Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
devolutions devolutions server vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2023-2400
Improper deletion of resource in the user management feature in Devolutions Server 2023.1.8 and previous versions allows an administrator to view users vaults of deleted users via database access.
Devolutions Devolutions Server
NA
CVE-2023-0951
Improper access controls on some API endpoints in Devolutions Server 2022.3.12 and previous versions could allow a standard privileged user to perform privileged actions.
Devolutions Devolutions Server
NA
CVE-2023-0952
Improper access controls on entries in Devolutions Server 2022.3.12 and previous versions could allow an authenticated user to access sensitive data without proper authorization.
Devolutions Devolutions Server
NA
CVE-2023-0953
Insufficient input sanitization in the documentation feature of Devolutions Server 2022.3.12 and previous versions allows an authenticated malicious user to perform an SQL Injection, potentially resulting in unauthorized access to system resources.
Devolutions Devolutions Server
6.5
CVSSv2
CVE-2022-33996
Incorrect permission management in Devolutions Server prior to 2022.2 allows a new user with a preexisting username to inherit the permissions of that previous user.
Devolutions Devolutions Server
3.5
CVSSv2
CVE-2022-2316
HTML injection vulnerability in secure messages of Devolutions Server prior to 2022.2 allows malicious users to alter the rendering of the page or redirect a user to another site.
Devolutions Devolutions Server
NA
CVE-2023-2118
Insufficient access control in support ticket feature in Devolutions Server 2023.1.5.0 and below allows an authenticated malicious user to send support tickets and download diagnostic files via specific endpoints.
Devolutions Devolutions Server
NA
CVE-2023-6264
Information leak in Content-Security-Policy header in Devolutions Server 2023.3.7.0 allows an unauthenticated malicious user to list the configured Devolutions Gateways endpoints.
Devolutions Devolutions Server
NA
CVE-2023-2445
Improper access control in Subscriptions Folder path filter in Devolutions Server 2023.1.1 and previous versions allows attackers with administrator privileges to retrieve usage information on folders in user vaults via a specific folder name.
Devolutions Devolutions Server
NA
CVE-2023-0661
Improper access control in Devolutions Server allows an authenticated user to access unauthorized sensitive data.
Devolutions Devolutions Server
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
type confusion
CVE-2023-38506
CVE-2024-37198
CVE-2023-45197
CVE-2024-38621
CVE-2024-30103
elevation of privilege
CVE-2024-0044
IMAP
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
NEXT »