Vulnerabilidades em Devolutions

176 resultados
Análise Vexday

Com 153 CVEs catalogadas e 35 surgidas nos últimos 90 dias, o portfólio de vulnerabilidades da Devolutions apresenta atividade recente relevante que merece acompanhamento contínuo. A taxa de exploração ativa está abaixo da média geral do catálogo CISA KEV, e nenhuma PoC pública foi identificada, o que reduz o risco imediato de exploração em massa. No entanto, a presença de 10 falhas críticas e o predomínio de CWE-284 (controle de acesso inadequado) indicam uma superfície de ataque estruturalmente sensível, especialmente em ambientes com gestão privilegiada de acessos remotos. A CVE mais perigosa atualmente rastreada, CVE-2021-42098, registra EPSS de 0,016, sugerindo probabilidade de exploração ainda baixa, mas equipes de segurança devem monitorar esse indicador dado o volume de novas entradas recentes.

CVE-2026-3204CRITICALImproper input validation in the error message page in Devolutions Server 2025.3.16 and earlier allows remote attackers to spoof the displaEPSS 0.5%CVE-2024-11671MEDIUMImproper authentication in SQL data source MFA validation in Devolutions Remote Desktop Manager 2024.3.17 and earlier on Windows allows an aEPSS 0.5%CVE-2024-10971MEDIUMImproper access control in the Password History feature in Devolutions DVLS 2024.3.6 and earlier allows a malicious authenticated user to obEPSS 0.5%CVE-2023-6264Information leak in Content-Security-Policy header in Devolutions Server 2023.3.7.0 allows an unauthenticated attacker to list the configureEPSS 0.5%CVE-2023-1980MEDIUMTwo factor authentication bypass on login in Devolutions Remote Desktop Manager 2022.3.35 and earlier allow user to cancel the two factorEPSS 0.5%CVE-2026-3224CRITICALAuthentication bypass in the Microsoft Entra ID (Azure AD) authentication mode in Devolutions Server 2025.3.15.0 and earlier allows an unautEPSS 0.5%CVE-2025-2280HIGHImproper access control in web extension restriction feature in Devolutions Server 2024.3.4.0 and earlier allows an authenticated user to EPSS 0.5%CVE-2026-13372HIGHIncorrect link resolution by display name in the custom PowerShell VPN editor in Devolutions Remote Desktop Manager 2026.2.5 through 2026.2.EPSS 0.5%CVE-2024-6055MEDIUMImproper removal of sensitive information in data source export feature in Devolutions Remote Desktop Manager 2024.1.32.0 and earlier on WinEPSS 0.5%CVE-2023-1574MEDIUMInformation disclosure in the user creation feature of a MSSQL data source in Devolutions Remote Desktop Manager 2023.1.9 and below on WindoEPSS 0.5%CVE-2022-3781MEDIUMDashlane password and Keepass Server password in My Account Settings  are not encrypted in the database in Devolutions Remote Desktop ManageEPSS 0.5%CVE-2024-12196MEDIUMIncorrect authorization in the permission component in Devolutions Server 2024.3.7.0 and earlier allows an authenticated user to view the paEPSS 0.5%CVE-2026-3130CRITICALImproper Enforcement of Behavioral Controls in Devolutions Server 2025.3.15 and earlier allows an authenticated attacker with the delete perEPSS 0.4%CVE-2025-2278MEDIUMImproper access control in temporary access requests and checkout requests endpoints in Devolutions Server 2024.3.13 and earlier allows an aEPSS 0.4%CVE-2023-2400LOWImproper deletion of resource in the user management feature in Devolutions Server 2023.1.8 and earlier allows an administrator to view useEPSS 0.4%CVE-2023-1202MEDIUMPermission bypass when importing or synchronizing entries in User vault in Devolutions Remote Desktop Manager 2023.1.9 and prior versions EPSS 0.4%CVE-2026-12161HIGHImproper input validation in the SSH Elevate Shell feature allows an authenticated user with permission to create or modify a shared SSH enEPSS 0.4%CVE-2026-13437MEDIUMInsertion of sensitive information into sent data in the AI Agent job API in Devolutions PowerShell Universal 2026.2.0 allows an authenticatEPSS 0.4%CVE-2025-2003HIGHIncorrect authorization in PAM vaults in Devolutions Server 2024.3.12 and earlier allows an authenticated user to bypass the 'add in root' pEPSS 0.4%CVE-2026-14536HIGHImproper enforcement of a mandatory multi-factor authentication policy in Devolutions Server 2026.2.9.0 allows an attacker with valid user cEPSS 0.4%