Vulnerability index

Browse CVEs

134 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Devolutions Server HIGH 8.1
CVE-2026-4434

Improper certificate validation in the PAM propagation WinRM connections allows a network attacker to perform a man-in-the-middle attack via disabl…

Fix: 2026.1.6.0+
Fix from $1,950 2026-03-20
Hub Reporting Service HIGH 8.1
CVE-2026-4396

Improper certificate validation in Devolutions Hub Reporting Service 2025.3.1.1 and earlier allows a network attacker to perform a man-in-the-middl…

Fix: 2026.1.1.0+
Fix from $1,950 2026-03-18
Devolutions Server MEDIUM 5.9
CVE-2026-3638

Improper access control in user and role restore API endpoints in Devolutions Server 2025.3.11.0 and earlier allows a low-privileged authenticated us…

Fix: 2025.3.12.0+
Fix from $1,600 2026-03-09
Remote Desktop Manager CRITICAL 9.8
CVE-2026-2590

Improper enforcement of the Disable password saving in vaults setting in the connection entry component in Devolutions Remote Desktop Manager 2025.…

Fix: after 2025.3.30.0
Fix from $2,300 2026-03-03
Devolutions Server CRITICAL 9.8
CVE-2026-3130

Improper Enforcement of Behavioral Controls in Devolutions Server 2025.3.15 and earlier allows an authenticated attacker with the delete permission t…

Fix: 2025.3.16.0+
Fix from $2,300 2026-03-03
Devolutions Server CRITICAL 9.8
CVE-2026-3204

Improper input validation in the error message page in Devolutions Server 2025.3.16 and earlier allows remote attackers to spoof the displayed error…

Fix: after 2025.3.16.0
Fix from $2,300 2026-03-03
Devolutions Server CRITICAL 9.8
CVE-2026-3224

Authentication bypass in the Microsoft Entra ID (Azure AD) authentication mode in Devolutions Server 2025.3.15.0 and earlier allows an unauthenticate…

Fix: 2025.3.16.0+
Fix from $2,300 2026-03-03
Devolutions Server MEDIUM 6.5
CVE-2026-3131

Improper access control in multiple DVLS REST API endpoints in Devolutions Server 2025.3.14.0 and earlier allows an authenticated user with view-on…

Fix: 2025.3.15.0+
Fix from $1,600 2026-02-24
Devolutions Server CRITICAL 9.8
CVE-2026-0610

SQL Injection vulnerability in remote-sessions in Devolutions Server.This issue affects Devolutions Server 2025.3.1 through 2025.3.12

Fix: 2025.3.14.0+
Fix from $2,300 2026-01-19
Devolutions Server HIGH 7.6
CVE-2026-1007

Incorrect Authorization vulnerability in virtual gateway component in Devolutions Server allows attackers to bypass deny IP rules.This issue affects …

Fix: 2025.3.14.0+
Fix from $1,950 2026-01-19
Devolutions Server MEDIUM 6.5
CVE-2025-13683

Exposure of credentials in unintended requests in Devolutions Server, Remote Desktop Manager on Windows.This issue affects Devolutions Server: throug…

Fix: 2025.3.10.0 / 2025.3.25.0+
Fix from $1,600 2025-11-28
Devolutions Server HIGH 8.8
CVE-2025-13757

SQL Injection vulnerability in last usage logs in Devolutions Server.This issue affects Devolutions Server: through 2025.2.20, through 2025.3.8.

Fix: 2025.2.21.0 / 2025.3.10.0+
Fix from $1,950 2025-11-27
Devolutions Server HIGH 8.8
CVE-2025-12485

Improper privilege management during pre-MFA cookie handling in Devolutions Server allows a low-privileged authenticated user to impersonate another …

Fix: 2025.2.17.0 / 2025.3.6.0+
Fix from $1,950 2025-11-06
Devolutions Server MEDIUM 6.5
CVE-2025-12808

Improper access control in Devolutions allows a View-only user to retrieve sensitive third-level nested fields, such as password lists custom values,…

Fix: 2025.2.17.0 / 2025.3.6.0+
Fix from $1,600 2025-11-06
Devolutions Server HIGH 8.4
CVE-2025-11957

Improper authorization in the temporary access workflow of Devolutions Server 2025.2.12.0 and earlier allows an authenticated basic user to self-appr…

