Skip to content
Noroxi

safe records

8 published records for vendor safe.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
1
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

8 records
  • Safe Software FME Server through 2018.1 creates and enables three additional accounts in addition to the initial administrator account.

    HighCVSS 8.8No exploitEPSS 1%

    safe · fme serverDec 23, 2018

  • A directory traversal vulnerability in Safe Software FME Server before 2022.2.5 allows an attacker to bypass validation when editing a netwo

    HighCVSS 8.1Proof of conceptEPSS 1%

    safe · fme serverJun 23, 2023

  • Safe Software FME Server v2021.2.5, v2022.0.0.2 and below was discovered to contain a Path Traversal vulnerability via the component fmedata

    HighCVSS 7.2No exploitEPSS 1%

    safe · fme serverSep 20, 2022

  • Safe Software FME Server v2021.2.5 and below does not employ server-side validation.

    HighCVSS 7.1No exploitEPSS 1%

    safe · fme serverSep 19, 2022

  • Safe Software FME Server v2021.2.5, v2022.0.0.2 and below was discovered to contain a XML External Entity (XXE) vulnerability which allows a

    MediumCVSS 6.5No exploitEPSS 1%

    safe · fme serverSep 13, 2022

  • Unauthenticated Stored XSS in FME Server versions 2019.2 and 2020.0 Beta allows a remote attacker to gain admin privileges by injecting arbi

    MediumCVSS 6.1No exploitEPSS 1%

    safe · fme serverApr 28, 2021

  • Safe Software FME Server v2021.2.5, v2022.0.0.2 and below contains a cross-site scripting (XSS) vulnerability which allows attackers to exec

    MediumCVSS 6.1No exploitEPSS 1%

    safe · fme serverSep 19, 2022

  • Authenticated Stored XSS in FME Server versions 2019.2 and 2020.0 Beta allows a remote attacker to execute codeby injecting arbitrary web sc

    MediumCVSS 5.4No exploitEPSS 1%

    safe · fme serverApr 28, 2021