Show filters
200 Total Results
Displaying 41-50 of 200
Sort by:
Attacker Value
Unknown
CVE-2023-1580
Disclosure Date: April 02, 2023 (last updated November 08, 2023)
Uncontrolled resource consumption in the logging feature in Devolutions Gateway 2023.1.1 and earlier allows an attacker to cause a denial of service by filling up the disk and render the system unusable.
0
Attacker Value
Unknown
CVE-2023-1201
Disclosure Date: March 10, 2023 (last updated November 08, 2023)
Improper access control in the secure messages feature in Devolutions Server 2022.3.12 and below allows an authenticated attacker that possesses the message UUID to access the data it contains.
0
Attacker Value
Unknown
CVE-2023-0953
Disclosure Date: March 01, 2023 (last updated November 08, 2023)
Insufficient input sanitization in the documentation feature of Devolutions Server 2022.3.12 and earlier allows an authenticated attacker to perform an SQL Injection, potentially resulting in unauthorized access to system resources.
0
Attacker Value
Unknown
CVE-2023-0952
Disclosure Date: March 01, 2023 (last updated November 08, 2023)
Improper access controls on entries in Devolutions Server
2022.3.12 and earlier could allow an authenticated user to access
sensitive data without proper authorization.
0
Attacker Value
Unknown
CVE-2023-0951
Disclosure Date: March 01, 2023 (last updated November 08, 2023)
Improper access controls on some API endpoints in Devolutions Server 2022.3.12
and earlier could allow a standard privileged user to perform privileged
actions.
0
Attacker Value
Unknown
CVE-2023-0661
Disclosure Date: February 12, 2023 (last updated November 08, 2023)
Improper access control in Devolutions Server allows an authenticated user to access unauthorized sensitive data.
0
Attacker Value
Unknown
CVE-2022-44036
Disclosure Date: January 03, 2023 (last updated November 08, 2023)
In b2evolution 7.2.5, if configured with admins_can_manipulate_sensitive_files, arbitrary file upload is allowed for admins, leading to command execution. NOTE: the vendor's position is that this is "very obviously a feature not an issue and if you don't like that feature it is very obvious how to disable it."
0
Attacker Value
Unknown
CVE-2022-3781
Disclosure Date: November 01, 2022 (last updated November 08, 2023)
Dashlane password and Keepass Server password in My Account Settings are not encrypted in the database in Devolutions Remote Desktop Manager 2022.2.26 and prior versions and Devolutions Server 2022.3.1 and prior versions which allows database users to read the data.
This issue affects :
Remote Desktop Manager 2022.2.26 and prior versions.
Devolutions Server 2022.3.1 and prior versions.
0
Attacker Value
Unknown
CVE-2022-30935
Disclosure Date: September 28, 2022 (last updated October 08, 2023)
An authorization bypass in b2evolution allows remote, unauthenticated attackers to predict password reset tokens for any user through the use of a bad randomness function. This allows the attacker to get valid sessions for arbitrary users, and optionally reset their password. Tested and confirmed in a default installation of version 7.2.3. Earlier versions are affected, possibly earlier major versions as well.
0
Attacker Value
Unknown
CVE-2022-33996
Disclosure Date: July 07, 2022 (last updated October 07, 2023)
Incorrect permission management in Devolutions Server before 2022.2 allows a new user with a preexisting username to inherit the permissions of that previous user.
0