Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
devolutions devolutions server vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2022-3781
Dashlane password and Keepass Server password in My Account Settings are not encrypted in the database in Devolutions Remote Desktop Manager 2022.2.26 and prior versions and Devolutions Server 2022.3.1 and prior versions which allows database users to read the data. This issue af...
Devolutions Remote Desktop Manager
Devolutions Devolutions Server
NA
CVE-2023-5240
Improper access control in PAM propagation scripts in Devolutions Server 2023.2.8.0 and ealier allows an attack with permission to manage PAM propagation scripts to retrieve passwords stored in it via a GET request.
Devolutions Devolutions Server
NA
CVE-2023-5575
Improper access control in the permission inheritance in Devolutions Server 2022.3.13.0 and previous versions allows an attacker that compromised a low privileged user to access entries via a specific combination of permissions in the entry and in its parent.
Devolutions Devolutions Server
NA
CVE-2023-0951
Improper access controls on some API endpoints in Devolutions Server 2022.3.12 and previous versions could allow a standard privileged user to perform privileged actions.
Devolutions Devolutions Server
NA
CVE-2023-0952
Improper access controls on entries in Devolutions Server 2022.3.12 and previous versions could allow an authenticated user to access sensitive data without proper authorization.
Devolutions Devolutions Server
NA
CVE-2023-0953
Insufficient input sanitization in the documentation feature of Devolutions Server 2022.3.12 and previous versions allows an authenticated malicious user to perform an SQL Injection, potentially resulting in unauthorized access to system resources.
Devolutions Devolutions Server
NA
CVE-2023-1201
Improper access control in the secure messages feature in Devolutions Server 2022.3.12 and below allows an authenticated attacker that possesses the message UUID to access the data it contains.
Devolutions Devolutions Server
312
VMScore
CVE-2022-2316
HTML injection vulnerability in secure messages of Devolutions Server prior to 2022.2 allows malicious users to alter the rendering of the page or redirect a user to another site.
Devolutions Devolutions Server
NA
CVE-2023-2118
Insufficient access control in support ticket feature in Devolutions Server 2023.1.5.0 and below allows an authenticated malicious user to send support tickets and download diagnostic files via specific endpoints.
Devolutions Devolutions Server
578
VMScore
CVE-2022-33996
Incorrect permission management in Devolutions Server prior to 2022.2 allows a new user with a preexisting username to inherit the permissions of that previous user.
Devolutions Devolutions Server
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-49223
CVE-2024-0044
information disclosure
CVE-2024-35753
HTML injection
CVE-2024-21306
CVE-2024-35733
SQL injection
CVE-2024-35732
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
NEXT »