Vulnerability index

Browse CVEs

134 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Devolutions Server MEDIUM 5.4
CVE-2022-2316

HTML injection vulnerability in secure messages of Devolutions Server before 2022.2 allows attackers to alter the rendering of the page or redirect a…

Fix: 2022.2+
Fix from $1,600 2022-07-06
Remote Desktop Manager MEDIUM 6.5
CVE-2022-2221

Information Exposure vulnerability in My Account Settings of Devolutions Remote Desktop Manager before 2022.1.8 allows authenticated users to access …

Fix: 2022.1.8+
Fix from $1,600 2022-06-27
Remote Desktop Manager HIGH 7.5
CVE-2022-33995

A path traversal issue in entry attachments in Devolutions Remote Desktop Manager before 2022.2 allows attackers to create or overwrite files in an a…

Fix: 2022.2+
Fix from $1,950 2022-06-21
Password Hub MEDIUM 6.6
CVE-2022-23849

The biometric lock in Devolutions Password Hub for iOS before 2021.3.4 allows attackers to access the application because of authentication bypass. A…

Fix: 2021.3.4+
Fix from $1,600 2022-03-03
Remote Desktop Manager HIGH 8.8
CVE-2021-42098

An incomplete permission check on entries in Devolutions Remote Desktop Manager before 2021.2.16 allows attackers to bypass permissions via batch cus…

Fix: 2021.2.16+
Fix from $1,950 2021-10-18
Devolutions Server HIGH 7.2
CVE-2021-28157

An SQL Injection issue in Devolutions Server before 2021.1 and Devolutions Server LTS before 2020.3.18 allows an administrative user to execute arbit…

Fix: 2020.3.18 / 2021.1+
Fix from $1,950 2021-04-14
Devolutions Server MEDIUM 6.5
CVE-2021-28048

An overly permissive CORS policy in Devolutions Server before 2021.1 and Devolutions Server LTS before 2020.3.18 allows a remote attacker to leak cro…

Fix: 2020.3.18 / 2021.1+
Fix from $1,600 2021-04-14
Devolutions Server CRITICAL 9.1
CVE-2021-23921

An issue was discovered in Devolutions Server before 2020.3. There is broken access control on Password List entry elements.

Fix: 2020.3+
Fix from $2,300 2021-04-01
Devolutions Server HIGH 8.1
CVE-2021-23923

An issue was discovered in Devolutions Server before 2020.3. There is Broken Authentication with Windows domain users.

Fix: 2020.3+
Fix from $1,950 2021-04-01
Devolutions Server HIGH 7.5
CVE-2021-23924

An issue was discovered in Devolutions Server before 2020.3. There is an exposure of sensitive information in diagnostic files.

Fix: 2020.3+
Fix from $1,950 2021-04-01
Devolutions Server MEDIUM 6.1
CVE-2021-23925

An issue was discovered in Devolutions Server before 2020.3. There is a cross-site scripting (XSS) vulnerability in entries of type Document.

Fix: 2020.3+
Fix from $1,600 2021-04-01
Remote Desktop Manager MEDIUM 5.4
CVE-2021-23922

An issue was discovered in Devolutions Remote Desktop Manager before 2020.2.12. There is a cross-site scripting (XSS) vulnerability in webviews.

Fix: 2020.2.12.0+
Fix from $1,600 2021-04-01
Remote Desktop Manager MEDIUM 5.4
CVE-2021-28047

Cross-Site Scripting (XSS) in Administrative Reports in Devolutions Remote Desktop Manager before 2021.1 allows remote authenticated users to inject …

Fix: 2021.1.0+
Fix from $1,600 2021-04-01
Gfwx HIGH 7.0
CVE-2020-36211

An issue was discovered in the gfwx crate before 0.3.0 for Rust. Because ImageChunkMut does not have bounds on its Send trait or Sync trait, a data r…

Fix: 0.3.0+
Fix from $1,950 2021-01-26