Skip to content

Security Advisories

CVE Shortened Description Severity Issue Date Updated on
CVE-2023-3897 Bypassing CAPTCHA & Enumerating Usernames via Password Reset Page
4.8 - Medium
07/25/2023 07/25/2023
CVE-2023-2331 Bypassing hardening via Unquoted Service path vulnerability
7.8 - High
04/27/2023 04/28/2023
CVE-2023-2335 Plaintext Password in Registry
6.5 - Medium
04/27/2023 04/28/2023
CVE-2021-44228 Apache Log4j Vulnerability (CVE-2021-44228)
10.0 - High
12/10/2021 02/06/2023
CVE-2022-42889 Apache Commons Text "Text4Shell"
9.8 - High
10/13/2022 03/01/2023
CVE-2018-15656 An issue was discovered in the registration API endpoint in 42Gears SureMDM before 2018-11-27. An attacker can submit a GET request to /api/register/:email
7.5 - High
02/04/2019 03/23/2021
CVE-2018-15658 An issue was discovered in 42Gears SureMDM before 2018-11-27. By visiting the page found at /console/ConsolePage/Master.html, an attacker is able to see the markup that would be presented to an authenticated user
7.5 - High
02/04/2019 03/23/2021
CVE-2018-15657 An SSRF issue was discovered in 42Gears SureMDM before 2018-11-27 via the /api/DownloadUrlResponse.ashx "url" parameter.
7.3 - High
02/04/2019 03/23/2021
CVE-2018-15655 CVE-2018-15659 An issue was discovered in 42Gears SureMDM before 2018-11-27, related to CORS settings. Cross-origin access is possible.
6.5 - Medium
02/05/2019 02/05/2019