Vulnerability index

Browse CVEs

134 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Devolutions Server HIGH 8.8
CVE-2026-17568

Improper access control in the role membership management endpoint in Devolutions Server allows an authenticated non-administrative user holding the …

Fix: 2026.1.24.0 / 2026.2.14.0+
Fix from $1,950 2026-07-27
Powershell Universal HIGH 8.8
CVE-2026-16801

Improper control of generation of code ('Code Injection') in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows an…

Fix: 2026.2.3.0+
Fix from $1,950 2026-07-24
Powershell Universal MEDIUM 6.5
CVE-2026-16802

Cleartext storage of sensitive information in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows a local actor wit…

Fix: 2026.2.3.0+
Fix from $1,600 2026-07-24
Powershell Universal HIGH 8.8
CVE-2026-16800

Improper control of generation of code ('Code Injection') in the schedule feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows an …

Fix: 2026.2.3.0+
Fix from $1,950 2026-07-24
Powershell Universal MEDIUM 6.5
CVE-2026-16798

Insertion of sensitive information into sent data in the automation jobs API in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authe…

Fix: 2026.2.3.0+
Fix from $1,600 2026-07-24
Powershell Universal MEDIUM 5.0
CVE-2026-16799

Improper access control in the automation tests and workflows features in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticat…

Fix: 2026.2.3.0+
Fix from $1,600 2026-07-24
Devolutions Server HIGH 7.5
CVE-2026-15637

Improper authorization in the PAM SSH key and certificate retrieval endpoints in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated lo…

Fix: 2026.1.23.0 / 2026.2.12.0+
Fix from $1,950 2026-07-14
Devolutions Server HIGH 7.1
CVE-2026-15641

Improper authorization in the access request status endpoint in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated low-privileged user t…

Fix: 2026.1.23.0 / 2026.2.12.0+
Fix from $1,950 2026-07-14
Devolutions Server HIGH 8.8
CVE-2026-14536

Improper enforcement of a mandatory multi-factor authentication policy in Devolutions Server 2026.2.9.0 allows an attacker with valid user credential…

Fix: after 2026.2.9.0
Fix from $1,950 2026-07-06
Powershell Universal MEDIUM 6.5
CVE-2026-13437

Insertion of sensitive information into sent data in the AI Agent job API in Devolutions PowerShell Universal 2026.2.0 allows an authenticated user w…

Mitigation only
Fix from $1,600 2026-06-29
Remote Desktop Manager HIGH 7.2
CVE-2026-13372

Incorrect link resolution by display name in the custom PowerShell VPN editor in Devolutions Remote Desktop Manager 2026.2.5 through 2026.2.11 allows…

Fix: after 2026.2.12.0
Fix from $1,950 2026-06-26
Unigetui HIGH 7.5
CVE-2026-10696

Use of an incorrectly resolved name or reference in the pinget backend in Devolutions UniGetUI 2026.2.0 and earlier allows a WinGet community catal…

Fix: 2026.2.1.0+
Fix from $1,950 2026-06-17
Devolutions Server MEDIUM 6.5
CVE-2026-12105

Improper access control in Devolutions Server 2026.2.5, 2026.1.21 allows an authenticated user to access attachments via folder duplication with in…

Fix: 2026.1.22.0 / 2026.2.7.0+
Fix from $1,600 2026-06-16
Remote Desktop Manager MEDIUM 5.5
CVE-2026-12162

Improper host validation in the social login autofill feature in Devolutions Remote Desktop Manager 2026.2.8 allows an attacker to disclose stored …

Fix: 2026.2.9.0+
Fix from $1,600 2026-06-16
Remote Desktop Manager HIGH 8.8
CVE-2026-12161

Improper input validation in the SSH Elevate Shell feature allows an authenticated user with permission to create or modify a shared SSH entry to ex…

Fix: 2026.2.8.0+
Fix from $1,950 2026-06-16
Devolutions Server MEDIUM 6.5
CVE-2026-10544

