Devolutions Inc.

First CVE: Oct 18, 2021Active for: 5 years
160
CVEs Published
More CVEs Published than 76% of tracked CNAs
26.7
Avg CVEs / Year
More Avg CVEs / Year than 75% of tracked CNAs
6.3
Avg CVSS Score
Higher Avg CVSS Score than 18% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by Devolutions Inc. as a CNA, 99.4% affect products that Devolutions Inc. develops as a vendor.

99.4%
Self-reported: 159Third-party: 1

Of all the CVEs published that affect products developed by Devolutions Inc., 91.9% are self-published by Devolutions Inc. as a CNA.

91.9%
Self-published: 159Published by other CNAs: 14

Trends Over Time

The number and severity of CVEs published by Devolutions Inc. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 18, 2021
4 years ago
Most Recent CVE
Jul 14, 2026
10 days ago

Top CVEs

All CVEs published by Devolutions Inc. as a CNA, regardless of affected vendor or product.

160 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Improper input validation in the SSH Elevate Shell feature allows an authenticated user with permission to create or modify a shared SSH entry to execute arbitrary commands on a
Jun 16, 20268.837NONO
Improper enforcement of a mandatory multi-factor authentication policy in Devolutions Server 2026.2.9.0 allows an attacker with valid user credentials to bypass the MFA Required po
Jul 6, 20268.835NONO
SQL Injection vulnerability in remote-sessions in Devolutions Server.This issue affects Devolutions Server 2025.3.1 through 2025.3.12
Jan 19, 20269.834NONO
Incorrect link resolution by display name in the custom PowerShell VPN editor in Devolutions Remote Desktop Manager 2026.2.5 through 2026.2.11 allows an authenticated attacker with
Jun 26, 20267.233NONO
Use of an incorrectly resolved name or reference in the pinget backend in Devolutions UniGetUI 2026.2.0 and earlier allows a WinGet community catalog contributor to cause an inst
Jun 17, 20267.532NONO
Improper handling of factor key state in the multi-factor authentication management feature in Devolutions Server allows an attacker with knowledge of a user's password to bypass t
May 22, 20267.632NONO
Improper authorization in the access request status endpoint in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated low-privileged user to approve their own pending acc
Jul 14, 20267.131NONO
Insertion of sensitive information into sent data in the AI Agent job API in Devolutions PowerShell Universal 2026.2.0 allows an authenticated user with AI Agent read access to obt
Jun 29, 20266.531NONO
Authentication bypass in the Microsoft Entra ID (Azure AD) authentication mode in Devolutions Server 2025.3.15.0 and earlier allows an unauthenticated user to authenticate as an ar
Mar 3, 20269.831NONO
Improper input validation in the error message page in Devolutions Server 2025.3.16 and earlier allows remote attackers to spoof the displayed error message via a specially crafte
Mar 3, 20269.831NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA160 CVEs
Severity distribution among all CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local11 (6.9%)
Network146 (91.3%)
Unknown0 (0.0%)
Physical2 (1.3%)
Adjacent Network1 (0.6%)
Attack Complexity
Low140 (87.5%)
High20 (12.5%)
Unknown0 (0.0%)
User Interaction
None142 (88.8%)
Unknown0 (0.0%)
Required18 (11.3%)
Privileges Required
Low108 (67.5%)
High13 (8.1%)
None39 (24.4%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (160 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by Devolutions Inc. as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Devolutions Inc. as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs