Vulnerabilities
Vulnerable Software
Security Vulnerabilities
Improper authorization in the access request status endpoint in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated low-privileged user to approve their own pending access request via a direct call to the request status endpoint, bypassing the required approver review.
CVSS Score
7.1
EPSS Score
0.002
Published
2026-07-14
Improper authorization in the secure messages deletion endpoint in Devolutions Server 2026.2.11, 2026.1.22 allows an authenticated user to delete another user's messages via a direct object reference to the message identifier.
CVSS Score
3.1
EPSS Score
0.002
Published
2026-07-14
Missing cryptographic step in Windows Boot Loader allows an authorized attacker to bypass a security feature locally.
CVSS Score
6.0
EPSS Score
0.002
Published
2026-07-14
Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.
CVSS Score
7.0
EPSS Score
0.002
Published
2026-07-14
Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.
CVSS Score
7.8
EPSS Score
0.003
Published
2026-07-14
Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.
CVSS Score
7.8
EPSS Score
0.003
Published
2026-07-14
Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.
CVSS Score
7.8
EPSS Score
0.003
Published
2026-07-14
Use after free in Windows Client-Side Caching (CSC) Service allows an authorized attacker to elevate privileges locally.
CVSS Score
7.0
EPSS Score
0.002
Published
2026-07-14
Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
CVSS Score
7.8
EPSS Score
0.003
Published
2026-07-14
Improper access control in Microsoft 365 Copilot for iOS allows an unauthorized attacker to elevate privileges over a network.
CVSS Score
8.1
EPSS Score
0.007
Published
2026-07-14


Contact Us

Shodan ® - All rights reserved