Fix: 2025.2.14.0+
Fix from $1,950 2025-10-22
Devolutions Server HIGH 8.8
CVE-2025-11619

Improper certificate validation when connecting to gateways in Devolutions Server 2025.3.2 and earlier allows attackers in MitM position to intercept…

Fix: 2025.2.15.0 / 2025.3.3.0+
Fix from $1,950 2025-10-15
Devolutions Server HIGH 7.1
CVE-2025-8312

Deadlock in PAM automatic check-in feature in Devolutions Server allows a password to remain valid beyond the end of its intended check-out period du…

Fix: 2025.2.7.0+
Fix from $1,950 2025-07-30
Devolutions Server MEDIUM 5.9
CVE-2025-8353

UI synchronization issue in the Just-in-Time (JIT) access request approval interface in Devolutions Server 2025.2.4.0 and earlier allows a remote aut…

Fix: 2025.2.5.0+
Fix from $1,600 2025-07-30
Devolutions Server HIGH 7.7
CVE-2025-6741

Improper access control in secure message component in Devolutions Server allows an authenticated user to steal unauthorized entries via the secure m…

Fix: 2025.2.5.0+
Fix from $1,950 2025-07-22
Devolutions Server HIGH 7.7
CVE-2025-6523

Use of weak credentials in emergency authentication component in Devolutions Server allows an unauthenticated attacker to bypass authentication via b…

Fix: 2025.2.4.0+
Fix from $1,950 2025-07-22
Devolutions Server MEDIUM 6.8
CVE-2025-5382

Improper access control in users MFA feature in Devolutions Server 2025.1.7.0 and earlier allows a user with user management permission to remove or …

Fix: 2025.1.9.0+
Fix from $1,600 2025-06-05
Devolutions Server MEDIUM 5.0
CVE-2025-3768

Improper access control in Tor network blocking feature in Devolutions Server 2025.1.10.0 and earlier allows an authenticated user to bypass the tor …

Fix: after 2025.1.10.0
Fix from $1,600 2025-06-05
Devolutions Server MEDIUM 5.0
CVE-2025-0691

Improper access control in permissions component in Devolutions Server 2025.1.10.0 and earlier allows an authenticated user to bypass the "Edit permi…

Fix: after 2025.1.10.0
Fix from $1,600 2025-06-05
Devolutions Server HIGH 8.8
CVE-2025-4433

Improper access control in user group management in Devolutions Server 2025.1.7.0 and earlier allows a non-administrative user with both "User Manage…

Fix: 2025.1.9.0+
Fix from $1,950 2025-05-30
Remote Desktop Manager HIGH 7.5
CVE-2025-5334

Exposure of private personal information to an unauthorized actor in the user vaults component of Devolutions Remote Desktop Manager allows an authen…

Fix: 2025.1.37.0 / 2025.2.0.0+
Fix from $1,950 2025-05-29
Devolutions Server MEDIUM 6.5
CVE-2025-4493

Improper privilege assignment in PAM JIT privilege sets in Devolutions Server allows a PAM user to perform PAM JIT requests on unauthorized groups …

Fix: after 2025.1.7.0
Fix from $1,600 2025-05-28
Devolutions Server MEDIUM 6.3
CVE-2025-3517

Incorrect privilege assignment in PAM JIT elevation feature in Devolutions Server 2025.1.5.0 and earlier allows a PAM user to elevate a previously co…

Fix: 2025.1.6.0+
Fix from $1,600 2025-05-01
Remote Desktop Manager MEDIUM 6.8
CVE-2025-2600

Improper authorization in the variable component in Devolutions Remote Desktop Manager on Windows allows an authenticated user to use the ELEVATED_PA…

Fix: 2024.3.31.0 / 2025.1.26.0+
Fix from $1,600 2025-03-26
Remote Desktop Manager MEDIUM 5.4
CVE-2025-2562

Insufficient logging in the autotyping feature in Devolutions Remote Desktop Manager on Windows allows an authenticated user to use a stored password…

Fix: 2024.3.31.0 / 2025.1.26.0+
Fix from $1,600 2025-03-26
Remote Desktop Manager MEDIUM 5.4
CVE-2025-2499

Client side access control bypass in the permission component in Devolutions Remote Desktop Manager on Windows. An authenticated user can exploit th…

Fix: 2024.3.31.0 / 2025.1.26.0+
Fix from $1,600 2025-03-26