Claris kayıtları
claris üreticisine ait 14 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
- CWE-284 Improper Access Control1
- CWE-285 Improper Authorization1
- CWE-287 Improper Authentication1
- CWE-427 Uncontrolled Search Path Element1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
14 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2025-46295Kavram kanıtı | Apache Commons Text versions prior to 1.10.0 included interpolation features that could be abused when applications passed untrusted input iclaris · filemaker server · CWE-94 | Kritik9,8 | — | %1,0 | 16 Ara 2025 |
31İzleyin | CVE-2014-8347Kavram kanıtı | An Authentication Bypass vulnerability exists in the MatchPasswordData function in DBEngine.dll in Filemaker Pro 13.03 and Filemaker Pro Advclaris · filemaker pro · CWE-287 | Yüksek7,8 | — | %1,4 | 11 Şub 2020 |
31İzleyin | CVE-2023-42920İstismar yok | Claris International has fixed a dylib hijacking vulnerability in the FileMaker Pro.app and Claris Pro.app versions on macOS.claris · claris pro · CWE-427 | Yüksek7,8 | — | %0,2 | 19 Mar 2024 |
30İzleyin | CVE-2024-27790İstismar yok | Claris International has resolved an issue of potentially allowing unauthorized access to records stored in databases hosted on FileMaker Seclaris · filemaker server · CWE-284 | Yüksek7,5 | — | %0,5 | 14 May 2024 |
28İzleyin | CVE-2026-43680İstismar yok | A Remote Code Execution vulnerability in Claris FileMaker Cloud allowed a user with Admin Console privileges to bypass a front-end restricticlaris · filemaker cloud · CWE-94 | Yüksek7,2 | — | %0,8 | 12 May 2026 |
28İzleyin | CVE-2026-43685İstismar yok | A Remote Code Execution vulnerability in Claris FileMaker Cloud allowed a user with Admin Console privileges to inject arbitrary operating sclaris · filemaker cloud · CWE-78 | Yüksek7,2 | — | %0,8 | 12 May 2026 |
24İzleyin | CVE-2024-27794İstismar yok | Claris FileMaker Server before version 20.3.2 was susceptible to a reflected Cross-Site Scripting vulnerability due to an improperly handledclaris · filemaker server · CWE-79 | Orta6,1 | — | %0,3 | 15 Nis 2024 |
24İzleyin | CVE-2025-46320İstismar yok | A cross-site scripting (XSS) vulnerability in a FileMaker WebDirect custom homepage could lead to unauthorized access and remote code executclaris · filemaker server · CWE-79 | Orta6,1 | — | %0,2 | 24 Şub 2026 |
22İzleyin | CVE-2021-44147İstismar yok | An XML External Entity issue in Claris FileMaker Pro and Server (including WebDirect) before 19.4.1 allows a remote attacker to disclose locclaris · filemaker pro · CWE-611 | Orta5,5 | — | %1,2 | 22 Kas 2021 |
21İzleyin | CVE-2025-46294İstismar yok | To enhance security, the FileMaker Server 22.0.4 installer now includes an option to disable IIS short filename enumeration by setting NtfsDclaris · filemaker server · CWE-200 | Orta5,3 | — | %0,2 | 16 Ara 2025 |
21İzleyin | CVE-2025-46296İstismar yok | An authorization bypass vulnerability in FileMaker Server Admin Console allowed administrator roles with minimal privileges to access adminiclaris · filemaker server · CWE-285 | Orta5,4 | — | %0,2 | 16 Ara 2025 |
19İzleyin | CVE-2026-43752İstismar yok | An authenticated administrator may be able to achieve arbitrary code execution on the host system by uploading a malicious file through the claris · filemaker server · CWE-434 | Orta4,9 | — | %0,5 | 9 Tem 2026 |
19İzleyin | CVE-2023-42955İstismar yok | Claris International has successfully resolved an issue of potentially exposing password information to front-end websites when signed in toclaris · filemaker server · CWE-522 | Orta4,9 | — | %0,5 | 14 May 2024 |
19İzleyin | CVE-2023-42954İstismar yok | A privilege escalation issue existed in FileMaker Server, potentially exposing sensitive information to front-end websites when signed in toclaris · claris pro · CWE-250 | Orta4,9 | — | %0,4 | 21 Mar 2024 |
- CVE-2025-4629539İzleyin
Apache Commons Text versions prior to 1.10.0 included interpolation features that could be abused when applications passed untrusted input i
KritikCVSS 9,8Kavram kanıtıEPSS %1claris · filemaker server16 Ara 2025
- CVE-2014-834731İzleyin
An Authentication Bypass vulnerability exists in the MatchPasswordData function in DBEngine.dll in Filemaker Pro 13.03 and Filemaker Pro Adv
YüksekCVSS 7,8Kavram kanıtıEPSS %1claris · filemaker pro11 Şub 2020
- CVE-2023-4292031İzleyin
Claris International has fixed a dylib hijacking vulnerability in the FileMaker Pro.app and Claris Pro.app versions on macOS.
YüksekCVSS 7,8İstismar yokEPSS %0claris · claris pro19 Mar 2024
- CVE-2024-2779030İzleyin
Claris International has resolved an issue of potentially allowing unauthorized access to records stored in databases hosted on FileMaker Se
YüksekCVSS 7,5İstismar yokEPSS %0claris · filemaker server14 May 2024
- CVE-2026-4368028İzleyin
A Remote Code Execution vulnerability in Claris FileMaker Cloud allowed a user with Admin Console privileges to bypass a front-end restricti
YüksekCVSS 7,2İstismar yokEPSS %1claris · filemaker cloud12 May 2026
- CVE-2026-4368528İzleyin
A Remote Code Execution vulnerability in Claris FileMaker Cloud allowed a user with Admin Console privileges to inject arbitrary operating s
YüksekCVSS 7,2İstismar yokEPSS %1claris · filemaker cloud12 May 2026
- CVE-2024-2779424İzleyin
Claris FileMaker Server before version 20.3.2 was susceptible to a reflected Cross-Site Scripting vulnerability due to an improperly handled
OrtaCVSS 6,1İstismar yokEPSS %0claris · filemaker server15 Nis 2024
- CVE-2025-4632024İzleyin
A cross-site scripting (XSS) vulnerability in a FileMaker WebDirect custom homepage could lead to unauthorized access and remote code execut
OrtaCVSS 6,1İstismar yokEPSS %0claris · filemaker server24 Şub 2026
- CVE-2021-4414722İzleyin
An XML External Entity issue in Claris FileMaker Pro and Server (including WebDirect) before 19.4.1 allows a remote attacker to disclose loc
OrtaCVSS 5,5İstismar yokEPSS %1claris · filemaker pro22 Kas 2021
- CVE-2025-4629421İzleyin
To enhance security, the FileMaker Server 22.0.4 installer now includes an option to disable IIS short filename enumeration by setting NtfsD
OrtaCVSS 5,3İstismar yokEPSS %0claris · filemaker server16 Ara 2025
- CVE-2025-4629621İzleyin
An authorization bypass vulnerability in FileMaker Server Admin Console allowed administrator roles with minimal privileges to access admini
OrtaCVSS 5,4İstismar yokEPSS %0claris · filemaker server16 Ara 2025
- CVE-2026-4375219İzleyin
An authenticated administrator may be able to achieve arbitrary code execution on the host system by uploading a malicious file through the
OrtaCVSS 4,9İstismar yokEPSS %0claris · filemaker server9 Tem 2026
- CVE-2023-4295519İzleyin
Claris International has successfully resolved an issue of potentially exposing password information to front-end websites when signed in to
OrtaCVSS 4,9İstismar yokEPSS %0claris · filemaker server14 May 2024
- CVE-2023-4295419İzleyin
A privilege escalation issue existed in FileMaker Server, potentially exposing sensitive information to front-end websites when signed in to
OrtaCVSS 4,9İstismar yokEPSS %0claris · claris pro21 Mar 2024