Devolutions
63 known vulnerabilities
Top Products
Improper certificate validation in the PAM propagation WinRM connections allows a network attacker to perform a man-in-
Improper certificate validation in Devolutions Hub Reporting Service 2025.3.1.1 and earlier allows a network attacker t
Improper access control in user and role restore API endpoints in Devolutions Server 2025.3.11.0 and earlier allows a lo
Authentication bypass in the Microsoft Entra ID (Azure AD) authentication mode in Devolutions Server 2025.3.15.0 and ear
Improper input validation in the error message page in Devolutions Server 2025.3.16 and earlier allows remote attackers
Improper Enforcement of Behavioral Controls in Devolutions Server 2025.3.15 and earlier allows an authenticated attacker
Improper enforcement of the Disable password saving in vaults setting in the connection entry component in Devolutions
Sensitive user account information is not encrypted in the database in Devolutions Server 2025.3.14 and earlier, which
Improper access control in multiple DVLS REST API endpoints in Devolutions Server 2025.3.14.0 and earlier allows an au
A permission cache poisoning vulnerability in Devolutions Server allows authenticated users to bypass permissions to acc
Incorrect Authorization vulnerability in virtual gateway component in Devolutions Server allows attackers to bypass deny
SQL Injection vulnerability in remote-sessions in Devolutions Server.This issue affects Devolutions Server 2025.3.1 thro
Exposure of sensitive information in the TeamViewer entry dashboard component in Devolutions Remote Desktop Manager 2025
Frequently Asked Questions
How many CVEs affect Devolutions?
Devolutions has 63 CVE records in our database, including 5 critical and 17 high severity vulnerabilities.
What are the most severe Devolutions vulnerabilities?
Devolutions has 5 critical severity (CVSS 9.0+) and 17 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Devolutions vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Devolutions products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Devolutions Vulnerabilities
CyberStrike scans your infrastructure for Devolutions vulnerabilities and provides real-time remediation guidance.
Get Started