Screenconnect
Vendor:
First CVE: Sep 28, 2022 · Active for 3 years
8
Total CVEs
More Total CVEs than 85% of tracked products
2.7
Avg CVEs / Year
Higher CVE frequency than 75% of tracked products
7.4
Avg CVSS
Higher Avg CVSS than 48% of tracked products
37.5%
KEV Rate
Higher KEV Rate than 98% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Screenconnect over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 28, 2022
3 years ago
Most Recent CVE
Dec 18, 2025
217 days ago
CVE Severity & Scoring
Screenconnect8 CVEs
38%
38%
25%
All CVEs352,101 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (12.5%)
Network7 (87.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (87.5%)
High1 (12.5%)
Unknown0 (0.0%)
User Interaction
None7 (87.5%)
Unknown0 (0.0%)
Required1 (12.5%)
Privileges Required
Low1 (12.5%)
High3 (37.5%)
None4 (50.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-1709CRITICAL ConnectWise ScreenConnect 23.9.7 and prior are affected by an Authentication Bypass Using an Alternate Path or Channel
vulnerability, which may allow an attacker direct access to | Feb 21, 2024 | 10.0 | 99 | YES | YES |
CVE-2024-1708HIGH ConnectWise ScreenConnect 23.9.7 and prior are affected by path-traversal vulnerability, which may allow an attacker
the ability to execute remote code or directly impact confide | Feb 21, 2024 | 8.4 | 97 | YES | YES |
CVE-2025-3935HIGH ScreenConnect versions 25.2.3 and earlier versions may be susceptible to a ViewState code injection attack. ASP.NET Web Forms use ViewState to preserve page and control state, with | Apr 25, 2025 | 7.2 | 63 | YES | NO |
CVE-2025-14265CRITICAL In versions of ScreenConnect™ prior to 25.8, server-side validation and integrity checks within the extension subsystem could allow the installation and execution of untrusted or a | Dec 11, 2025 | 9.1 | 32 | NO | NO |
CVE-2023-47257HIGH ConnectWise ScreenConnect through 23.8.4 allows man-in-the-middle attackers to achieve remote code execution via crafted messages. | Feb 1, 2024 | 8.1 | 23 | NO | NO |
CVE-2025-14823MEDIUM In deployments using the ScreenConnect™ Certificate Signing Extension, encrypted configuration values including an Azure Key Vault-related key, could be returned to unauthenticated | Dec 18, 2025 | 5.3 | 20 | NO | NO |
CVE-2022-36781MEDIUM ConnectWise ScreenConnect versions 22.6 and below contained a flaw allowing potential brute force attacks on custom access tokens due to inadequate rate-limiting controls in the de | Sep 28, 2022 | 5.3 | 20 | NO | NO |
CVE-2023-47256MEDIUM ConnectWise ScreenConnect through 23.8.4 allows local users to connect to arbitrary relay servers via implicit trust of proxy settings | Feb 1, 2024 | 5.5 | 17 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (8 CVEs).
CISA KEV
3 CVEs
37.5% of CVEs· 98th percentile
Metasploit
2 CVEs
25.0% of CVEs· 98th percentile
Nuclei
1 CVE
12.5% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (8 CVEs).
Media Mentions
Signals from CVEs in this product scope (8 CVEs).
Top CNAs Publishing CVEs For Screenconnect
Top CWEs
Versions
No cataloged versions.