Vulnerability index

Browse CVEs

10 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Automate MEDIUM 6.1
CVE-2023-23126

Connectwise Automate 2022.11 is vulnerable to Clickjacking. The login screen can be iframed and used to manipulate users to perform unintended action…

Mitigation only
Fix from $1,600 2023-02-01
Connectwise MEDIUM 6.1
CVE-2023-23128

Connectwise Control 22.8.10013.8329 is vulnerable to Cross Origin Resource Sharing (CORS). The vendor's position is that two endpoints have Access-Co…

Mitigation only
Fix from $1,600 2023-02-01
Automate MEDIUM 5.9
CVE-2023-23130

Connectwise Automate 2022.11 is vulnerable to Cleartext authentication. Authentication is being done via HTTP (cleartext) with SSL disabled. OTE: the…

Mitigation only
Fix from $1,600 2023-02-01
Connectwise MEDIUM 5.3
CVE-2023-23127

In Connectwise Control 22.8.10013.8329, the login page does not implement HSTS headers therefore not enforcing HTTPS. NOTE: the vendor's position is …

Mitigation only
Fix from $1,600 2023-02-01
Control CRITICAL 9.8
CVE-2019-16517

An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. There is a CORS misconfiguration, which reflected t…

No fix yet
Fix from $2,300 2020-01-23
Control HIGH 8.8
CVE-2019-16513

An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. CSRF can be used to send API requests.

No fix yet
Fix from $1,950 2020-01-23
Control HIGH 7.2
CVE-2019-16514

An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. The server allows remote code execution. Administra…

No fix yet
Fix from $1,950 2020-01-23
Control MEDIUM 6.5
CVE-2019-16515

An issue was discovered in ConnectWise Control (formerly known as ScreenConnect) 19.3.25270.7185. Certain HTTP security headers are not used.

No fix yet
Fix from $1,600 2020-01-23
Manage HIGH 8.8
CVE-2017-11726

services/system_io/actionprocessor/System.rails in ConnectWise Manage 2017.5 is vulnerable to Cross-Site Request Forgery (CSRF), as demonstrated by c…

No fix yet
Fix from $1,950 2017-07-31
Manage MEDIUM 6.1
CVE-2017-11727

services/system_io/actionprocessor/Contact.rails in ConnectWise Manage 2017.5 allows arbitrary client-side JavaScript code execution (involving a Con…

No fix yet
Fix from $1,600 2017-07-31