Show filters
200 Total Results
Displaying 41-50 of 200
Sort by:
Attacker Value
Unknown

CVE-2023-1580

Disclosure Date: April 02, 2023 (last updated November 08, 2023)
Uncontrolled resource consumption in the logging feature in Devolutions Gateway 2023.1.1 and earlier allows an attacker to cause a denial of service by filling up the disk and render the system unusable.
Attacker Value
Unknown

CVE-2023-1201

Disclosure Date: March 10, 2023 (last updated November 08, 2023)
Improper access control in the secure messages feature in Devolutions Server 2022.3.12 and below allows an authenticated attacker that possesses the message UUID to access the data it contains.
Attacker Value
Unknown

CVE-2023-0953

Disclosure Date: March 01, 2023 (last updated November 08, 2023)
Insufficient input sanitization in the documentation feature of Devolutions Server 2022.3.12 and earlier allows an authenticated attacker to perform an SQL Injection, potentially resulting in unauthorized access to system resources.
Attacker Value
Unknown

CVE-2023-0952

Disclosure Date: March 01, 2023 (last updated November 08, 2023)
Improper access controls on entries in Devolutions Server 2022.3.12 and earlier could allow an authenticated user to access sensitive data without proper authorization.
Attacker Value
Unknown

CVE-2023-0951

Disclosure Date: March 01, 2023 (last updated November 08, 2023)
Improper access controls on some API endpoints in Devolutions Server 2022.3.12 and earlier could allow a standard privileged user to perform privileged actions.
Attacker Value
Unknown

CVE-2023-0661

Disclosure Date: February 12, 2023 (last updated November 08, 2023)
Improper access control in Devolutions Server allows an authenticated user to access unauthorized sensitive data.
Attacker Value
Unknown

CVE-2022-44036

Disclosure Date: January 03, 2023 (last updated November 08, 2023)
In b2evolution 7.2.5, if configured with admins_can_manipulate_sensitive_files, arbitrary file upload is allowed for admins, leading to command execution. NOTE: the vendor's position is that this is "very obviously a feature not an issue and if you don't like that feature it is very obvious how to disable it."
Attacker Value
Unknown

CVE-2022-3781

Disclosure Date: November 01, 2022 (last updated November 08, 2023)
Dashlane password and Keepass Server password in My Account Settings  are not encrypted in the database in Devolutions Remote Desktop Manager 2022.2.26 and prior versions and Devolutions Server 2022.3.1 and prior versions which allows database users to read the data. This issue affects : Remote Desktop Manager 2022.2.26 and prior versions. Devolutions Server 2022.3.1 and prior versions.
Attacker Value
Unknown

CVE-2022-30935

Disclosure Date: September 28, 2022 (last updated October 08, 2023)
An authorization bypass in b2evolution allows remote, unauthenticated attackers to predict password reset tokens for any user through the use of a bad randomness function. This allows the attacker to get valid sessions for arbitrary users, and optionally reset their password. Tested and confirmed in a default installation of version 7.2.3. Earlier versions are affected, possibly earlier major versions as well.
Attacker Value
Unknown

CVE-2022-33996

Disclosure Date: July 07, 2022 (last updated October 07, 2023)
Incorrect permission management in Devolutions Server before 2022.2 allows a new user with a preexisting username to inherit the permissions of that previous user.