Vulnerability index

Browse CVEs

134 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Devolutions Server HIGH 8.1
CVE-2025-2280

Improper access control in web extension restriction feature in Devolutions Server 2024.3.4.0 and earlier allows an authenticated user to bypass th…

Fix: 2024.3.6.0+
Fix from $1,950 2025-03-13
Devolutions Server HIGH 7.5
CVE-2025-2277

Exposure of password in web-based SSH authentication component in Devolutions Server 2024.3.13 and earlier allows a user to unadvertently leak his SS…

Fix: 2025.1.3.0+
Fix from $1,950 2025-03-13
Devolutions Server MEDIUM 6.5
CVE-2025-2278

Improper access control in temporary access requests and checkout requests endpoints in Devolutions Server 2024.3.13 and earlier allows an authentica…

Fix: 2025.1.3.0+
Fix from $1,600 2025-03-13
Remote Desktop Manager MEDIUM 6.5
CVE-2025-1635

Exposure of sensitive information in hub data source export feature in Devolutions Remote Desktop Manager 2024.3.29 and earlier on Windows allows a u…

Fix: 2024.3.31.0+
Fix from $1,600 2025-03-13
Remote Desktop Manager MEDIUM 6.5
CVE-2025-1636

Exposure of sensitive information in My Personal Credentials password history component in Devolutions Remote Desktop Manager 2024.3.29 and earlier o…

Fix: 2024.3.31.0+
Fix from $1,600 2025-03-13
Devolutions Server HIGH 7.1
CVE-2025-2003

Incorrect authorization in PAM vaults in Devolutions Server 2024.3.12 and earlier allows an authenticated user to bypass the 'add in root' permission.

Fix: 2024.3.13.0+
Fix from $1,950 2025-03-05
Devolutions Server MEDIUM 5.4
CVE-2025-1231

Improper password reset in PAM Module in Devolutions Server 2024.3.10.0 and earlier allows an authenticated user to reuse the oracle user password af…

Fix: 2024.3.11.0+
Fix from $1,600 2025-02-11
Remote Desktop Manager HIGH 8.1
CVE-2025-1193

Improper host validation in the certificate validation component in Devolutions Remote Desktop Manager on 2024.3.19 and earlier on Windows allows an …

Fix: 2024.3.20.0+
Fix from $1,950 2025-02-10
Remote Desktop Manager HIGH 8.8
CVE-2024-11621

Missing certificate validation in Devolutions Remote Desktop Manager on macOS, iOS, Android, Linux allows an attacker to intercept and modify encrypt…

Fix: 2024.3.2.9 / 2024.3.4.0+
Fix from $1,950 2025-02-10
Devolutions Server MEDIUM 6.5
CVE-2024-12196

Incorrect authorization in the permission component in Devolutions Server 2024.3.7.0 and earlier allows an authenticated user to view the password hi…

Fix: 2024.3.8.0+
Fix from $1,600 2024-12-04
Remote Desktop Manager HIGH 8.1
CVE-2024-12149

Incorrect permission assignment in temporary access requests component in Devolutions Remote Desktop Manager 2024.3.19.0 and earlier on Windows allow…

Fix: 2024.3.20.0+
Fix from $1,950 2024-12-04
Devolutions Server MEDIUM 5.0
CVE-2024-12151

Incorrect permission assignment in the user migration feature in Devolutions Server 2024.3.8.0 and earlier allows users to retain their old permissio…

Fix: 2024.3.9.0+
Fix from $1,600 2024-12-04
Remote Desktop Manager MEDIUM 5.4
CVE-2024-11671

Improper authentication in SQL data source MFA validation in Devolutions Remote Desktop Manager 2024.3.17 and earlier on Windows allows an authentica…

Fix: 2024.3.18.0+
Fix from $1,600 2024-11-25
Remote Desktop Manager MEDIUM 5.4
CVE-2024-11670

Incorrect authorization in the permission validation component of Devolutions Remote Desktop Manager 2024.2.21 and earlier on Windows allows a malici…

Fix: after 2024.3.10.0
Fix from $1,600 2024-11-25
Remote Desktop Manager MEDIUM 5.5
CVE-2024-7421

An information exposure in Devolutions Remote Desktop Manager 2024.2.20.0 and earlier on Windows allows local attackers with access to system logs to…

