Vulnerabilities > Devolutions > Devolutions Server > 2019.1.18.0

DATE CVE VULNERABILITY TITLE RISK
2023-03-10 CVE-2023-1201 Unspecified vulnerability in Devolutions Server
Improper access control in the secure messages feature in Devolutions Server 2022.3.12 and below allows an authenticated attacker that possesses the message UUID to access the data it contains.
network
low complexity
devolutions
6.5
2023-03-01 CVE-2023-0951 Unspecified vulnerability in Devolutions Server
Improper access controls on some API endpoints in Devolutions Server 2022.3.12 and earlier could allow a standard privileged user to perform privileged actions.
network
low complexity
devolutions
8.8
2023-03-01 CVE-2023-0952 Incorrect Authorization vulnerability in Devolutions Server
Improper access controls on entries in Devolutions Server 2022.3.12 and earlier could allow an authenticated user to access sensitive data without proper authorization.
network
low complexity
devolutions CWE-863
6.5
2023-03-01 CVE-2023-0953 SQL Injection vulnerability in Devolutions Server
Insufficient input sanitization in the documentation feature of Devolutions Server 2022.3.12 and earlier allows an authenticated attacker to perform an SQL Injection, potentially resulting in unauthorized access to system resources.
network
low complexity
devolutions CWE-89
8.8
2022-11-01 CVE-2022-3781 Insufficiently Protected Credentials vulnerability in Devolutions Remote Desktop Manager
Dashlane password and Keepass Server password in My Account Settings  are not encrypted in the database in Devolutions Remote Desktop Manager 2022.2.26 and prior versions and Devolutions Server 2022.3.1 and prior versions which allows database users to read the data. This issue affects : Remote Desktop Manager 2022.2.26 and prior versions. Devolutions Server 2022.3.1 and prior versions.
network
low complexity
devolutions CWE-522
6.5
2022-07-07 CVE-2022-33996 Incorrect Default Permissions vulnerability in Devolutions Server
Incorrect permission management in Devolutions Server before 2022.2 allows a new user with a preexisting username to inherit the permissions of that previous user.
network
low complexity
devolutions CWE-276
8.8
2022-07-06 CVE-2022-2316 Cross-site Scripting vulnerability in Devolutions Server
HTML injection vulnerability in secure messages of Devolutions Server before 2022.2 allows attackers to alter the rendering of the page or redirect a user to another site.
network
low complexity
devolutions CWE-79
5.4
2021-07-12 CVE-2021-36382 Insufficiently Protected Credentials vulnerability in Devolutions Server
Devolutions Server before 2021.1.18, and LTS before 2020.3.20, allows attackers to intercept private keys via a man-in-the-middle attack against the connections/partial endpoint (which accepts cleartext).
network
high complexity
devolutions CWE-522
3.7
2021-04-01 CVE-2021-23925 Cross-site Scripting vulnerability in Devolutions Server
An issue was discovered in Devolutions Server before 2020.3.
network
low complexity
devolutions CWE-79
6.1
2021-04-01 CVE-2021-23924 Information Exposure Through Log Files vulnerability in Devolutions Server
An issue was discovered in Devolutions Server before 2020.3.
network
low complexity
devolutions CWE-532
7.5