Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Securenvoy

First CVE: Mar 15, 2018Active for: 8 yearsTotal CVEs: 12
41.1
VTI Score
High

Securenvoy develops a focused portfolio of multi-factor authentication and secure communications products, including SecureMail and SecureAccess, deployed in environments where authentication and message confidentiality are critical. Vulnerabilities affecting the vendor skew toward critical severity and frequently acquire public exploit code, while the recurring weakness classes—path traversal, cross-site scripting, cleartext transmission, CSRF, and information exposure—reflect the authentication-boundary and web-interface risks inherent to identity and communications systems. Defenders should treat updates for this vendor's MFA and access-control solutions as high-priority given their role in the security perimeter; live severity and exploitation figures are shown alongside this summary.

FAUCET AI Generated
12
Total CVEs
More Total CVEs than 93% of tracked vendors
0.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
7.0
Avg CVSS Score
Higher Avg CVSS Score than 50% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Securenvoy over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 15, 2018
8 years ago
Most Recent CVE
Mar 19, 2025
492 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (12 CVEs).

12 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-7702CRITICAL
SecurEnvoy SecurMail before 9.2.501 allows remote attackers to spoof transmission of arbitrary e-mail messages, resend e-mail messages to arbitrary recipients, or modify arbitrary
Mar 15, 20189.144NOYES
CVE-2018-7705HIGH
Directory traversal vulnerability in SecurEnvoy SecurMail before 9.2.501 allows remote authenticated users to read e-mail messages to arbitrary recipients via a .. (dot dot) in the
Mar 15, 20188.137NOYES
CVE-2024-37393HIGH
Multiple LDAP injections vulnerabilities exist in SecurEnvoy MFA before 9.4.514 due to improper validation of user-supplied input. An unauthenticated remote attacker could exfiltra
Jun 10, 20247.533NOYES
CVE-2018-7706MEDIUM
Directory traversal vulnerability in SecurEnvoy SecurMail before 9.2.501 allows remote authenticated users to read arbitrary e-mail messages via a .. (dot dot) in the option2 param
Mar 15, 20186.533NOYES
CVE-2018-7704MEDIUM
SecurEnvoy SecurMail before 9.2.501 allows remote authenticated users to read arbitrary e-mail messages via the option1 parameter in a reply action to secmail/getmessage.exe.
Mar 15, 20186.532NOYES
CVE-2018-7701MEDIUM
Multiple cross-site request forgery (CSRF) vulnerabilities in SecurEnvoy SecurMail before 9.2.501 allow remote attackers to hijack the authentication of arbitrary users for request
Mar 15, 20186.531NOYES
CVE-2018-7707MEDIUM
Cross-site scripting (XSS) vulnerability in SecurEnvoy SecurMail before 9.2.501 allows remote attackers to inject arbitrary web script or HTML via an HTML-formatted e-mail message.
Mar 15, 20186.130NOYES
CVE-2018-7703MEDIUM
Cross-site scripting (XSS) vulnerability in SecurEnvoy SecurMail before 9.2.501 allows remote attackers to inject arbitrary web script or HTML via the mailboxid parameter to secmai
Mar 15, 20186.130NOYES
CVE-2020-13376CRITICAL
SecurEnvoy SecurMail 9.3.503 allows attackers to upload executable files and achieve OS command execution via a crafted SecurEnvoyReply cookie.
Aug 7, 20209.029NONO
CVE-2025-30236HIGH
Shearwater SecurEnvoy SecurAccess Enrol before 9.4.515 allows authentication through only a six-digit TOTP code (skipping a password check) if an HTTP POST request contains a SESSI
Mar 19, 20258.625NONO
View all 12 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products12 CVEs
8%
42%
33%
17%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (8.3%)
Network11 (91.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (75.0%)
High3 (25.0%)
Unknown0 (0.0%)
User Interaction
None9 (75.0%)
Unknown0 (0.0%)
Required3 (25.0%)
Privileges Required
Low5 (41.7%)
High0 (0.0%)
None7 (58.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (12 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
8.3% of CVEs· 96th percentile
ExploitDB
7 CVEs
58.3% of CVEs· 83rd percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Securenvoy.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Securenvoy — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Securenvoy's Products

View all 1 CNAs →

Top CWEs