Fix: 2024.3.10+
Fix from $1,600 2024-09-25
Devolutions Server MEDIUM 6.5
CVE-2024-6512

Authorization bypass in the PAM access request approval mechanism in Devolutions Server 2024.2.10 and earlier allows authenticated users with permiss…

Fix: 2024.3.0+
Fix from $1,600 2024-09-25
Remote Desktop Manager HIGH 7.4
CVE-2024-6492

Exposure of Sensitive Information in edge browser session proxy feature in Devolutions Remote Desktop Manager 2024.2.14.0 and earlier on Windows allo…

Fix: 2024.2.15.0+
Fix from $1,950 2024-07-16
Remote Desktop Manager HIGH 7.2
CVE-2024-6354

Improper access control in PAM dashboard in Devolutions Remote Desktop Manager 2024.2.11 and earlier on Windows allows an authenticated user to bypas…

Fix: 2024.2.12.0+
Fix from $1,950 2024-06-26
Devolutions Server MEDIUM 6.3
CVE-2024-4846

Authentication bypass in the 2FA feature in Devolutions Server 2024.1.14.0 and earlier allows an authenticated attacker to authenticate to another us…

Fix: 2024.1.15.0+
Fix from $1,600 2024-06-25
Remote Desktop Manager CRITICAL 9.8
CVE-2024-6057

Improper authentication in the vault password feature in Devolutions Remote Desktop Manager 2024.1.31.0 and earlier allows an attacker that has compr…

Fix: 2024.1.32.0+
Fix from $2,300 2024-06-17
Devolutions Server MEDIUM 6.5
CVE-2024-5072

Improper input validation in PAM JIT elevation feature in Devolutions Server 2024.1.11.0 and earlier allows an authenticated user with access to the …

Fix: 2024.1.12.0+
Fix from $1,600 2024-05-17
Devolutions Server CRITICAL 9.8
CVE-2024-2921

Improper access control in PAM vault permissions in Devolutions Server 2024.1.10.0 and earlier allows an authenticated user with access to the PAM to…

Fix: 2024.1.8.0+
Fix from $2,300 2024-03-26
Devolutions Server HIGH 8.8
CVE-2024-2915

Improper access control in PAM JIT elevation in Devolutions Server 2024.1.6 and earlier allows an attacker with access to the PAM JIT elevation featu…

Fix: 2024.1.8.0+
Fix from $1,950 2024-03-26
Remote Desktop Manager MEDIUM 5.9
CVE-2024-2403

Improper cleanup in temporary file handling component in Devolutions Remote Desktop Manager 2024.1.12 and earlier on Windows allows an attacker that …

Fix: 2024.1.15.0+
Fix from $1,600 2024-03-13
Workspace MEDIUM 6.3
CVE-2024-2241

Improper access control in the user interface in Devolutions Workspace 2024.1.0 and earlier allows an authenticated user to perform unintended action…

Fix: 2024.1.1.0+
Fix from $1,600 2024-03-07
Devolutions Server MEDIUM 5.5
CVE-2024-1900

Improper session management in the identity provider authentication flow in Devolutions Server 2023.3.14.0 and earlier allows an authenticated user v…

Fix: after 2023.3.16.0
Fix from $1,600 2024-03-05
Devolutions Server HIGH 7.6
CVE-2024-1764

Improper privilege management in Just-in-time (JIT) elevation module in Devolutions Server 2023.3.14.0 and earlier allows a user to continue using th…

Fix: 2023.3.16.0+
Fix from $1,950 2024-03-05
Remote Desktop Manager MEDIUM 5.4
CVE-2024-0589

Cross-site scripting (XSS) vulnerability in the entry overview tab in Devolutions Remote Desktop Manager 2023.3.36 and earlier on Windows allows an a…

Fix: after 2023.3.36.0
Fix from $1,600 2024-01-31
Remote Desktop Manager CRITICAL 9.8
CVE-2023-6593

Client side permission bypass in Devolutions Remote Desktop Manager 2023.3.4.0 and earlier on iOS allows an attacker that has access to the applicati…

Fix: 2023.3.5.0+
Fix from $2,300 2023-12-12
Workspace MEDIUM 6.5
CVE-2023-6588

Offline mode is always enabled, even if permission disallows it, in Devolutions Server data source in Devolutions Workspace 2023.3.2.0 and earlier.…

Fix: after 2023.3.2.0
Fix from $1,600 2023-12-07