Search Results (42 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-4989 1 Devolutions 2 Devolutions Server, Server 2026-04-07 4.3 Medium
Improper input validation in the gateway health check feature in Devolutions Server allows a low-privileged authenticated user to perform server-side request forgery (SSRF), potentially leading to information disclosure, via a crafted API request. This issue affects Server: from 2026.1.1 through 2026.1.11, from 2025.3.1 through 2025.3.17.
CVE-2026-4434 1 Devolutions 2 Devolutions Server, Server 2026-03-30 8.1 High
Improper certificate validation in the PAM propagation WinRM connections allows a network attacker to perform a man-in-the-middle attack via disabled TLS certificate verification.