safe records
8 published records for vendor safe.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-1188 Initialization of a Resource with an Insecure Default1
- CWE-611 Improper Restriction of XML External Entity Reference1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
8 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
35Monitor | CVE-2018-20402No exploit | Safe Software FME Server through 2018.1 creates and enables three additional accounts in addition to the initial administrator account.safe · fme server · CWE-1188 | High8.8 | — | 1.0% | Dec 23, 2018 |
32Monitor | CVE-2023-35801Proof of concept | A directory traversal vulnerability in Safe Software FME Server before 2022.2.5 allows an attacker to bypass validation when editing a netwosafe · fme server · CWE-22 | High8.1 | — | 1.5% | Jun 23, 2023 |
28Monitor | CVE-2022-38340No exploit | Safe Software FME Server v2021.2.5, v2022.0.0.2 and below was discovered to contain a Path Traversal vulnerability via the component fmedatasafe · fme server · CWE-22 | High7.2 | — | 1.3% | Sep 20, 2022 |
28Monitor | CVE-2022-38341No exploit | Safe Software FME Server v2021.2.5 and below does not employ server-side validation.safe · fme server | High7.1 | — | 0.6% | Sep 19, 2022 |
26Monitor | CVE-2022-38342No exploit | Safe Software FME Server v2021.2.5, v2022.0.0.2 and below was discovered to contain a XML External Entity (XXE) vulnerability which allows asafe · fme server · CWE-611 | Medium6.5 | — | 0.6% | Sep 13, 2022 |
24Monitor | CVE-2020-22789No exploit | Unauthenticated Stored XSS in FME Server versions 2019.2 and 2020.0 Beta allows a remote attacker to gain admin privileges by injecting arbisafe · fme server · CWE-79 | Medium6.1 | — | 1.2% | Apr 28, 2021 |
24Monitor | CVE-2022-38339No exploit | Safe Software FME Server v2021.2.5, v2022.0.0.2 and below contains a cross-site scripting (XSS) vulnerability which allows attackers to execsafe · fme server · CWE-79 | Medium6.1 | — | 0.6% | Sep 19, 2022 |
21Monitor | CVE-2020-22790No exploit | Authenticated Stored XSS in FME Server versions 2019.2 and 2020.0 Beta allows a remote attacker to execute codeby injecting arbitrary web scsafe · fme server · CWE-79 | Medium5.4 | — | 1.3% | Apr 28, 2021 |
- CVE-2018-2040235Monitor
Safe Software FME Server through 2018.1 creates and enables three additional accounts in addition to the initial administrator account.
HighCVSS 8.8No exploitEPSS 1%safe · fme serverDec 23, 2018
- CVE-2023-3580132Monitor
A directory traversal vulnerability in Safe Software FME Server before 2022.2.5 allows an attacker to bypass validation when editing a netwo
HighCVSS 8.1Proof of conceptEPSS 1%safe · fme serverJun 23, 2023
- CVE-2022-3834028Monitor
Safe Software FME Server v2021.2.5, v2022.0.0.2 and below was discovered to contain a Path Traversal vulnerability via the component fmedata
HighCVSS 7.2No exploitEPSS 1%safe · fme serverSep 20, 2022
- CVE-2022-3834128Monitor
Safe Software FME Server v2021.2.5 and below does not employ server-side validation.
HighCVSS 7.1No exploitEPSS 1%safe · fme serverSep 19, 2022
- CVE-2022-3834226Monitor
Safe Software FME Server v2021.2.5, v2022.0.0.2 and below was discovered to contain a XML External Entity (XXE) vulnerability which allows a
MediumCVSS 6.5No exploitEPSS 1%safe · fme serverSep 13, 2022
- CVE-2020-2278924Monitor
Unauthenticated Stored XSS in FME Server versions 2019.2 and 2020.0 Beta allows a remote attacker to gain admin privileges by injecting arbi
MediumCVSS 6.1No exploitEPSS 1%safe · fme serverApr 28, 2021
- CVE-2022-3833924Monitor
Safe Software FME Server v2021.2.5, v2022.0.0.2 and below contains a cross-site scripting (XSS) vulnerability which allows attackers to exec
MediumCVSS 6.1No exploitEPSS 1%safe · fme serverSep 19, 2022
- CVE-2020-2279021Monitor
Authenticated Stored XSS in FME Server versions 2019.2 and 2020.0 Beta allows a remote attacker to execute codeby injecting arbitrary web sc
MediumCVSS 5.4No exploitEPSS 1%safe · fme serverApr 28, 2021