Vulnerability index

Browse CVEs

8 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fme Server HIGH 8.1
CVE-2023-35801

A directory traversal vulnerability in Safe Software FME Server before 2022.2.5 allows an attacker to bypass validation when editing a network-based …

Fix: 2022.2.5+
Fix from $1,950 2023-06-23
Fme Server HIGH 7.2
CVE-2022-38340

Safe Software FME Server v2021.2.5, v2022.0.0.2 and below was discovered to contain a Path Traversal vulnerability via the component fmedataupload.

Fix: 2021.2.6 / 2022.0.1+
Fix from $1,950 2022-09-20
Fme Server MEDIUM 6.1
CVE-2022-38339

Safe Software FME Server v2021.2.5, v2022.0.0.2 and below contains a cross-site scripting (XSS) vulnerability which allows attackers to execute arbit…

Fix: 2021.2.6 / 2022.0.1.1+
Fix from $1,600 2022-09-19
Fme Server HIGH 7.1
CVE-2022-38341

Safe Software FME Server v2021.2.5 and below does not employ server-side validation.

Fix: 2021.2.6+
Fix from $1,950 2022-09-19
Fme Server MEDIUM 6.5
CVE-2022-38342

Safe Software FME Server v2021.2.5, v2022.0.0.2 and below was discovered to contain a XML External Entity (XXE) vulnerability which allows authentica…

Fix: 2021.2.6.0 / 2022.0.0.2+
Fix from $1,600 2022-09-13
Fme Server MEDIUM 6.1
CVE-2020-22789

Unauthenticated Stored XSS in FME Server versions 2019.2 and 2020.0 Beta allows a remote attacker to gain admin privileges by injecting arbitrary web…

No fix yet
Fix from $1,600 2021-04-28
Fme Server MEDIUM 5.4
CVE-2020-22790

Authenticated Stored XSS in FME Server versions 2019.2 and 2020.0 Beta allows a remote attacker to execute codeby injecting arbitrary web script or H…

No fix yet
Fix from $1,600 2021-04-28
Fme Server HIGH 8.8
CVE-2018-20402

Safe Software FME Server through 2018.1 creates and enables three additional accounts in addition to the initial administrator account. The passwords…

Fix: after 2018.1
Fix from $1,950 2018-12-23