Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3059▲ 556 respecto a la semana anterior
Críticas / altas1460▲ 282 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
14 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Crítica (9.1) | 0.33% | — | Filemaker ServerAI | 23/9/2026 | 24/9/2026 | An authorization bypass vulnerability in the FileMaker Server Web Publishing Engine allowed requests containing an extended privilege header to bypass the disabled Custom Web Publishing with XML setting and access the XML Web Publishing interface. This vulnerability is addressed in FileMaker Server version 26.0.3. | |
| Pendiente de análisis | Crítica (9.1) | 0.29% | — | Filemaker ServerAI | 23/9/2026 | 24/9/2026 | An out-of-bounds read vulnerability in FileMaker Server for Linux allowed an attacker uploading a specially crafted image file to a container field to disclose process memory during thumbnail generation in FileMaker WebDirect. This vulnerability is addressed in FileMaker Server version 26.0.3. | |
| Pendiente de análisis | Alta (7.8) | 0.13% | — | Filemaker ServerAI | 23/9/2026 | 24/9/2026 | A heap buffer overflow vulnerability in the FileMaker Server database engine block parsing routine allowed a maliciously crafted .fmp12 database file to cause memory corruption, potentially leading to arbitrary code execution. This vulnerability is addressed in FileMaker Server version 26.0.3. | |
| Analizada | Media (4.9) | 0.49% | — | Claris Filemaker Server | 9/7/2026 | 10/7/2026 | An authenticated administrator may be able to achieve arbitrary code execution on the host system by uploading a malicious file through the Open Source LLM setup feature in the Admin Console. This vulnerability has been addressed in FileMaker Server 26.0.1. | |
| Analizada | Media (6.1) | 0.22% | — | Claris Filemaker Server | 24/2/2026 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in a FileMaker WebDirect custom homepage could lead to unauthorized access and remote code execution. This vulnerability has been fully addressed in FileMaker Server 22.0.4 and FileMaker Server 21.1.7. | |
| Analizada | Media (5.4) | 0.17% | — | Claris Filemaker Server | 16/12/2025 | 17/6/2026 | An authorization bypass vulnerability in FileMaker Server Admin Console allowed administrator roles with minimal privileges to access administrative features such as viewing license details and downloading application logs. This vulnerability has been fully addressed in FileMaker Server 22.0.4. | |
| Analizada | Crítica (9.8) | 1.0% | — | Claris Filemaker Server | 16/12/2025 | 17/6/2026 | Apache Commons Text versions prior to 1.10.0 included interpolation features that could be abused when applications passed untrusted input into the text-substitution API. Because some interpolators could trigger actions like executing commands or accessing external resources, an attacker could potentially achieve… | |
| Analizada | Media (5.3) | 0.23% | — | Claris Filemaker Server | 16/12/2025 | 17/6/2026 | To enhance security, the FileMaker Server 22.0.4 installer now includes an option to disable IIS short filename enumeration by setting NtfsDisable8dot3NameCreation in the Windows registry. This prevents attackers from using the tilde character to discover hidden files and directories. This vulnerability has been fully… | |
| Analizada | Alta (7.5) | 0.46% | — | Claris Filemaker Server | 14/5/2024 | 17/6/2026 | Claris International has resolved an issue of potentially allowing unauthorized access to records stored in databases hosted on FileMaker Server. This issue has been fixed in FileMaker Server 20.3.2 by validating transactions before replying to client requests. | |
| Analizada | Media (4.9) | 0.45% | — | Claris Filemaker Server | 14/5/2024 | 17/6/2026 | Claris International has successfully resolved an issue of potentially exposing password information to front-end websites when signed in to the Admin Console with an administrator role. This issue has been fixed in FileMaker Server 20.3.1 by eliminating the send of Admin Role passwords in the Node.js socket. | |
| Analizada | Media (6.1) | 0.31% | — | Claris Filemaker Server | 15/4/2024 | 17/6/2026 | Claris FileMaker Server before version 20.3.2 was susceptible to a reflected Cross-Site Scripting vulnerability due to an improperly handled parameter in the FileMaker WebDirect login endpoint. The vulnerability was resolved in FileMaker Server 20.3.2 by escaping the HTML contents of the login error message on the… | |
| Analizada | Media (4.9) | 0.45% | — | Claris PROClaris Filemaker Server | 21/3/2024 | 17/6/2026 | A privilege escalation issue existed in FileMaker Server, potentially exposing sensitive information to front-end websites when signed in to the Admin Console with an administrator role. This issue has been fixed in FileMaker Server 20.3.1 by reducing the information sent in requests. | |
| Modificada | Media (5.5) | 1.2% | — | Claris Filemaker PROClaris Filemaker Server | 22/11/2021 | 17/6/2026 | An XML External Entity issue in Claris FileMaker Pro and Server (including WebDirect) before 19.4.1 allows a remote attacker to disclose local files via a crafted XML/Excel document and perform server-side request forgery attacks. | |
| Modificada | Media (4.3) | 1.2% | — | FilemakerFilemaker Server | 23/11/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Instant Web Publishing feature in FileMaker Pro 7 and 8, Server 7 and 8, and Developer 7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |