Show filters
82 Total Results
Displaying 71-80 of 82
Sort by:
Attacker Value
Unknown

CVE-2022-23849

Disclosure Date: March 03, 2022 (last updated October 07, 2023)
The biometric lock in Devolutions Password Hub for iOS before 2021.3.4 allows attackers to access the application because of authentication bypass. An attacker must rapidly make failed biometric authentication attempts.
Attacker Value
Unknown

CVE-2021-42098

Disclosure Date: October 18, 2021 (last updated February 23, 2025)
An incomplete permission check on entries in Devolutions Remote Desktop Manager before 2021.2.16 allows attackers to bypass permissions via batch custom PowerShell.
Attacker Value
Unknown

CVE-2021-36382

Disclosure Date: July 12, 2021 (last updated February 23, 2025)
Devolutions Server before 2021.1.18, and LTS before 2020.3.20, allows attackers to intercept private keys via a man-in-the-middle attack against the connections/partial endpoint (which accepts cleartext).
Attacker Value
Unknown

CVE-2021-28157

Disclosure Date: April 14, 2021 (last updated February 22, 2025)
An SQL Injection issue in Devolutions Server before 2021.1 and Devolutions Server LTS before 2020.3.18 allows an administrative user to execute arbitrary SQL commands via a username in api/security/userinfo/delete.
Attacker Value
Unknown

CVE-2021-28048

Disclosure Date: April 14, 2021 (last updated February 22, 2025)
An overly permissive CORS policy in Devolutions Server before 2021.1 and Devolutions Server LTS before 2020.3.18 allows a remote attacker to leak cross-origin data via a crafted HTML page.
Attacker Value
Unknown

CVE-2021-23921

Disclosure Date: April 01, 2021 (last updated February 22, 2025)
An issue was discovered in Devolutions Server before 2020.3. There is broken access control on Password List entry elements.
Attacker Value
Unknown

CVE-2021-23925

Disclosure Date: April 01, 2021 (last updated February 22, 2025)
An issue was discovered in Devolutions Server before 2020.3. There is a cross-site scripting (XSS) vulnerability in entries of type Document.
Attacker Value
Unknown

CVE-2021-23923

Disclosure Date: April 01, 2021 (last updated February 22, 2025)
An issue was discovered in Devolutions Server before 2020.3. There is Broken Authentication with Windows domain users.
Attacker Value
Unknown

CVE-2021-23924

Disclosure Date: April 01, 2021 (last updated February 22, 2025)
An issue was discovered in Devolutions Server before 2020.3. There is an exposure of sensitive information in diagnostic files.
Attacker Value
Unknown

CVE-2021-23922

Disclosure Date: April 01, 2021 (last updated February 22, 2025)
An issue was discovered in Devolutions Remote Desktop Manager before 2020.2.12. There is a cross-site scripting (XSS) vulnerability in webviews.