Screenconnect

Vendor:

First CVE: Sep 28, 2022 · Active for 3 years

8
Total CVEs
More Total CVEs than 85% of tracked products
2.7
Avg CVEs / Year
Higher CVE frequency than 75% of tracked products
7.4
Avg CVSS
Higher Avg CVSS than 48% of tracked products
37.5%
KEV Rate
Higher KEV Rate than 98% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Screenconnect over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 28, 2022
3 years ago
Most Recent CVE
Dec 18, 2025
217 days ago

CVE Severity & Scoring

Screenconnect8 CVEs
All CVEs352,101 CVEs
MediumHighCritical
Attack Vector
Local1 (12.5%)
Network7 (87.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (87.5%)
High1 (12.5%)
Unknown0 (0.0%)
User Interaction
None7 (87.5%)
Unknown0 (0.0%)
Required1 (12.5%)
Privileges Required
Low1 (12.5%)
High3 (37.5%)
None4 (50.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (8 CVEs).

8 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
ConnectWise ScreenConnect 23.9.7 and prior are affected by an Authentication Bypass Using an Alternate Path or Channel vulnerability, which may allow an attacker direct access to
Feb 21, 202410.099YESYES
ConnectWise ScreenConnect 23.9.7 and prior are affected by path-traversal vulnerability, which may allow an attacker the ability to execute remote code or directly impact confide
Feb 21, 20248.497YESYES
ScreenConnect versions 25.2.3 and earlier versions may be susceptible to a ViewState code injection attack. ASP.NET Web Forms use ViewState to preserve page and control state, with
Apr 25, 20257.263YESNO
In versions of ScreenConnect™ prior to 25.8, server-side validation and integrity checks within the extension subsystem could allow the installation and execution of untrusted or a
Dec 11, 20259.132NONO
ConnectWise ScreenConnect through 23.8.4 allows man-in-the-middle attackers to achieve remote code execution via crafted messages.
Feb 1, 20248.123NONO
In deployments using the ScreenConnect™ Certificate Signing Extension, encrypted configuration values including an Azure Key Vault-related key, could be returned to unauthenticated
Dec 18, 20255.320NONO
ConnectWise ScreenConnect versions 22.6 and below contained a flaw allowing potential brute force attacks on custom access tokens due to inadequate rate-limiting controls in the de
Sep 28, 20225.320NONO
ConnectWise ScreenConnect through 23.8.4 allows local users to connect to arbitrary relay servers via implicit trust of proxy settings
Feb 1, 20245.517NONO

Exploit Exposure

Signals from CVEs in this product scope (8 CVEs).

CISA KEV
3 CVEs
37.5% of CVEs· 98th percentile
Metasploit
2 CVEs
25.0% of CVEs· 98th percentile
Nuclei
1 CVE
12.5% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (8 CVEs).

Media Mentions

Signals from CVEs in this product scope (8 CVEs).

Top CNAs Publishing CVEs For Screenconnect

Top CWEs

Versions

No cataloged versions.