Devolutions / Powershell Universal
13 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-92237 | Insertion of sensitive information into log file in the slow query logging feature in Devolutions PowerShell Universal 2026.2.5 and earlier allows an authentic… | MEDIUM | 6.5 | Sep 15, 2026 |
| CVE-2026-19768 | Improper control of generation of code ('Code Injection') in the settings feature in Devolutions PowerShell Universal 2026.2.3 and earlier allows an authentica… | HIGH | 8.1 | Aug 14, 2026 |
| CVE-2026-16802 | Cleartext storage of sensitive information in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows a local actor with file sys… | MEDIUM | 6.5 | Jul 24, 2026 |
| CVE-2026-16801 | Improper control of generation of code ('Code Injection') in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authentic… | HIGH | 8.8 | Jul 24, 2026 |
| CVE-2026-16800 | Improper control of generation of code ('Code Injection') in the schedule feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authentica… | HIGH | 8.8 | Jul 24, 2026 |
| CVE-2026-16799 | Improper access control in the automation tests and workflows features in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user wi… | MEDIUM | 5.0 | Jul 24, 2026 |
| CVE-2026-16798 | Insertion of sensitive information into sent data in the automation jobs API in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated u… | MEDIUM | 6.5 | Jul 24, 2026 |
| CVE-2026-13437 | Insertion of sensitive information into sent data in the AI Agent job API in Devolutions PowerShell Universal 2026.2.0 allows an authenticated user with AI Age… | MEDIUM | 6.5 | Jun 29, 2026 |
| CVE-2026-8694 | Improper access control on the API documentation endpoint in PowerShell Universal | MEDIUM | 5.3 | Jun 12, 2026 |
| CVE-2026-3563 | Improper input validation in the apps and endpoints configuration in PowerShell Universal before 2026.1.4 allows an authenticated user with permissions to crea… | MEDIUM | 5.5 | Mar 17, 2026 |
| CVE-2026-4064 | Missing authorization checks on multiple gRPC service endpoints in PowerShell Universal before 2026.1.4 allows an authenticated user with any valid token to by… | HIGH | 8.3 | Mar 17, 2026 |
| CVE-2026-3277 | The OpenID Connect (OIDC) authentication configuration in PowerShell Universal before 2026.1.3 stores the OIDC client secret in cleartext in the .universal/aut… | MEDIUM | 6.5 | Feb 27, 2026 |
| CVE-2026-0618 | Cross-site Scripting vulnerability in Devolutions PowerShell Universal.This issue affects Powershell Universal: before 4.5.6, before 5.6.13. | MEDIUM | 6.1 | Jan 7, 2026 |
Showing 1 to 13 of 13 CVEs