Vulnerability index

Browse CVEs

134 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Remote Desktop Manager HIGH 7.8
CVE-2023-6288

Code injection in Remote Desktop Manager 2023.3.9.3 and earlier on macOS allows an attacker to execute code via the DYLIB_INSERT_LIBRARIES environmen…

Fix: 2023.3.10.2+
Fix from $1,950 2023-12-06
Devolutions Server MEDIUM 5.3
CVE-2023-6264

Information leak in Content-Security-Policy header in Devolutions Server 2023.3.7.0 allows an unauthenticated attacker to list the configured Devolut…

Fix: 2023.3.8.0+
Fix from $1,600 2023-11-22
Remote Desktop Manager CRITICAL 9.8
CVE-2023-5765

Improper access control in the password analyzer feature in Devolutions Remote Desktop Manager 2023.2.33 and earlier on Windows allows an attacker to…

Fix: after 2023.2.33
Fix from $2,300 2023-11-01
Remote Desktop Manager CRITICAL 9.8
CVE-2023-5766

A remote code execution vulnerability in Remote Desktop Manager 2023.2.33 and earlier on Windows allows an attacker to remotely execute code from ano…

Fix: after 2023.2.33
Fix from $2,300 2023-11-01
Devolutions Server MEDIUM 5.3
CVE-2023-5358

Improper access control in Report log filters feature in Devolutions Server 2023.2.10.0 and earlier allows attackers to retrieve logs from vaults or …

Fix: 2023.3.4.0+
Fix from $1,600 2023-11-01
Devolutions Server MEDIUM 6.5
CVE-2023-5575

Improper access control in the permission inheritance in Devolutions Server 2022.3.13.0 and earlier allows an attacker that compromised a low privile…

Fix: after 2022.3.13.0
Fix from $1,600 2023-10-16
Devolutions Server HIGH 7.5
CVE-2023-5240

Improper access control in PAM propagation scripts in Devolutions Server 2023.2.8.0 and ealier allows an attack with permission to manage PAM propaga…

Fix: after 2023.2.8.0
Fix from $1,950 2023-10-13
Remote Desktop Manager MEDIUM 6.5
CVE-2023-4417

Improper access controls in the entry duplication component in Devolutions Remote Desktop Manager 2023.2.19 and earlier versions on Windows allows an…

Fix: after 2023.2.19
Fix from $1,600 2023-08-21
Remote Desktop Manager CRITICAL 9.8
CVE-2023-4373

Inadequate validation of permissions when employing remote tools and macros within Devolutions Remote Desktop Manager versions 2023.2.19 and earlier …

Fix: after 2023.2.19
Fix from $2,300 2023-08-21
Remote Desktop Manager MEDIUM 6.5
CVE-2023-2282

Improper access control in the Web Login listener in Devolutions Remote Desktop Manager 2023.1.22 and earlier on Windows allows an authenticated user…

Fix: after 2023.1.22
Fix from $1,600 2023-04-25
Workspace HIGH 7.8
CVE-2023-2257

Authentication Bypass in Hub Business integration in Devolutions Workspace Desktop 2023.1.1.3 and earlier on Windows and macOS allows an attacker wit…

Fix: 2023.1.1.4+
Fix from $1,950 2023-04-24
Devolutions Server MEDIUM 5.4
CVE-2023-2118

Insufficient access control in support ticket feature in Devolutions Server 2023.1.5.0 and below allows an authenticated attacker to send support tic…

Fix: 2023.1.6.0+
Fix from $1,600 2023-04-21
Remote Desktop Manager MEDIUM 6.5
CVE-2023-1980

Two factor authentication bypass on login in Devolutions Remote Desktop Manager 2022.3.35 and earlier allow user to cancel the two factor authenti…

Fix: after 2022.3.35
Fix from $1,600 2023-04-11
Devolutions Gateway HIGH 7.5
CVE-2023-1580

Uncontrolled resource consumption in the logging feature in Devolutions Gateway 2023.1.1 and earlier allows an attacker to cause a denial of service …

Fix: 2023.1.2+
Fix from $1,950 2023-04-02
Remote Desktop Manager MEDIUM 6.5
CVE-2023-1202

Permission bypass when importing or synchronizing entries in User vault in Devolutions Remote Desktop Manager 2023.1.9 and prior versions allows us…

