Devolutions / Remote Desktop Manager
53 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-78417 | Insufficient verification of data authenticity in the IronVNC client in Devolutions Remote Desktop Manager 2026.2.17.0 and earlier, 2026.1.24.0 and earlier, al… | MEDIUM | 4.3 | Aug 24, 2026 |
| CVE-2026-13372 | Incorrect link resolution by display name in the custom PowerShell VPN editor in Devolutions Remote Desktop Manager 2026.2.5 through 2026.2.11 allows an authen… | HIGH | 7.2 | Jun 26, 2026 |
| CVE-2026-12162 | Improper host validation in the social login autofill feature in Devolutions Remote Desktop Manager 2026.2.8 allows an attacker to disclose stored social login… | MEDIUM | 5.5 | Jun 15, 2026 |
| CVE-2026-12161 | Improper input validation in the SSH Elevate Shell feature allows an authenticated user with permission to create or modify a shared SSH entry to execute arbit… | HIGH | 8.8 | Jun 15, 2026 |
| CVE-2026-2590 | Improper enforcement of the Disable password saving in vaults setting in the connection entry component in Devolutions Remote Desktop Manager 2025.3.30 and ear… | CRITICAL | 9.8 | Mar 3, 2026 |
| CVE-2026-0747 | Exposure of sensitive information in the TeamViewer entry dashboard component in Devolutions Remote Desktop Manager 2025.3.24.0 through 2025.3.28.0 on Windows… | LOW | 3.3 | Jan 8, 2026 |
| CVE-2025-13683 | Exposure of credentials in unintended requests in Devolutions Server, Remote Desktop Manager on Windows.This issue affects Devolutions Server: through 2025.3.8… | MEDIUM | 6.5 | Nov 28, 2025 |
| CVE-2025-5334 | Exposure of private personal information to an unauthorized actor in the user vaults component of Devolutions Remote Desktop Manager allows an authenticated us… | HIGH | 7.5 | May 29, 2025 |
| CVE-2025-2600 | Improper authorization in the variable component in Devolutions Remote Desktop Manager on Windows allows an authenticated user to use the ELEVATED_PASSWORD var… | MEDIUM | 6.8 | Mar 26, 2025 |
| CVE-2025-2562 | Insufficient logging in the autotyping feature in Devolutions Remote Desktop Manager on Windows allows an authenticated user to use a stored password without g… | MEDIUM | 5.4 | Mar 26, 2025 |
| CVE-2025-2528 | Improper authorization in application password policy in Devolutions Remote Desktop Manager on Windows allows an authenticated user to use a configuration diff… | LOW | 3.6 | Mar 26, 2025 |
| CVE-2025-2499 | Client side access control bypass in the permission component in Devolutions Remote Desktop Manager on Windows. An authenticated user can exploit this flaw to… | MEDIUM | 5.4 | Mar 26, 2025 |
| CVE-2025-1636 | Exposure of sensitive information in My Personal Credentials password history component in Devolutions Remote Desktop Manager 2024.3.29 and earlier on Windows… | MEDIUM | 6.5 | Mar 13, 2025 |
| CVE-2025-1635 | Exposure of sensitive information in hub data source export feature in Devolutions Remote Desktop Manager 2024.3.29 and earlier on Windows allows a user export… | MEDIUM | 6.5 | Mar 13, 2025 |
| CVE-2024-11621 | Missing certificate validation in Devolutions Remote Desktop Manager on macOS, iOS, Android, Linux allows an attacker to intercept and modify encrypted communi… | HIGH | 8.8 | Feb 10, 2025 |
| CVE-2025-1193 | Improper host validation in the certificate validation component in Devolutions Remote Desktop Manager on 2024.3.19 and earlier on Windows allows an attacker t… | HIGH | 8.1 | Feb 10, 2025 |
| CVE-2024-12149 | Incorrect permission assignment in temporary access requests component in Devolutions Remote Desktop Manager 2024.3.19.0 and earlier on Windows allows an authe… | HIGH | 8.1 | Dec 4, 2024 |
| CVE-2024-11670 | Incorrect authorization in the permission validation component of Devolutions Remote Desktop Manager 2024.2.21 and earlier on Windows allows a malicious authen… | MEDIUM | 5.4 | Nov 25, 2024 |
| CVE-2024-11671 | Improper authentication in SQL data source MFA validation in Devolutions Remote Desktop Manager 2024.3.17 and earlier on Windows allows an authenticated user t… | MEDIUM | 5.4 | Nov 25, 2024 |
| CVE-2024-11672 | Incorrect authorization in the add permission component in Devolutions Remote Desktop Manager 2024.2.21 and earlier on Windows allows an authenticated maliciou… | MEDIUM | 4.3 | Nov 25, 2024 |
| CVE-2024-7421 | An information exposure in Devolutions Remote Desktop Manager 2024.2.20.0 and earlier on Windows allows local attackers with access to system logs to obtain se… | MEDIUM | 5.5 | Sep 25, 2024 |
| CVE-2024-6492 | Exposure of Sensitive Information in edge browser session proxy feature in Devolutions Remote Desktop Manager 2024.2.14.0 and earlier on Windows allows an atta… | HIGH | 7.4 | Jul 16, 2024 |
| CVE-2024-6354 | Improper access control in PAM dashboard in Devolutions Remote Desktop Manager 2024.2.11 and earlier on Windows allows an authenticated user to bypass the exec… | HIGH | 7.2 | Jun 26, 2024 |
| CVE-2024-6057 | Improper authentication in the vault password feature in Devolutions Remote Desktop Manager 2024.1.31.0 and earlier allows an attacker that has compromised an… | CRITICAL | 9.8 | Jun 17, 2024 |
| CVE-2024-6055 | Improper removal of sensitive information in data source export feature in Devolutions Remote Desktop Manager 2024.1.32.0 and earlier on Windows allows an atta… | MEDIUM | 4.7 | Jun 17, 2024 |
Showing 1 to 25 of 53 CVEs