CVE-2025-13758
- EPSS 0.29%
- Veröffentlicht 27.11.2025 15:30:47
- Zuletzt bearbeitet 03.12.2025 14:46:33
Exposure of credentials in unintended requests in Devolutions Server.This issue affects Server: through 2025.2.20, through 2025.3.8.
CVE-2025-13757
- EPSS 0.57%
- Veröffentlicht 27.11.2025 15:30:30
- Zuletzt bearbeitet 03.12.2025 14:54:08
SQL Injection vulnerability in last usage logs in Devolutions Server.This issue affects Devolutions Server: through 2025.2.20, through 2025.3.8.
CVE-2025-13765
- EPSS 0.36%
- Veröffentlicht 27.11.2025 15:30:13
- Zuletzt bearbeitet 03.12.2025 14:47:18
Exposure of email service credentials to users without administrative rights in Devolutions Server.This issue affects Devolutions Server: before 2025.2.21, before 2025.3.9.
CVE-2025-12485
- EPSS 0.59%
- Veröffentlicht 06.11.2025 16:37:14
- Zuletzt bearbeitet 10.11.2025 16:31:06
Improper privilege management during pre-MFA cookie handling in Devolutions Server allows a low-privileged authenticated user to impersonate another account by replaying the pre-MFA cookie.This does not bypass the target account MFA verification step...
CVE-2025-12808
- EPSS 0.4%
- Veröffentlicht 06.11.2025 16:36:14
- Zuletzt bearbeitet 10.11.2025 16:30:59
Improper access control in Devolutions allows a View-only user to retrieve sensitive third-level nested fields, such as password lists custom values, resulting in password disclosure. This issue affects the following versions : * Devolutions...
- EPSS 0.31%
- Veröffentlicht 22.10.2025 17:15:56
- Zuletzt bearbeitet 25.11.2025 18:15:49
Improper authorization in the temporary access workflow of Devolutions Server 2025.2.12.0 and earlier allows an authenticated basic user to self-approve or approve the temporary access requests of other users and gain unauthorized access to vaults an...
CVE-2025-11958
- EPSS 0.42%
- Veröffentlicht 22.10.2025 17:15:56
- Zuletzt bearbeitet 25.11.2025 18:15:49
An improper input validation in the Security Dashboard ignored-tasks API of Devolutions Server 2025.2.15.0 and earlier allows an authenticated user to cause a denial of service to the Security Dashboard via a crafted request.
CVE-2025-11619
- EPSS 0.23%
- Veröffentlicht 15.10.2025 19:45:10
- Zuletzt bearbeitet 03.12.2025 14:51:58
Improper certificate validation when connecting to gateways in Devolutions Server 2025.3.2 and earlier allows attackers in MitM position to intercept traffic.
CVE-2025-8312
- EPSS 0.31%
- Veröffentlicht 30.07.2025 16:10:05
- Zuletzt bearbeitet 19.08.2025 13:15:41
Deadlock in PAM automatic check-in feature in Devolutions Server allows a password to remain valid beyond the end of its intended check-out period due to a deadlock occurring in the scheduling service.This issue affects the following version(s) : ...
CVE-2025-8353
- EPSS 0.4%
- Veröffentlicht 30.07.2025 16:06:46
- Zuletzt bearbeitet 06.08.2025 14:37:13
UI synchronization issue in the Just-in-Time (JIT) access request approval interface in Devolutions Server 2025.2.4.0 and earlier allows a remote authenticated attacker to gain unauthorized access to deleted JIT Groups via stale UI state during stand...