Fix: 2023.1.10+
Fix from $1,600 2023-04-02
Remote Desktop Manager MEDIUM 6.5
CVE-2023-1574

Information disclosure in the user creation feature of a MSSQL data source in Devolutions Remote Desktop Manager 2023.1.9 and below on Windows allows…

Fix: 2023.1.10+
Fix from $1,600 2023-04-02
Devolutions Server MEDIUM 6.5
CVE-2023-1603

Permission bypass when importing or synchronizing entries in User vault in Devolutions Server 2022.3.13 and prior versions allows users with restri…

Fix: 2023.1.3.0+
Fix from $1,600 2023-04-02
Devolutions Server MEDIUM 6.5
CVE-2023-1201

Improper access control in the secure messages feature in Devolutions Server 2022.3.12 and below allows an authenticated attacker that possesses the …

Fix: 2022.3.13+
Fix from $1,600 2023-03-10
Remote Desktop Manager MEDIUM 6.5
CVE-2023-1203

Improper removal of sensitive data in the entry edit feature of Hub Business submodule in Devolutions Remote Desktop Manager PowerShell Module 2022.3…

Fix: 2022.3.1.6+
Fix from $1,600 2023-03-10
Devolutions Server HIGH 8.8
CVE-2023-0951

Improper access controls on some API endpoints in Devolutions Server 2022.3.12 and earlier could allow a standard privileged user to perform privile…

Fix: after 2022.3.12
Fix from $1,950 2023-03-01
Devolutions Server HIGH 8.8
CVE-2023-0953

Insufficient input sanitization in the documentation feature of Devolutions Server 2022.3.12 and earlier allows an authenticated attacker to perform …

Fix: after 2022.3.12
Fix from $1,950 2023-03-01
Devolutions Server MEDIUM 6.5
CVE-2023-0952

Improper access controls on entries in Devolutions Server 2022.3.12 and earlier could allow an authenticated user to access sensitive data without …

Fix: after 2022.3.12
Fix from $1,600 2023-03-01
Devolutions Server MEDIUM 6.5
CVE-2023-0661

Improper access control in Devolutions Server allows an authenticated user to access unauthorized sensitive data.

Fix: 2022.3.10.0+
Fix from $1,600 2023-02-12
Remote Desktop Manager HIGH 7.5
CVE-2022-26964

Weak password derivation for export in Devolutions Remote Desktop Manager before 2022.1 allows information disclosure via a password brute-force atta…

Fix: 2022.1+
Fix from $1,950 2022-12-26
Remote Desktop Manager HIGH 8.8
CVE-2022-4287

Authentication bypass in local application lock feature in Devolutions Remote Desktop Manager  2022.3.26 and earlier on Windows allows malicious user…

Fix: 2022.3.27+
Fix from $1,950 2022-12-21
Remote Desktop Manager HIGH 8.8
CVE-2022-3641

Elevation of privilege in the Azure SQL Data Source in Devolutions Remote Desktop Manager 2022.3.13 to 2022.3.24 allows an authenticated user to spoo…

Fix: 2022.3.26+
Fix from $1,950 2022-12-12
Remote Desktop Manager HIGH 7.5
CVE-2022-3780

Database connections on deleted users could stay active on MySQL data sources in Remote Desktop Manager 2022.3.7 and below which allow deleted users …

Fix: 2022.3.8+
Fix from $1,950 2022-11-01
Devolutions Server MEDIUM 6.5
CVE-2022-3781

Dashlane password and Keepass Server password in My Account Settings  are not encrypted in the database in Devolutions Remote Desktop Manager 2022.2.…

Fix: 2022.2.27 / 2022.3.2+
Fix from $1,600 2022-11-01
Remote Desktop Manager HIGH 7.0
CVE-2022-3182

Improper Access Control vulnerability in the Duo SMS two-factor of Devolutions Remote Desktop Manager 2022.2.14 and earlier allows attackers to bypas…

Fix: 2022.2.15+
Fix from $1,950 2022-09-13
Devolutions Server HIGH 8.8
CVE-2022-33996

Incorrect permission management in Devolutions Server before 2022.2 allows a new user with a preexisting username to inherit the permissions of that …

Fix: 2022.2.0+
Fix from $1,950 2022-07-07