Vulnerability index

Browse CVEs

134 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.1 CVE-2026-4434 Improper certificate validation in the PAM propagation WinRM connections allows a network attacker to perform a man-in-the-middle attack via disabl… Devolutions Server 2026.1.6.0+ Fix from $1,9502026-03-20 HIGH 8.1 CVE-2026-4396 Improper certificate validation in Devolutions Hub Reporting Service 2025.3.1.1 and earlier allows a network attacker to perform a man-in-the-middl… Hub Reporting Service 2026.1.1.0+ Fix from $1,9502026-03-18 MEDIUM 5.9 CVE-2026-3638 Improper access control in user and role restore API endpoints in Devolutions Server 2025.3.11.0 and earlier allows a low-privileged authenticated us… Devolutions Server 2025.3.12.0+ Fix from $1,6002026-03-09 CRITICAL 9.8 CVE-2026-2590 Improper enforcement of the Disable password saving in vaults setting in the connection entry component in Devolutions Remote Desktop Manager 2025.… Remote Desktop Manager after 2025.3.30.0 Fix from $2,3002026-03-03 CRITICAL 9.8 CVE-2026-3130 Improper Enforcement of Behavioral Controls in Devolutions Server 2025.3.15 and earlier allows an authenticated attacker with the delete permission t… Devolutions Server 2025.3.16.0+ Fix from $2,3002026-03-03 CRITICAL 9.8 CVE-2026-3204 Improper input validation in the error message page in Devolutions Server 2025.3.16 and earlier allows remote attackers to spoof the displayed error… Devolutions Server after 2025.3.16.0 Fix from $2,3002026-03-03 CRITICAL 9.8 CVE-2026-3224 Authentication bypass in the Microsoft Entra ID (Azure AD) authentication mode in Devolutions Server 2025.3.15.0 and earlier allows an unauthenticate… Devolutions Server 2025.3.16.0+ Fix from $2,3002026-03-03 MEDIUM 6.5 CVE-2026-3131 Improper access control in multiple DVLS REST API endpoints in Devolutions Server 2025.3.14.0 and earlier allows an authenticated user with view-on… Devolutions Server 2025.3.15.0+ Fix from $1,6002026-02-24 CRITICAL 9.8 CVE-2026-0610 SQL Injection vulnerability in remote-sessions in Devolutions Server.This issue affects Devolutions Server 2025.3.1 through 2025.3.12 Devolutions Server 2025.3.14.0+ Fix from $2,3002026-01-19 HIGH 7.6 CVE-2026-1007 Incorrect Authorization vulnerability in virtual gateway component in Devolutions Server allows attackers to bypass deny IP rules.This issue affects … Devolutions Server 2025.3.14.0+ Fix from $1,9502026-01-19 MEDIUM 6.5 CVE-2025-13683 Exposure of credentials in unintended requests in Devolutions Server, Remote Desktop Manager on Windows.This issue affects Devolutions Server: throug… Devolutions Server 2025.3.10.0 / 2025.3.25.0+ Fix from $1,6002025-11-28 HIGH 8.8 CVE-2025-13757 SQL Injection vulnerability in last usage logs in Devolutions Server.This issue affects Devolutions Server: through 2025.2.20, through 2025.3.8. Devolutions Server 2025.2.21.0 / 2025.3.10.0+ Fix from $1,9502025-11-27 HIGH 8.8 CVE-2025-12485 Improper privilege management during pre-MFA cookie handling in Devolutions Server allows a low-privileged authenticated user to impersonate another … Devolutions Server 2025.2.17.0 / 2025.3.6.0+ Fix from $1,9502025-11-06 MEDIUM 6.5 CVE-2025-12808 Improper access control in Devolutions allows a View-only user to retrieve sensitive third-level nested fields, such as password lists custom values,… Devolutions Server 2025.2.17.0 / 2025.3.6.0+ Fix from $1,6002025-11-06 HIGH 8.4 CVE-2025-11957 Improper authorization in the temporary access workflow of Devolutions Server 2025.2.12.0 and earlier allows an authenticated basic user to self-appr… Devolutions Server 2025.2.14.0+ Fix from $1,9502025-10-22 HIGH 8.8 CVE-2025-11619 Improper certificate validation when connecting to gateways in Devolutions Server 2025.3.2 and earlier allows attackers in MitM position to intercept… Devolutions Server 2025.2.15.0 / 2025.3.3.0+ Fix from $1,9502025-10-15 HIGH 7.1 CVE-2025-8312 Deadlock in PAM automatic check-in feature in Devolutions Server allows a password to remain valid beyond the end of its intended check-out period du… Devolutions Server 2025.2.7.0+ Fix from $1,9502025-07-30 MEDIUM 5.9 CVE-2025-8353 UI synchronization issue in the Just-in-Time (JIT) access request approval interface in Devolutions Server 2025.2.4.0 and earlier allows a remote aut… Devolutions Server 2025.2.5.0+ Fix from $1,6002025-07-30 HIGH 7.7 CVE-2025-6741 Improper access control in secure message component in Devolutions Server allows an authenticated user to steal unauthorized entries via the secure m… Devolutions Server 2025.2.5.0+ Fix from $1,9502025-07-22 HIGH 7.7 CVE-2025-6523 Use of weak credentials in emergency authentication component in Devolutions Server allows an unauthenticated attacker to bypass authentication via b… Devolutions Server 2025.2.4.0+ Fix from $1,9502025-07-22 MEDIUM 6.8 CVE-2025-5382 Improper access control in users MFA feature in Devolutions Server 2025.1.7.0 and earlier allows a user with user management permission to remove or … Devolutions Server 2025.1.9.0+ Fix from $1,6002025-06-05 MEDIUM 5.0 CVE-2025-3768 Improper access control in Tor network blocking feature in Devolutions Server 2025.1.10.0 and earlier allows an authenticated user to bypass the tor … Devolutions Server after 2025.1.10.0 Fix from $1,6002025-06-05 MEDIUM 5.0 CVE-2025-0691 Improper access control in permissions component in Devolutions Server 2025.1.10.0 and earlier allows an authenticated user to bypass the "Edit permi… Devolutions Server after 2025.1.10.0 Fix from $1,6002025-06-05 HIGH 8.8 CVE-2025-4433 Improper access control in user group management in Devolutions Server 2025.1.7.0 and earlier allows a non-administrative user with both "User Manage… Devolutions Server 2025.1.9.0+ Fix from $1,9502025-05-30 HIGH 7.5 CVE-2025-5334 Exposure of private personal information to an unauthorized actor in the user vaults component of Devolutions Remote Desktop Manager allows an authen… Remote Desktop Manager 2025.1.37.0 / 2025.2.0.0+ Fix from $1,9502025-05-29 MEDIUM 6.5 CVE-2025-4493 Improper privilege assignment in PAM JIT privilege sets in Devolutions Server allows a PAM user to perform PAM JIT requests on unauthorized groups … Devolutions Server after 2025.1.7.0 Fix from $1,6002025-05-28 MEDIUM 6.3 CVE-2025-3517 Incorrect privilege assignment in PAM JIT elevation feature in Devolutions Server 2025.1.5.0 and earlier allows a PAM user to elevate a previously co… Devolutions Server 2025.1.6.0+ Fix from $1,6002025-05-01 MEDIUM 6.8 CVE-2025-2600 Improper authorization in the variable component in Devolutions Remote Desktop Manager on Windows allows an authenticated user to use the ELEVATED_PA… Remote Desktop Manager 2024.3.31.0 / 2025.1.26.0+ Fix from $1,6002025-03-26 MEDIUM 5.4 CVE-2025-2562 Insufficient logging in the autotyping feature in Devolutions Remote Desktop Manager on Windows allows an authenticated user to use a stored password… Remote Desktop Manager 2024.3.31.0 / 2025.1.26.0+ Fix from $1,6002025-03-26 MEDIUM 5.4 CVE-2025-2499 Client side access control bypass in the permission component in Devolutions Remote Desktop Manager on Windows. An authenticated user can exploit th… Remote Desktop Manager 2024.3.31.0 / 2025.1.26.0+ Fix from $1,6002025-03-26