Vulnerabilidades em Devolutions

176 resultados
Análise Vexday

Com 153 CVEs catalogadas e 35 surgidas nos últimos 90 dias, o portfólio de vulnerabilidades da Devolutions apresenta atividade recente relevante que merece acompanhamento contínuo. A taxa de exploração ativa está abaixo da média geral do catálogo CISA KEV, e nenhuma PoC pública foi identificada, o que reduz o risco imediato de exploração em massa. No entanto, a presença de 10 falhas críticas e o predomínio de CWE-284 (controle de acesso inadequado) indicam uma superfície de ataque estruturalmente sensível, especialmente em ambientes com gestão privilegiada de acessos remotos. A CVE mais perigosa atualmente rastreada, CVE-2021-42098, registra EPSS de 0,016, sugerindo probabilidade de exploração ainda baixa, mas equipes de segurança devem monitorar esse indicador dado o volume de novas entradas recentes.

CVE-2026-12105MEDIUMImproper access control in Devolutions Server 2026.2.5, 2026.1.21 allows an authenticated user to access attachments via folder duplicationEPSS 0.3%CVE-2025-13758LOWExposure of credentials in unintended requests in Devolutions Server.This issue affects Server: through 2025.2.20, through 2025.3.8.EPSS 0.3%CVE-2024-0589MEDIUMCross-site scripting (XSS) vulnerability in the entry overview tab in Devolutions Remote Desktop Manager 2023.3.36 and earlier on Windows alEPSS 0.3%CVE-2026-16801HIGHImproper control of generation of code ('Code Injection') in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier EPSS 0.3%CVE-2026-15641HIGHImproper authorization in the access request status endpoint in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated low-privilegEPSS 0.3%CVE-2024-3545MEDIUMImproper permission handling in the vault offline cache feature in Devolutions Remote Desktop Manager 2024.1.20 and earlier on windows and DEPSS 0.3%CVE-2024-12151MEDIUMIncorrect permission assignment in the user migration feature in Devolutions Server 2024.3.8.0 and earlier allows users to retain their old EPSS 0.3%CVE-2026-19768HIGHImproper control of generation of code ('Code Injection') in the settings feature in Devolutions PowerShell Universal 2026.2.3 and earlier aEPSS 0.3%CVE-2026-92237MEDIUMInsertion of sensitive information into log file in the slow query logging feature in Devolutions PowerShell Universal 2026.2.5 and earlier EPSS 0.3%CVE-2026-10696HIGHUse of an incorrectly resolved name or reference in the pinget backend in Devolutions UniGetUI 2026.2.0 and earlier allows a WinGet communiEPSS 0.3%CVE-2026-12117MEDIUMImproper access control in the social login connection endpoint in Devolutions Server 2026.2.5 allows an authenticated vault member to enuEPSS 0.3%CVE-2026-4828HIGHImproper authentication in the OAuth login functionality in Devolutions Server 2026.1.11 and earlier allows a remote attacker with valid creEPSS 0.3%CVE-2025-3768MEDIUMImproper access control in Tor network blocking feature in Devolutions Server 2025.1.10.0 and earlier allows an authenticated user to bypassEPSS 0.3%CVE-2026-5175MEDIUMImproper access control in the multi-factor authentication (MFA) management API in Devolutions Server allows an authenticated attacker to deEPSS 0.3%CVE-2026-15637HIGHImproper authorization in the PAM SSH key and certificate retrieval endpoints in Devolutions Server 2026.2.11, 2026.1.22 allows an authentEPSS 0.3%CVE-2026-8477LOWImproper enforcement of the sealed-entry workflow in the entry sensitive-data retrieval feature in Devolutions Server allows an authenticateEPSS 0.2%CVE-2026-7325HIGHImproper authorization in the Active Directory browsing feature in Devolutions Server allows a low-privileged authenticated user to obtain aEPSS 0.2%CVE-2024-2918LOWImproper input validation in PAM JIT elevation feature in Devolutions Server 2024.1.6 and earlier allows an attacker with access to the PAM EPSS 0.2%CVE-2025-11619HIGHImproper certificate validation when connecting to gateways in Devolutions Server 2025.3.2 and earlier allows attackers in MitM position to EPSS 0.2%CVE-2026-5171MEDIUMImproper access control in the entry activity log feature in Devolutions Server allows an authenticated user with access to an entry but witEPSS 0.2%