← Back

Devolutions

devolutions

168 CVEs • 10 products

Products (10)

Click to collapse
Toggle

CVEs (168)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Devolutions
1Devolutions Server
Jun 17, 2026
Apr 14, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
An overly permissive CORS policy in Devolutions Server before 2021.1 and Devolutions Server LTS before 2020.3.18 allows a remote attacker to leak cross-origin data via a crafted HTML page.
1Devolutions
1Devolutions Server
Jun 17, 2026
Apr 1, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in Devolutions Server before 2020.3. There is a cross-site scripting (XSS) vulnerability in entries of type Document.
1Devolutions
1Devolutions Server
Jun 17, 2026
Apr 1, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in Devolutions Server before 2020.3. There is an exposure of sensitive information in diagnostic files.
1Devolutions
1Devolutions Server
Jun 17, 2026
Apr 1, 2021
N/A· v4
8.1 HIGH· v3
4.9 MEDIUM· v2
An issue was discovered in Devolutions Server before 2020.3. There is Broken Authentication with Windows domain users.
1Devolutions
1Remote Desktop Manager
Jun 17, 2026
Apr 1, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in Devolutions Remote Desktop Manager before 2020.2.12. There is a cross-site scripting (XSS) vulnerability in webviews.
1Devolutions
1Devolutions Server
Jun 17, 2026
Apr 1, 2021
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
An issue was discovered in Devolutions Server before 2020.3. There is broken access control on Password List entry elements.
1Devolutions
1Remote Desktop Manager
Jun 17, 2026
Apr 1, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-Site Scripting (XSS) in Administrative Reports in Devolutions Remote Desktop Manager before 2021.1 allows remote authenticated users to inject arbitrary web script or HTML via multiple input fields.
1Devolutions
1Gfwx
Jun 17, 2026
Jan 26, 2021
N/A· v4
7.0 HIGH· v3
4.4 MEDIUM· v2
An issue was discovered in the gfwx crate before 0.3.0 for Rust. Because ImageChunkMut does not have bounds on its Send trait or Sync trait, a data race and memory corruption can occur.