Improper neutralization of special elements in the built-in PAM provider password rotation templates in Devolutions Server allows an authenticated us…

Fix: 2026.1.21.0+
Fix from $1,600 2026-06-08
Devolutions Server MEDIUM 6.5
CVE-2026-10786

Improper access control in the ticketing integration settings in Devolutions Server allows an authenticated low-privileged user to obtain cleartext c…

Fix: 2026.1.21.0+
Fix from $1,600 2026-06-08
Devolutions Server MEDIUM 5.4
CVE-2026-9522

Improper access control in the PAM account discovery feature in Devolutions Server 2026.1.19 and earlier allows an authenticated user without adminis…

Fix: 2026.1.20.0+
Fix from $1,600 2026-06-02
Devolutions Server MEDIUM 5.3
CVE-2026-9590

Improper access control in the permission validation component in Devolutions Server 2026.1.19 and earlier allows an authenticated user with entry ed…

Fix: 2026.1.20.0+
Fix from $1,600 2026-06-02
Devolutions Server MEDIUM 5.4
CVE-2026-9251

Missing authorization in the entry status management feature in Devolutions Server allows a non-administrator authenticated user to bypass the admini…

Fix: 2025.3.22.0 / 2026.1.19.0+
Fix from $1,600 2026-05-22
Devolutions Server MEDIUM 5.0
CVE-2026-9245

Improper input validation in the external authentication provider flow in Devolutions Server allows an unauthenticated remote attacker to redirect vi…

Fix: 2025.3.22.0 / 2026.1.19.0+
Fix from $1,600 2026-05-22
Devolutions Server HIGH 7.6
CVE-2026-9047

Improper handling of factor key state in the multi-factor authentication management feature in Devolutions Server allows an attacker with knowledge o…

Fix: 2026.1.19.0+
Fix from $1,950 2026-05-22
Devolutions Server HIGH 7.1
CVE-2026-7325

Improper authorization in the Active Directory browsing feature in Devolutions Server allows a low-privileged authenticated user to obtain authentica…

Fix: 2025.3.22.0 / 2026.1.19.0+
Fix from $1,950 2026-05-22
Devolutions Server MEDIUM 6.5
CVE-2026-6706

Improper access control in the vault documentation feature in Devolutions Server allows an authenticated attacker to read documentation content fr…

Fix: 2025.3.19.0 / 2026.1.15.0+
Fix from $1,600 2026-04-28
Devolutions Server MEDIUM 5.0
CVE-2026-5175

Improper access control in the multi-factor authentication (MFA) management API in Devolutions Server allows an authenticated attacker to delete thei…

Fix: 2026.1.12.0+
Fix from $1,600 2026-04-01
Devolutions Server HIGH 8.2
CVE-2026-4828

Improper authentication in the OAuth login functionality in Devolutions Server 2026.1.11 and earlier allows a remote attacker with valid credentials …

Fix: 2025.3.18.0 / 2026.1.12.0+
Fix from $1,950 2026-04-01
Devolutions Server HIGH 8.2
CVE-2026-4924

Improper authentication in the two-factor authentication (2FA) feature in Devolutions Server 2026.1.11 and earlier allows a remote attacker with va…

Fix: 2025.3.18.0 / 2026.1.12.0+
Fix from $1,950 2026-04-01
Devolutions Server MEDIUM 6.5
CVE-2026-4927

Exposure of sensitive information in the users MFA feature in Devolutions Server allows users with user management privileges to obtain other users O…

Fix: 2026.1.12.0+
Fix from $1,600 2026-04-01
Devolutions Server MEDIUM 5.4
CVE-2026-4829

Improper authentication in the external OAuth authentication flow in Devolutions Server 2026.1.11 and earlier allows an authenticated user to authent…

Fix: 2026.1.12.0+
Fix from $1,600 2026-04-01
Devolutions Server MEDIUM 5.0
CVE-2026-4925

Improper access control in the users MFA feature in Devolutions Server allows an authenticated user to bypass administrator-enforced restrictions and…

Fix: 2026.1.12.0+
Fix from $1,600 2026-04-01