CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1 (more results available)

CVE-2026-100289 MEDIUM

Missing authorization in the gateway network scan token API in Devolutions Server 2026.3.5.0 and earlier allows an authenticated low-privileged user to generat…

CVSS 5.0 EPSS 0.16% Sep 29, 2026
CVE-2026-100288 HIGH

Cleartext storage of sensitive information in the database in Devolutions Server 2026.3.5.0 and earlier allows an attacker with read access to the database to…

CVSS 7.2 EPSS 0.07% Sep 29, 2026
CVE-2026-100287 MEDIUM

Missing authorization in the attachment history API in Devolutions Server 2026.3.5.0 and earlier allows an authenticated low-privileged user to permanently del…

CVSS 5.4 EPSS 0.17% Sep 29, 2026
CVE-2026-100286 MEDIUM

Missing authorization in the data source settings API in Devolutions Server 2026.3.5.0 and earlier allows an authenticated non-administrative user to disclose…

CVSS 6.5 EPSS 0.22% Sep 29, 2026
CVE-2026-93332 MEDIUM

Improper access control in the partial connection API in Devolutions Server 2026.3.5.0 and earlier allows an authenticated low-privileged user to read, create,…

CVSS 5.4 EPSS 0.17% Sep 29, 2026
CVE-2026-93330 MEDIUM

Improper rule enforcement in the PAM Active Directory provider in Devolutions Server 2026.3.5 allows a user with PAM edit permissions to bypass the Devolutions…

CVSS 4.3 EPSS 0.19% Sep 29, 2026
CVE-2026-92237 MEDIUM

Insertion of sensitive information into log file in the slow query logging feature in Devolutions PowerShell Universal 2026.2.5 and earlier allows an authentic…

CVSS 6.5 EPSS 0.37% Sep 15, 2026
CVE-2026-13327 HIGH

Improper certificate validation on LDAPS connections to Active Directory in Devolutions Server 2026.2.16 and earlier allows a network-positioned attacker to in…

CVSS 8.3 EPSS 0.13% Sep 15, 2026
CVE-2026-84850 MEDIUM

Improper certificate validation in the shared HTTP client used by synchronization and integration features in Devolutions Server 2026.2.16 and earlier allows a…

CVSS 4.8 EPSS 0.14% Sep 15, 2026
CVE-2026-90969 MEDIUM

Improper access control in the vault entry listing feature in Devolutions Server 2026.2.16 and earlier allows an authenticated user lacking the view-password p…

CVSS 6.5 EPSS 0.35% Sep 15, 2026
CVE-2026-90971 MEDIUM

Server-Side Request Forgery (SSRF) in the VMware synchronization feature in Devolutions Server 2026.2.16 and earlier allows a low-privileged authenticated user…

CVSS 6.5 EPSS 0.34% Sep 15, 2026
CVE-2026-78417 MEDIUM

Insufficient verification of data authenticity in the IronVNC client in Devolutions Remote Desktop Manager 2026.2.17.0 and earlier, 2026.1.24.0 and earlier, al…

CVSS 4.3 EPSS 0.15% Aug 24, 2026
CVE-2026-19768 HIGH

Improper control of generation of code ('Code Injection') in the settings feature in Devolutions PowerShell Universal 2026.2.3 and earlier allows an authentica…

CVSS 8.1 EPSS 0.39% Aug 14, 2026
CVE-2026-8497 HIGH

Improper certificate validation in the Devolutions Server connection handling in Devolutions Password Manager 2026.2.1.0 and earlier on Android, iOS, and macOS…

CVSS 7.4 EPSS 0.13% Jul 29, 2026
CVE-2026-17570 MEDIUM

Improper access control in the PAM password history endpoints in Devolutions Server allows an authenticated low-privileged user to disclose plaintext credentia…

CVSS 4.3 EPSS 0.25% Jul 27, 2026
CVE-2026-17569 MEDIUM

Improper access control in the NetBox synchronizer in Devolutions Server allows an authenticated user with view-only permission on an entry to obtain a stored…

CVSS 4.3 EPSS 0.27% Jul 27, 2026
CVE-2026-17568 HIGH

Improper access control in the role membership management endpoint in Devolutions Server allows an authenticated non-administrative user holding the user-group…

CVSS 8.8 EPSS 0.42% Jul 27, 2026
CVE-2026-16802 MEDIUM

Cleartext storage of sensitive information in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows a local actor with file sys…

CVSS 6.5 EPSS 0.10% Jul 24, 2026
CVE-2026-16801 HIGH

Improper control of generation of code ('Code Injection') in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authentic…

CVSS 8.8 EPSS 0.53% Jul 24, 2026
CVE-2026-16800 HIGH

Improper control of generation of code ('Code Injection') in the schedule feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authentica…

CVSS 8.8 EPSS 0.53% Jul 24, 2026
CVE-2026-16799 MEDIUM

Improper access control in the automation tests and workflows features in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user wi…

CVSS 5.0 EPSS 0.25% Jul 24, 2026
CVE-2026-16798 MEDIUM

Insertion of sensitive information into sent data in the automation jobs API in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated u…

CVSS 6.5 EPSS 0.38% Jul 24, 2026
CVE-2026-15058 LOW

Improper authorization in the secure messages deletion endpoint in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated user to delete another user'…

CVSS 3.1 EPSS 0.21% Jul 14, 2026
CVE-2026-15642 LOW

Insertion of sensitive information into a file in the Recovery Kit response file generation feature in Devolutions Server 2026.1.22.0, 2026.2.11.0 allows an at…

CVSS 3.3 EPSS 0.15% Jul 14, 2026
CVE-2026-15641 HIGH

Improper authorization in the access request status endpoint in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated low-privileged user to approve…

CVSS 7.1 EPSS 0.29% Jul 14, 2026

Showing 1 to 25 CVEs · page 1 (more available)