication mode in Devolutions Server 2025.3.15.0 and earlier allows an unaut

    KritikCVSS 9,8İstismar yokEPSS %1

    devolutions · devolutions server3 Mar 2026

  • CVE-2026-3204
    39İzleyin

    Improper input validation in the error message page in Devolutions Server 2025.3.16 and earlier allows remote attackers to spoof the displa

    KritikCVSS 9,8İstismar yokEPSS %1

    devolutions · devolutions server3 Mar 2026

  • CVE-2023-5765
    39İzleyin

    Improper access control in the password analyzer feature in Devolutions Remote Desktop Manager 2023.2.33 and earlier on Windows allows an at

    KritikCVSS 9,8İstismar yokEPSS %1

    devolutions · remote desktop manager1 Kas 2023

  • CVE-2023-5766
    39İzleyin

    A remote code execution vulnerability in Remote Desktop Manager 2023.2.33 and earlier on Windows allows an attacker to remotely execute co

    KritikCVSS 9,8İstismar yokEPSS %1

    devolutions · remote desktop manager1 Kas 2023

  • CVE-2026-3130
    39İzleyin

    Improper Enforcement of Behavioral Controls in Devolutions Server 2025.3.15 and earlier allows an authenticated attacker with the delete per

    KritikCVSS 9,8İstismar yokEPSS %1

    devolutions · devolutions server3 Mar 2026

  • CVE-2026-2590
    39İzleyin

    Improper enforcement of the Disable password saving in vaults setting in the connection entry component in Devolutions Remote Desktop Mana

    KritikCVSS 9,8İstismar yokEPSS %0

    devolutions · remote desktop manager3 Mar 2026

  • CVE-2026-0610
    39İzleyin

    SQL Injection vulnerability in remote-sessions in Devolutions Server.This issue affects Devolutions Server 2025.3.1 through 2025.3.12

    KritikCVSS 9,8İstismar yokEPSS %0

    devolutions · devolutions server19 Oca 2026

  • CVE-2025-6523
    38İzleyin

    Use of weak credentials in emergency authentication component in Devolutions Server allows an unauthenticated attacker to bypass authenticat

    KritikCVSS 9,5İstismar yokEPSS %0

    devolutions · devolutions server22 Tem 2025

  • CVE-2021-42098
    36İzleyin

    An incomplete permission check on entries in Devolutions Remote Desktop Manager before 2021.2.16 allows attackers to bypass permissions via

    YüksekCVSS 8,8İstismar yokEPSS %2

    devolutions · remote desktop manager18 Eki 2021

  • CVE-2021-23921
    36İzleyin

    An issue was discovered in Devolutions Server before 2020.3.

    KritikCVSS 9,1İstismar yokEPSS %1

    devolutions · devolutions server1 Nis 2021

  • CVE-2025-11957
    36İzleyin

    Improper authorization in the temporary access workflow of Devolutions Server 2025.2.12.0 and earlier allows an authenticated basic user to

    KritikCVSS 9,0İstismar yokEPSS %0

    devolutions · devolutions server22 Eki 2025

  • CVE-2022-33996
    35İzleyin

    Incorrect permission management in Devolutions Server before 2022.2 allows a new user with a preexisting username to inherit the permissions

    YüksekCVSS 8,8İstismar yokEPSS %1

    devolutions · devolutions server7 Tem 2022

  • CVE-2023-0953
    35İzleyin

    Insufficient input sanitization in the documentation feature of Devolutions Server 2022.3.12 and earlier allows an authenticated attacker to

    YüksekCVSS 8,8İstismar yokEPSS %1

    devolutions · devolutions server1 Mar 2023

  • CVE-2022-4287
    35İzleyin

    Authentication bypass in local application lock feature in Devolutions Remote Desktop Manager  2022.3.26 and earlier on Windows allows malic

    YüksekCVSS 8,8İstismar yokEPSS %1

    devolutions · remote desktop manager21 Ara 2022

  • CVE-2023-0951
    35İzleyin

    Improper access controls on some API endpoints in Devolutions Server 2022.3.12 and earlier could allow a standard privileged user to perfor

    YüksekCVSS 8,8İstismar yokEPSS %1

    devolutions · devolutions server1 Mar 2023

  • CVE-2024-2915
    35İzleyin

    Improper access control in PAM JIT elevation in Devolutions Server 2024.1.6 and earlier allows an attacker with access to the PAM JIT elevat

    YüksekCVSS 8,8İstismar yokEPSS %1

    devolutions · devolutions server26 Mar 2024

  • CVE-2025-12485
    35İzleyin

    Improper privilege management during pre-MFA cookie handling in Devolutions Server allows a low-privileged authenticated user to impersonate

    YüksekCVSS 8,8İstismar yokEPSS %1

    devolutions · devolutions server6 Kas 2025

  • CVE-2025-13757
    35İzleyin

    SQL Injection vulnerability in last usage logs in Devolutions Server.This issue affects Devolutions Server: through 2025.2.20, through 2025.

    YüksekCVSS 8,8İstismar yokEPSS %1

    devolutions · devolutions server27 Kas 2025

  • CVE-2022-3641
    35İzleyin

    Elevation of privilege in the Azure SQL Data Source in Devolutions Remote Desktop Manager 2022.3.13 to 2022.3.24 allows an authenticated use

    YüksekCVSS 8,8İstismar yokEPSS %1

    devolutions · remote desktop manager12 Ara 2022

  • CVE-2026-16801
    35İzleyin

    Improper control of generation of code ('Code Injection') in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier

    YüksekCVSS 8,8İstismar yokEPSS %1

    devolutions · powershell universal24 Tem 2026

  • CVE-2026-16800
    35İzleyin

    Improper control of generation of code ('Code Injection') in the schedule feature in Devolutions PowerShell Universal 2026.2.2 and earlier a

    YüksekCVSS 8,8İstismar yokEPSS %1

    devolutions · powershell universal24 Tem 2026