Skip to content
Noroxi

fleetdm records

28 published records for vendor fleetdm.

All records

28 records
  • SAML authentication vulnerability in Fleet

    CriticalCVSS 9.8No exploitEPSS 2%

    fleetdm · fleetDec 17, 2020

  • Fleet has a JWT signature bypass vulnerability in Azure AD MDM enrollment

    CriticalCVSS 9.3No exploitEPSS 0%

    fleetdm · fleetJan 21, 2026

  • Fleet server may terminate unexpectedly when handling certain gRPC requests

    HighCVSS 8.7No exploitEPSS 1%

    fleetdm · fleetMay 14, 2026

  • Fleet's unbounded request body read allows remote Denial of Service

    HighCVSS 8.7No exploitEPSS 0%

    fleetdm · fleetMar 27, 2026

  • Improper Authorization in github.com/fleetdm/fleet

    HighCVSS 8.1No exploitEPSS 1%

    fleetdm · fleetApr 18, 2022

  • Fleet Windows MDM Azure AD JWT Authentication Bypass

    HighCVSS 8.2No exploitEPSS 0%

    fleetdm · fleetMay 14, 2026

  • Fleet has a Windows MDM management endpoint authentication bypass

    HighCVSS 8.2No exploitEPSS 0%

    fleetdm · fleetMay 14, 2026

  • Fleet Affected by Local Privilege Escalation via Tcl Command Injection in Orbit

    HighCVSS 7.8No exploitEPSS 0%

    fleetdm · fleetApr 8, 2026

  • Fleet has a rate limiting bypass via untrusted client IP headers

    MediumCVSS 6.9No exploitEPSS 0%

    fleetdm · fleetMay 14, 2026

  • Fleet: IP spoofing allows bypassing API rate limiting

    MediumCVSS 6.9No exploitEPSS 0%

    fleetdm · fleetMay 14, 2026

  • Limited ability to spoof SAML authentication with missing audience verification

    MediumCVSS 6.5No exploitEPSS 1%

    fleetdm · fleetFeb 4, 2022

  • Fleet vulnerable to Denial of Service via unhandled gRPC log type in launcher endpoint

    MediumCVSS 6.6No exploitEPSS 0%

    fleetdm · fleetMar 27, 2026

  • Fleet Vulnerable to Windows MDM cross-device command disclosure

    MediumCVSS 6.6No exploitEPSS 0%

    fleetdm · fleetMar 27, 2026

  • Fleet vulnerable to SQL injection in MDM bootstrap package by authenticated team or global admin

    MediumCVSS 6.3No exploitEPSS 0%

    fleetdm · fleetMar 27, 2026

  • Fleet has an Access Control vulnerability in debug/pprof endpoints

    MediumCVSS 6.3No exploitEPSS 0%

    fleetdm · fleetJan 21, 2026

  • Fleet vulnerable to OS command injection in software packages

    MediumCVSS 6.0No exploitEPSS 1%

    fleetdm · fleetMay 14, 2026

  • Fleet: Password reset tokens remain valid after password change for 24 hours

    MediumCVSS 6.0No exploitEPSS 0%

    fleetdm · fleetMar 27, 2026

  • Fleet's Apple MDM profile delivery has second-order SQL injection that can compromise the database

    MediumCVSS 6.2No exploitEPSS 0%

    fleetdm · fleetMar 27, 2026

  • Fleet vulnerable to OS command injection via crafted software package metadata in uninstall scripts

    MediumCVSS 5.7No exploitEPSS 2%

    fleetdm · fleetMar 27, 2026

  • Fleet Windows MDM endpoint has a Cross-site Scripting vulnerability

    MediumCVSS 5.5No exploitEPSS 0%

    fleetdm · fleetJan 21, 2026

  • Fleet has a SQL injection via backtick escape in ORDER BY parameter

    MediumCVSS 5.1No exploitEPSS 1%

    fleetdm · fleetFeb 25, 2026

  • Fleet's team maintainer can transfer hosts from any team via missing source team authorization

    MediumCVSS 4.9No exploitEPSS 0%

    fleetdm · fleetMar 27, 2026

  • Fleet's user account creation via invite does not enforce invited email address

    MediumCVSS 4.9No exploitEPSS 0%

    fleetdm · fleetMar 27, 2026

  • Denial-of-service in Fleet

    LowCVSS 2.7No exploitEPSS 2%

    fleetdm · fleetFeb 10, 2021

  • Fleet: Unauthenticated Android device disenrollment vulnerability via Pub/Sub endpoint

    LowCVSS 1.7No exploitEPSS 0%

    fleetdm · fleetFeb 25, 2026