Vulnerability index

Browse CVEs

35 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2026-9089 The ConnectWise Automate™ Agent does not fully verify the authenticity of components obtained during plugin loading and self-update operations. This … Automate 2026.5+ Fix from $1,9502026-05-21 HIGH 7.1 CVE-2026-6066 ConnectWise has released a security update for ConnectWise Automate™ that addresses a behavior in the ConnectWise Automate Solution Center where cert… Automate 2026.4+ Fix from $1,9502026-04-20 MEDIUM 6.5 CVE-2026-0696 In ConnectWise PSA versions older than 2026.1, certain session cookies were not set with the HttpOnly attribute. In some scenarios, this could allow … Professional Service Automation 2026.1+ Fix from $1,6002026-01-16 MEDIUM 5.4 CVE-2026-0695 In ConnectWise PSA versions older than 2026.1, Time Entry notes stored in the Time Entry Audit Trail may be rendered without applying output encoding… Professional Service Automation 2026.1+ Fix from $1,6002026-01-16 MEDIUM 5.3 CVE-2025-14823 In deployments using the ScreenConnect™ Certificate Signing Extension, encrypted configuration values including an Azure Key Vault-related key, could… Screenconnect 1.0.12+ Fix from $1,6002025-12-18 CRITICAL 9.1 CVE-2025-14265 In versions of ScreenConnect™ prior to 25.8, server-side validation and integrity checks within the extension subsystem could allow the installation … Screenconnect 25.8.0.9438+ Fix from $2,3002025-12-11 HIGH 7.5 CVE-2025-11493 The ConnectWise Automate Agent does not fully verify the authenticity of files downloaded from the server, such as updates, dependencies, and integra… Automate 2025.9+ Fix from $1,9502025-10-16 HIGH 7.5 CVE-2025-11492 In the ConnectWise Automate Agent, communications could be configured to use HTTP instead of HTTPS. In such cases, an on-path threat actor with a man… Automate 2025.9+ Fix from $1,9502025-10-16 MEDIUM 6.5 CVE-2025-7204 In ConnectWise PSA versions older than 2025.9, a vulnerability exists where authenticated users could gain access to sensitive user information. Spec… Professional Service Automation 2025.9+ Fix from $1,6002025-07-09 HIGH 7.2 CVE-2025-3935 KEV ScreenConnect versions 25.2.3 and earlier versions may be susceptible to a ViewState code injection attack. ASP.NET Web Forms use ViewState to preser… Screenconnect 25.2.4+ Fix from $1,9502025-04-25 CRITICAL 10.0 CVE-2024-1709 KEVEPSS 100% ConnectWise ScreenConnect 23.9.7 and prior are affected by an Authentication Bypass Using an Alternate Path or Channel vulnerability, which may all… Screenconnect 23.9.8+ Fix from $2,3002024-02-21 HIGH 8.4 CVE-2024-1708 KEVEPSS 88% ConnectWise ScreenConnect 23.9.7 and prior are affected by path-traversal vulnerability, which may allow an attacker the ability to execute remote … Screenconnect 23.9.8+ Fix from $1,9502024-02-21 HIGH 8.1 CVE-2023-47257 ConnectWise ScreenConnect through 23.8.4 allows man-in-the-middle attackers to achieve remote code execution via crafted messages. Automate 23.8.5+ Fix from $1,9502024-02-01 MEDIUM 5.5 CVE-2023-47256 ConnectWise ScreenConnect through 23.8.4 allows local users to connect to arbitrary relay servers via implicit trust of proxy settings Automate 23.8.5+ Fix from $1,6002024-02-01 CRITICAL 9.8 CVE-2023-25718 In ConnectWise Control through 22.9.10032 (formerly known as ScreenConnect), after an executable file is signed, additional instructions can be added… Control after 22.9.10032 Fix from $2,3002023-02-13 HIGH 8.8 CVE-2023-25719 ConnectWise Control before 22.9.10032 (formerly known as ScreenConnect) fails to validate user-supplied parameters such as the Bin/ConnectWiseControl… Control 22.9.10032+ Fix from $1,9502023-02-13 MEDIUM 6.1 CVE-2023-23126 Connectwise Automate 2022.11 is vulnerable to Clickjacking. The login screen can be iframed and used to manipulate users to perform unintended action… Automate Mitigation only Fix from $1,6002023-02-01 MEDIUM 6.1 CVE-2023-23128 Connectwise Control 22.8.10013.8329 is vulnerable to Cross Origin Resource Sharing (CORS). The vendor's position is that two endpoints have Access-Co… Connectwise Mitigation only Fix from $1,6002023-02-01 MEDIUM 5.9 CVE-2023-23130 Connectwise Automate 2022.11 is vulnerable to Cleartext authentication. Authentication is being done via HTTP (cleartext) with SSL disabled. OTE: the… Automate Mitigation only Fix from $1,6002023-02-01 MEDIUM 5.3 CVE-2023-23127 In Connectwise Control 22.8.10013.8329, the login page does not implement HSTS headers therefore not enforcing HTTPS. NOTE: the vendor's position is … Connectwise Mitigation only Fix from $1,6002023-02-01 MEDIUM 5.3 CVE-2022-36781 ConnectWise ScreenConnect versions 22.6 and below contained a flaw allowing potential brute force attacks on custom access tokens due to inadequate r… Screenconnect 22.7+ Fix from $1,6002022-09-28 CRITICAL 9.8 CVE-2021-35066 An XXE vulnerability exists in ConnectWise Automate before 2021.0.6.132. Automate 2021.0.6.132+ Fix from $2,3002021-06-21 HIGH 7.5 CVE-2021-32582 An issue was discovered in ConnectWise Automate before 2021.5. A blind SQL injection vulnerability exists in core agent inventory communication that … Connectwise Automate 2021.5+ Fix from $1,9502021-06-17 HIGH 8.8 CVE-2020-15838 The Agent Update System in ConnectWise Automate before 2020.8 allows Privilege Escalation because the _LTUPDATE folder has weak permissions. Automate 2020.8+ Fix from $1,9502020-10-09 CRITICAL 9.8 CVE-2020-15027 ConnectWise Automate through 2020.x has insufficient validation on certain authentication paths, allowing authentication bypass via a series of attem… Automate 2019.12+ Fix from $2,3002020-07-16 HIGH 7.5 CVE-2020-15008 A SQLi exists in the probe code of all Connectwise Automate versions before 2020.7 or 2019.12. A SQL Injection in the probe implementation to save da… Connectwise Automate 2020.7+ Fix from $1,9502020-07-07 HIGH 8.8 CVE-2020-14159 By using an Automate API in ConnectWise Automate before 2020.5.178, a remote authenticated user could execute commands and/or modifications within an… Automate Api 2019.12.337 / 2020.1.53+ Fix from $1,9502020-06-15 CRITICAL 9.8 CVE-2019-16517 An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. There is a CORS misconfiguration, which reflected t… Control No fix yet Fix from $2,3002020-01-23 HIGH 8.8 CVE-2019-16513 An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. CSRF can be used to send API requests. Control No fix yet Fix from $1,9502020-01-23 HIGH 7.2 CVE-2019-16514 An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. The server allows remote code execution. Administra… Control No fix yet Fix from $1,9502020-01-23