Vulnerability index

Browse CVEs

8 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.3 CVE-2026-8694 Improper access control in Devolutions PowerShell Universal 2026.1.7 and earlier allows an unauthenticated remote attacker to obtain the OpenAPI spec… Powershell Universal 2026.1.7+ Fix from $1,6002026-06-12 HIGH 8.3 CVE-2026-4064 Missing authorization checks on multiple gRPC service endpoints in PowerShell Universal before 2026.1.4 allows an authenticated user with any valid t… Powershell Universal 2026.1.4+ Fix from $1,9502026-03-17 MEDIUM 5.5 CVE-2026-3563 Improper input validation in the apps and endpoints configuration in PowerShell Universal before 2026.1.4 allows an authenticated user with permissio… Powershell Universal 2026.1.4+ Fix from $1,6002026-03-17 MEDIUM 6.5 CVE-2026-3277 The OpenID Connect (OIDC) authentication configuration in PowerShell Universal before 2026.1.3 stores the OIDC client secret in cleartext in the .u… Powershell Universal 2026.1.3+ Fix from $1,6002026-02-27 MEDIUM 6.1 CVE-2026-0618 Cross-site Scripting vulnerability in Devolutions PowerShell Universal.This issue affects Powershell Universal: before 4.5.6, before 5.6.13. Powershell Universal 4.5.6 / 5.6.13+ Fix from $1,6002026-01-07 HIGH 8.8 CVE-2023-49213 The API endpoints in Ironman PowerShell Universal 3.0.0 through 4.2.0 allow remote attackers to execute arbitrary commands via crafted HTTP requests … Powershell Universal 3.10.2 / 4.1.10+ Fix from $1,9502023-11-23 HIGH 8.8 CVE-2022-45183 Escalation of privileges in the Web Server in Ironman Software PowerShell Universal 2.x and 3.x allows an attacker with a valid app token to retrieve… Powershell Universal 2.12.6 / 3.4.7+ Fix from $1,9502022-11-14 HIGH 7.2 CVE-2022-45184 The Web Server in Ironman Software PowerShell Universal v3.x and v2.x allows for directory traversal outside of the configuration directory, which al… Powershell Universal 3.4.7 / 3.5.3+ Fix from $1,9502022-11-14