Security Advisories
CVE | Shortened Description | Severity | Issue Date | Updated on |
---|---|---|---|---|
CVE-2023-3897 | Bypassing CAPTCHA & Enumerating Usernames via Password Reset Page |
4.8 - Medium |
07/25/2023 | 07/25/2023 |
CVE-2023-2331 | Bypassing hardening via Unquoted Service path vulnerability |
7.8 - High |
04/27/2023 | 04/28/2023 |
CVE-2023-2335 | Plaintext Password in Registry |
6.5 - Medium |
04/27/2023 | 04/28/2023 |
CVE-2021-44228 | Apache Log4j Vulnerability (CVE-2021-44228) |
10.0 - High |
12/10/2021 | 02/06/2023 |
CVE-2022-42889 | Apache Commons Text "Text4Shell" |
9.8 - High |
10/13/2022 | 03/01/2023 |
CVE-2018-15656 | An issue was discovered in the registration API endpoint in 42Gears SureMDM before 2018-11-27. An attacker can submit a GET request to /api/register/:email |
7.5 - High |
02/04/2019 | 03/23/2021 |
CVE-2018-15658 | An issue was discovered in 42Gears SureMDM before 2018-11-27. By visiting the page found at /console/ConsolePage/Master.html, an attacker is able to see the markup that would be presented to an authenticated user |
7.5 - High |
02/04/2019 | 03/23/2021 |
CVE-2018-15657 | An SSRF issue was discovered in 42Gears SureMDM before 2018-11-27 via the /api/DownloadUrlResponse.ashx "url" parameter. |
7.3 - High |
02/04/2019 | 03/23/2021 |
CVE-2018-15655 CVE-2018-15659 | An issue was discovered in 42Gears SureMDM before 2018-11-27, related to CORS settings. Cross-origin access is possible. |
6.5 - Medium |
02/05/2019 | 02/05/2019 |