VYPR

Remote Desktop Manager

by Devolutions

CVEs (53)

  • CVE-2024-0589MedJan 31, 2024
    risk 0.35cvss 5.4epss 0.00

    Cross-site scripting (XSS) vulnerability in the entry overview tab in Devolutions Remote Desktop Manager 2023.3.36 and earlier on Windows allows an attacker with access to a data source to inject a malicious script via a specially crafted input in an entry.

  • CVE-2021-23922MedApr 1, 2021
    risk 0.35cvss 5.4epss 0.01

    An issue was discovered in Devolutions Remote Desktop Manager before 2020.2.12. There is a cross-site scripting (XSS) vulnerability in webviews.

  • CVE-2021-28047MedApr 1, 2021
    risk 0.35cvss 5.4epss 0.01

    Cross-Site Scripting (XSS) in Administrative Reports in Devolutions Remote Desktop Manager before 2021.1 allows remote authenticated users to inject arbitrary web script or HTML via multiple input fields.

  • CVE-2024-6055MedJun 17, 2024
    risk 0.31cvss 4.7epss 0.01

    Improper removal of sensitive information in data source export feature in Devolutions Remote Desktop Manager 2024.1.32.0 and earlier on Windows allows an attacker that obtains the exported settings to recover powershell credentials configured on the data source via stealing the…

  • CVE-2022-1342MedJun 15, 2022
    risk 0.30cvss 4.6epss 0.00

    A lack of password masking in Devolutions Remote Desktop Manager allows physically proximate attackers to observe sensitive data. A caching issue can cause sensitive fields to sometimes stay revealed when closing and reopening a panel, which could lead to involuntarily…

  • CVE-2023-7047MedDec 21, 2023
    risk 0.29cvss 4.4epss 0.00

    Inadequate validation of permissions when employing remote tools and macros via the context menu within Devolutions Remote Desktop Manager versions 2023.3.31 and earlier permits a user to initiate a connection without proper execution rights via the remote tools feature.…

  • CVE-2024-11672MedNov 25, 2024
    risk 0.28cvss 4.3epss 0.01

    Incorrect authorization in the add permission component in Devolutions Remote Desktop Manager 2024.2.21 and earlier on Windows allows an authenticated malicious user to bypass the "Add" permission via the import in vault feature.

  • CVE-2024-3545MedApr 9, 2024
    risk 0.28cvss 4.3epss 0.00

    Improper permission handling in the vault offline cache feature in Devolutions Remote Desktop Manager 2024.1.20 and earlier on windows and Devolutions Server 2024.1.8 and earlier allows an attacker to access sensitive informations contained in the offline cache file by gaining…

  • CVE-2023-1939MedApr 11, 2023
    risk 0.28cvss 4.3epss 0.00

    No access control for the OTP key   on OTP entries in Devolutions Remote Desktop Manager Windows 2022.3.33.0 and prior versions and Remote Desktop Manager Linux 2022.3.2.0 and prior versions allows non admin users to see OTP keys via the user interface.

  • CVE-2025-2528LowMar 26, 2025
    risk 0.23cvss 3.6epss 0.00

    Improper authorization in application password policy in Devolutions Remote Desktop Manager on Windows allows an authenticated user to use a configuration different from the one mandated by the system administrators. This issue affects Remote Desktop Manager versions from…

  • CVE-2026-0747LowJan 8, 2026
    risk 0.21cvss 3.3epss 0.00

    Exposure of sensitive information in the TeamViewer entry dashboard component in Devolutions Remote Desktop Manager 2025.3.24.0 through 2025.3.28.0 on Windows allows an external observer to view a password on screen via a defective masking feature, for example during physical…

  • CVE-2023-0463LowJan 26, 2023
    risk 0.21cvss 3.3epss 0.00

    The force offline MFA prompt setting is not respected when switching to offline mode in Devolutions Remote Desktop Manager 2022.3.29 to 2022.3.30 allows a user to save sensitive data on disk.

  • CVE-2026-13372HigJun 26, 2026
    risk 0.00cvss 7.2epss 0.00

    Incorrect link resolution by display name in the custom PowerShell VPN editor in Devolutions Remote Desktop Manager 2026.2.5 through 2026.2.11 allows an authenticated attacker with write access to a shared workspace to execute a PowerShell script in another user's context via a…

Page 3 of 3