ConnectWise / ScreenConnect
10 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-84869 KEV | ScreenConnect Client: Guest-to-Host File Execution via File-Transfer Actions | CRITICAL | 9.9 | Sep 8, 2026 |
| CVE-2026-11596 | In ScreenConnect™ versions prior to 26.2, input validation within the Host Pass creation functionality could allow an authenticated user with Host Pass creatio… | MEDIUM | 4.7 | Jun 10, 2026 |
| CVE-2026-3564 | ScreenConnect Instance Level Cryptographic Material Exposure | CRITICAL | 9.0 | Mar 17, 2026 |
| CVE-2025-14823 | Certificate Signing Extension Returns Encrypted Values | MEDIUM | 5.3 | Dec 18, 2025 |
| CVE-2025-14265 | Improper server-side validation in ScreenConnect extension framework | CRITICAL | 9.1 | Dec 11, 2025 |
| CVE-2025-3935 KEV | ScreenConnect Exposure to ASP.NET ViewState Code Injection | HIGH | 8.1 | Apr 25, 2025 |
| CVE-2024-1709 KEV | Authentication bypass using an alternate path or channel | CRITICAL | 10.0 | Feb 21, 2024 |
| CVE-2024-1708 KEV | Improper limitation of a pathname to a restricted directory (“path traversal”) | HIGH | 8.4 | Feb 21, 2024 |
| CVE-2023-47257 | ConnectWise ScreenConnect through 23.8.4 allows man-in-the-middle attackers to achieve remote code execution via crafted messages. | HIGH | 8.1 | Feb 1, 2024 |
| CVE-2023-47256 | ConnectWise ScreenConnect through 23.8.4 allows local users to connect to arbitrary relay servers via implicit trust of proxy settings | MEDIUM | 5.5 | Feb 1, 2024 |
| CVE-2022-36781 | ConnectWise - ScreenConnect Session Code Bypass | MEDIUM | 5.3 | Sep 28, 2022 |
Showing 1 to 10 of 10 CVEs