Vulnerabilities

Summary — last 7 days

New vulnerabilities3,042▲ 436 vs. last week
Critical / high1,431▲ 190 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)383▲ 168 vs. last week
–

423 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
Awaiting AnalysisMedium (5.4)0.17%—Devolutions ServerAI9/29/20269/30/2026
Improper access control in the partial connection API in Devolutions Server 2026.3.5.0 and earlier allows an authenticated low-privileged user to read, create, modify, and delete System Vault entries via a crafted API request.
Awaiting AnalysisMedium (4.3)0.19%—Devolutions ServerAI9/29/20269/29/2026
Improper rule enforcement in the PAM Active Directory provider in Devolutions Server 2026.3.5 allows a user with PAM edit permissions to bypass the Devolutions Gateway host ruleset.
Awaiting AnalysisMedium (5)0.16%—DevolutionsAI9/29/20269/29/2026
Missing authorization in the gateway network scan token API in Devolutions Server 2026.3.5.0 and earlier allows an authenticated low-privileged user to generate a network scan token and perform internal network discovery and port scanning through the gateway via a crafted API request.
Awaiting AnalysisHigh (7.2)0.07%—Devolutions ServerAI9/29/20269/30/2026
Cleartext storage of sensitive information in the database in Devolutions Server 2026.3.5.0 and earlier allows an attacker with read access to the database to obtain external identity provider tokens and active session identifiers via direct inspection of stored records.
Awaiting AnalysisMedium (5.4)0.17%—Devolutions ServerAI9/29/20269/29/2026
Missing authorization in the attachment history API in Devolutions Server 2026.3.5.0 and earlier allows an authenticated low-privileged user to permanently delete or restore vault attachments via a crafted API request.
Awaiting AnalysisMedium (6.5)0.22%—Devolutions ServerAI9/29/20269/29/2026
Missing authorization in the data source settings API in Devolutions Server 2026.3.5.0 and earlier allows an authenticated non-administrative user to disclose integration secrets via a crafted API request.
DeferredLow (2.1)0.45%—ST Engineering Idirect EvolutionAIST Engineering Velocity Webserver EvolutionAI9/21/20269/30/2026
A vulnerability was determined in ST Engineering iDirect Evolution and Velocity WebServer Evolution. This vulnerability affects unknown code of the file /authorize of the component HTTP Request Handler. Executing a manipulation of the argument Success can lead to http response splitting. It is possible to launch the…
DeferredLow (2.1)0.46%—ST Engineering Idirect EvolutionAIST Engineering Velocity Webserver EvolutionAI9/21/20269/30/2026
A vulnerability was found in ST Engineering iDirect Evolution and Velocity WebServer Evolution up to 20260717. This affects an unknown part of the component Location Header Handler. Performing a manipulation of the argument Host results in open redirect. It is possible to initiate the attack remotely. The exploit has…
DeferredCritical (9.2)0.85%—B2evolution CMSAI9/17/20269/23/2026
b2evolution CMS versions 6.7.8 through 7.2.5 contain an incomplete fix for CVE-2016-8901 where the serialized-array object check in param_check_serialized_array() fails to reject payloads with negative integer array keys. Unauthenticated attackers can submit crafted serialized PHP objects via POST requests to…
Awaiting AnalysisMedium (6.5)0.37%—Devolutions Powershell UniversalAI9/15/20269/16/2026
Insertion of sensitive information into log file in the slow query logging feature in Devolutions PowerShell Universal 2026.2.5 and earlier allows an authenticated user with log read permission to obtain application tokens, data protection key material and other stored credentials via SQL parameter values written to…
Awaiting AnalysisHigh (8.3)0.13%—DevolutionsAI9/15/20269/20/2026
Improper certificate validation on LDAPS connections to Active Directory in Devolutions Server 2026.2.16 and earlier allows a network-positioned attacker to intercept privileged directory service credentials via a spoofed domain controller certificate.
Awaiting AnalysisMedium (6.5)0.34%—DevolutionsAI9/15/20269/20/2026
Server-Side Request Forgery (SSRF) in the VMware synchronization feature in Devolutions Server 2026.2.16 and earlier allows a low-privileged authenticated user to obtain other users' credentials and reach internal or cloud-metadata network endpoints via a crafted connection definition submitted for datacenter…
Awaiting AnalysisMedium (6.5)0.35%—DevolutionsAI9/15/20269/20/2026
