19 Total CVEs
19 AI Analyzed
0 CISA KEV
1 Critical

Profile

0% ended up actively exploited 0 of 19 added to CISA KEV
5% rated critical (CVSS 9.0+) 1 critical, 18 high
0 with a public exploit on record positive-only index; absence is not proof

Last 12 months

16 CVEs in the last 12 months

Products

  • Server12
  • PowerShell Universal4
  • Hub Reporting Service1
  • Remote Desktop Manager1
  • Devolutions Server1

5 products in total

Every figure counts the high and critical CVEs CVE Brief has published for this vendor, not every CVE the vendor has ever received. Exploitation means listing in the CISA Known Exploited Vulnerabilities catalog. No patch-availability figure is shown because CVE Brief does not measure it.

All Vendors
Showing 1-19 of 19 CVEs
CVE-2026-4924
Analyzed
8.2
Devolutions Server

Improper authentication in the two-factor authentication (2FA) feature in Devolutions Server 2026

2026-04-02
Full analysis →
CVE-2026-4828
Analyzed
8.2
Devolutions Server

Improper authentication in the OAuth login functionality in Devolutions Server 2026

2026-04-02
Full analysis →
CVE-2026-4396
Analyzed
8.3
Devolutions Hub Reporting Service

Improper certificate validation in Devolutions Hub Reporting Service 2025

2026-03-19
Full analysis →
CVE-2026-4064
Analyzed
8.3
Devolutions PowerShell Universal

Missing authorization checks on multiple gRPC service endpoints in PowerShell Universal before 2026

2026-03-18
Full analysis →
CVE-2026-19768
Analyzed
8.1
Devolutions PowerShell Universal

Improper control of generation of code ('Code Injection') in the settings feature in Devolutions PowerShell Universal 2026

2026-08-16
Full analysis →
CVE-2026-17568
Analyzed
8.8
Devolutions Server

Improper access control in the role membership management endpoint in Devolutions Server allows an authenticated non-administrative user holding the u...

2026-07-29
Full analysis →
CVE-2026-16801
Analyzed
8.8
Devolutions PowerShell Universal

Improper control of generation of code ('Code Injection') in the variables feature in Devolutions PowerShell Universal 2026

2026-07-25
Full analysis →
CVE-2026-16800
Analyzed
8.8
Devolutions PowerShell Universal

Improper control of generation of code ('Code Injection') in the schedule feature in Devolutions PowerShell Universal 2026

2026-07-25
Full analysis →
CVE-2026-15641
Analyzed
7.1
Devolutions Server

Improper authorization in the access request status endpoint in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated low-privileged user to...

2026-07-20
Full analysis →
CVE-2026-15637
Analyzed
7.5
Devolutions Server

Improper authorization in the PAM SSH key and certificate retrieval endpoints in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated low...

2026-07-20
Full analysis →
CVE-2026-14536
Analyzed
9.8
Devolutions Server

Devolutions Server 2026.2.4.0 through 2026.2.9.0 fails to enforce mandatory multi-factor authentication (MFA) policies when encountering invalid defau...

2026-07-11
Full analysis →
CVE-2026-12161
Analyzed
8.8
Devolutions Remote Desktop Manager

Improper input validation in the SSH Elevate Shell feature in Devolutions Remote Desktop Manager 2026

2026-06-17
Full analysis →
CVE-2026-1007
Analyzed
7.6
Devolutions Server

Incorrect Authorization vulnerability in virtual gateway component in Devolutions Server allows attackers to bypass deny IP rules

2026-01-21
Full analysis →
CVE-2025-8312
Analyzed
7.1
Devolutions Server

Deadlock in PAM automatic check-in feature in Devolutions Server allows a password to remain valid beyond the end of its intended check-out period due...

2025-07-30
Full analysis →
CVE-2025-6741
Analyzed
7.7
Devolutions Server

Improper access control in secure message component in Devolutions Server allows an authenticated user to steal unauthorized entries via the secure me...

2025-07-23
Full analysis →
CVE-2025-6523
Analyzed
7.7
Devolutions Server

Use of weak credentials in emergency authentication component in Devolutions Server allows an unauthenticated attacker to bypass authentication via br...

2025-07-23
Full analysis →
CVE-2025-12485
Analyzed
8.8
Devolutions Server

Improper privilege management during pre-MFA cookie handling in Devolutions Server 2025

2025-11-06
Full analysis →
CVE-2025-11957
Analyzed
8.4
Devolutions Server

Improper authorization in the temporary access workflow of Devolutions Server 2025

2025-10-22
Full analysis →
CVE-2025-11619
Analyzed
8.8
Devolutions Devolutions Server

Improper certificate validation when connecting to gateways in Devolutions Server 2025

2025-10-15
Full analysis →