filemaker records
9 published records for vendor filemaker.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-310 Cryptographic Issues2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
9 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
31Monitor | CVE-2000-0123No exploit | The shopping cart application provided with Filemaker allows remote users to modify sensitive purchase information via hidden form fields.filemaker · filemaker | High7.5 | — | 2.1% | Feb 1, 2000 |
30Monitor | CVE-2000-0386No exploit | FileMaker Pro 5 Web Companion allows remote attackers to send anonymous or forged email.filemaker · filemaker | High7.5 | — | 1.4% | May 2, 2000 |
30Monitor | CVE-2016-1208No exploit | The server in Apple FileMaker before 14.0.4 on OS X allows remote attackers to read PHP source code via unspecified vectors.apple · mac os x · CWE-200 | High7.5 | — | 1.3% | May 14, 2016 |
23Monitor | CVE-2013-2319No exploit | FileMaker Pro before 12 and Pro Advanced before 12 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attacfilemaker · filemaker pro · CWE-310 | Medium5.8 | — | 0.5% | Jun 10, 2013 |
23Monitor | CVE-2014-5321No exploit | FileMaker Pro before 13 and Pro Advanced before 13 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attacfilemaker · filemaker pro · CWE-310 | Medium5.8 | — | 0.5% | Sep 21, 2014 |
20Monitor | CVE-2000-0385No exploit | FileMaker Pro 5 Web Companion allows remote attackers to bypass Field-Level database security restrictions via the XML publishing or email cfilemaker · filemaker | Medium5.0 | — | 1.6% | May 2, 2000 |
18Monitor | CVE-2014-5322No exploit | Cross-site scripting (XSS) vulnerability in the Instant Web Publish function in FileMaker Pro before 13 and Pro Advanced before 13 allows refilemaker · filemaker pro · CWE-79 | Medium4.3 | — | 1.8% | Sep 21, 2014 |
17Monitor | CVE-2007-6104No exploit | Cross-site scripting (XSS) vulnerability in the Instant Web Publishing feature in FileMaker Pro 7 and 8, Server 7 and 8, and Developer 7 allfilemaker · filemaker · CWE-79 | Medium4.3 | — | 1.2% | Nov 23, 2007 |
17Monitor | CVE-2013-3640No exploit | Cross-site scripting (XSS) vulnerability in the Instant Web Publish function in FileMaker Pro before 12 and Pro Advanced before 12 allows refilemaker · filemaker pro · CWE-79 | Medium4.3 | — | 0.9% | Jun 10, 2013 |
- CVE-2000-012331Monitor
The shopping cart application provided with Filemaker allows remote users to modify sensitive purchase information via hidden form fields.
HighCVSS 7.5No exploitEPSS 2%filemaker · filemakerFeb 1, 2000
- CVE-2000-038630Monitor
FileMaker Pro 5 Web Companion allows remote attackers to send anonymous or forged email.
HighCVSS 7.5No exploitEPSS 1%filemaker · filemakerMay 2, 2000
- CVE-2016-120830Monitor
The server in Apple FileMaker before 14.0.4 on OS X allows remote attackers to read PHP source code via unspecified vectors.
HighCVSS 7.5No exploitEPSS 1%apple · mac os xMay 14, 2016
- CVE-2013-231923Monitor
FileMaker Pro before 12 and Pro Advanced before 12 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attac
MediumCVSS 5.8No exploitEPSS 1%filemaker · filemaker proJun 10, 2013
- CVE-2014-532123Monitor
FileMaker Pro before 13 and Pro Advanced before 13 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attac
MediumCVSS 5.8No exploitEPSS 1%filemaker · filemaker proSep 21, 2014
- CVE-2000-038520Monitor
FileMaker Pro 5 Web Companion allows remote attackers to bypass Field-Level database security restrictions via the XML publishing or email c
MediumCVSS 5.0No exploitEPSS 2%filemaker · filemakerMay 2, 2000
- CVE-2014-532218Monitor
Cross-site scripting (XSS) vulnerability in the Instant Web Publish function in FileMaker Pro before 13 and Pro Advanced before 13 allows re
MediumCVSS 4.3No exploitEPSS 2%filemaker · filemaker proSep 21, 2014
- CVE-2007-610417Monitor
Cross-site scripting (XSS) vulnerability in the Instant Web Publishing feature in FileMaker Pro 7 and 8, Server 7 and 8, and Developer 7 all
MediumCVSS 4.3No exploitEPSS 1%filemaker · filemakerNov 23, 2007
- CVE-2013-364017Monitor
Cross-site scripting (XSS) vulnerability in the Instant Web Publish function in FileMaker Pro before 12 and Pro Advanced before 12 allows re
MediumCVSS 4.3No exploitEPSS 1%filemaker · filemaker proJun 10, 2013