Improper access control in the vault entry listing feature in Devolutions Server 2026.2.16 and earlier allows an authenticated user lacking the view-password permission to obtain cleartext passwords via a request to the entry listing endpoint with password disclosure parameters.
Awaiting AnalysisMedium (4.8)0.14%—DevolutionsAI9/15/20269/20/2026
Improper certificate validation in the shared HTTP client used by synchronization and integration features in Devolutions Server 2026.2.16 and earlier allows a network-positioned attacker to intercept and tamper with outbound TLS connections via a spoofed or self-signed certificate.
DeferredMedium (6.9)0.45%—Evolution APIAI9/15/20269/24/2026
evolution-api through 2.3.7 contains an incorrect array comparison in the metricsIPWhitelist middleware that always evaluates to false, allowing unauthenticated access to the /metrics endpoint. Attackers can bypass IP whitelist restrictions to access sensitive metrics disclosing server version, database client name,…
Awaiting AnalysisMedium (6.3)0.53%—EvolutionAI9/10/20269/10/2026
A flaw was found in Evolution. A remote attacker can exploit this vulnerability by sending a specially crafted HTML email containing a spoofed vCard control. When a victim clicks on this control, Evolution's trusted JavaScript handler incorrectly assigns an attacker-controlled JavaScript URL to an iframe's source.…
Awaiting AnalysisMedium (4.3)0.15%—Devolutions Remote Desktop ManagerAIIronvncAI8/24/20268/28/2026
Insufficient verification of data authenticity in the IronVNC client in Devolutions Remote Desktop Manager 2026.2.17.0 and earlier, 2026.1.24.0 and earlier, allows an on-path attacker to intercept and tamper with VNC sessions via automatic acceptance of the server's RSA key during RSA-AES authentication.
Awaiting AnalysisHigh (8.1)0.39%—Devolutions Powershell UniversalAI8/14/20268/28/2026
Improper control of generation of code ('Code Injection') in the settings feature in Devolutions PowerShell Universal 2026.2.3 and earlier allows an authenticated user with settings management permission to execute arbitrary PowerShell code via a crafted setting value that is not properly escaped when written to the…
AnalyzedHigh (7.4)0.13%—Devolutions Password Manager7/29/20268/21/2026
Improper certificate validation in the Devolutions Server connection handling in Devolutions Password Manager 2026.2.1.0 and earlier on Android, iOS, and macOS allows an adjacent-network attacker to intercept and modify sensitive information via a forged TLS certificate.
AnalyzedMedium (4.3)0.25%—Devolutions Server7/27/20268/3/2026
Improper access control in the PAM password history endpoints in Devolutions Server allows an authenticated low-privileged user to disclose plaintext credential secrets via crafted API requests. This issue affects :
AnalyzedMedium (4.3)0.27%—Devolutions Server7/27/20268/3/2026
Improper access control in the NetBox synchronizer in Devolutions Server allows an authenticated user with view-only permission on an entry to obtain a stored API token via the partial connection endpoint. This issue affects :
AnalyzedHigh (8.8)0.42%—Devolutions Server7/27/20268/3/2026
Improper access control in the role membership management endpoint in Devolutions Server allows an authenticated non-administrative user holding the user-group membership management permission to escalate privileges to administrator via a crafted API request. This issue affects :
AnalyzedMedium (6.5)0.10%—Devolutions Powershell Universal7/24/20267/29/2026
Cleartext storage of sensitive information in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows a local actor with file system access to read secret values via secret variables stored in cleartext on disk when no vault is selected.
AnalyzedHigh (8.8)0.53%—Devolutions Powershell Universal7/24/20267/29/2026
Improper control of generation of code ('Code Injection') in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with variable write permission to execute arbitrary PowerShell code via a crafted variable value that is not properly escaped when written to the…
AnalyzedHigh (8.8)0.53%—Devolutions Powershell Universal7/24/20267/29/2026
Improper control of generation of code ('Code Injection') in the schedule feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with schedule creation permission to execute arbitrary PowerShell code via crafted schedule parameter names concatenated into a script invocation.