Show filters
26 Total Results
Displaying 11-20 of 26
Sort by:
Attacker Value
Unknown

CVE-2023-1603

Disclosure Date: April 02, 2023 (last updated November 08, 2023)
Permission bypass when importing or synchronizing entries in User vault in Devolutions Server 2022.3.13 and prior versions allows users with restricted rights to bypass entry permission via id collision.
Attacker Value
Unknown

CVE-2023-1201

Disclosure Date: March 10, 2023 (last updated November 08, 2023)
Improper access control in the secure messages feature in Devolutions Server 2022.3.12 and below allows an authenticated attacker that possesses the message UUID to access the data it contains.
Attacker Value
Unknown

CVE-2023-0953

Disclosure Date: March 01, 2023 (last updated November 08, 2023)
Insufficient input sanitization in the documentation feature of Devolutions Server 2022.3.12 and earlier allows an authenticated attacker to perform an SQL Injection, potentially resulting in unauthorized access to system resources.
Attacker Value
Unknown

CVE-2023-0952

Disclosure Date: March 01, 2023 (last updated November 08, 2023)
Improper access controls on entries in Devolutions Server 2022.3.12 and earlier could allow an authenticated user to access sensitive data without proper authorization.
Attacker Value
Unknown

CVE-2023-0951

Disclosure Date: March 01, 2023 (last updated November 08, 2023)
Improper access controls on some API endpoints in Devolutions Server 2022.3.12 and earlier could allow a standard privileged user to perform privileged actions.
Attacker Value
Unknown

CVE-2023-0661

Disclosure Date: February 12, 2023 (last updated November 08, 2023)
Improper access control in Devolutions Server allows an authenticated user to access unauthorized sensitive data.
Attacker Value
Unknown

CVE-2022-3781

Disclosure Date: November 01, 2022 (last updated November 08, 2023)
Dashlane password and Keepass Server password in My Account Settings  are not encrypted in the database in Devolutions Remote Desktop Manager 2022.2.26 and prior versions and Devolutions Server 2022.3.1 and prior versions which allows database users to read the data. This issue affects : Remote Desktop Manager 2022.2.26 and prior versions. Devolutions Server 2022.3.1 and prior versions.
Attacker Value
Unknown

CVE-2022-33996

Disclosure Date: July 07, 2022 (last updated October 07, 2023)
Incorrect permission management in Devolutions Server before 2022.2 allows a new user with a preexisting username to inherit the permissions of that previous user.
Attacker Value
Unknown

CVE-2022-2316

Disclosure Date: July 06, 2022 (last updated October 07, 2023)
HTML injection vulnerability in secure messages of Devolutions Server before 2022.2 allows attackers to alter the rendering of the page or redirect a user to another site.
Attacker Value
Unknown

CVE-2021-36382

Disclosure Date: July 12, 2021 (last updated February 23, 2025)
Devolutions Server before 2021.1.18, and LTS before 2020.3.20, allows attackers to intercept private keys via a man-in-the-middle attack against the connections/partial endpoint (which accepts cleartext).