Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Safe

First CVE: Dec 23, 2018Active for: 8 yearsTotal CVEs: 8

Safe's vulnerability footprint centers on FME Server, a data-integration and ETL platform widely deployed in business analytics and geospatial workflows, with the recurring exposure rooted in web-facing input handling and configuration management. The durable signal reflects the product's role processing untrusted data and generating dynamic content: vulnerabilities cluster around cross-site scripting, path traversal, XML external entity injection, and insecure defaults that are endemic to platforms bridging user input, file systems, and markup generation. Current severity, exploitation, and disclosure counts are shown alongside this summary.

FAUCET AI Generated
8
Total CVEs
More Total CVEs than 90% of tracked vendors
2.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 80% of tracked vendors
6.9
Avg CVSS Score
Higher Avg CVSS Score than 49% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Safe over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 23, 2018
7 years ago
Most Recent CVE
Jun 23, 2023
1,127 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (8 CVEs).

8 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-20402HIGH
Safe Software FME Server through 2018.1 creates and enables three additional accounts in addition to the initial administrator account. The passwords to the three accounts are the
Dec 23, 20188.826NONO
CVE-2022-38340HIGH
Safe Software FME Server v2021.2.5, v2022.0.0.2 and below was discovered to contain a Path Traversal vulnerability via the component fmedataupload.
Sep 20, 20227.225NONO
CVE-2022-38341HIGH
Safe Software FME Server v2021.2.5 and below does not employ server-side validation.
Sep 19, 20227.124NONO
CVE-2023-35801HIGH
A directory traversal vulnerability in Safe Software FME Server before 2022.2.5 allows an attacker to bypass validation when editing a network-based resource connection, resulting
Jun 23, 20238.123NONO
CVE-2022-38339MEDIUM
Safe Software FME Server v2021.2.5, v2022.0.0.2 and below contains a cross-site scripting (XSS) vulnerability which allows attackers to execute arbitrary web scripts or HTML via a
Sep 19, 20226.123NONO
CVE-2020-22789MEDIUM
Unauthenticated Stored XSS in FME Server versions 2019.2 and 2020.0 Beta allows a remote attacker to gain admin privileges by injecting arbitrary web script or HTML via the login p
Apr 28, 20216.120NONO
CVE-2020-22790MEDIUM
Authenticated Stored XSS in FME Server versions 2019.2 and 2020.0 Beta allows a remote attacker to execute codeby injecting arbitrary web script or HTML via modifying the name of t
Apr 28, 20215.419NONO
CVE-2022-38342MEDIUM
Safe Software FME Server v2021.2.5, v2022.0.0.2 and below was discovered to contain a XML External Entity (XXE) vulnerability which allows authenticated attackers to perform data e
Sep 13, 20226.517NONO
View all 8 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products8 CVEs
50%
50%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network8 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None5 (62.5%)
Unknown0 (0.0%)
Required3 (37.5%)
Privileges Required
Low5 (62.5%)
High1 (12.5%)
None2 (25.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (8 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Safe.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Safe — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Safe's Products

View all 1 CNAs →

Top CWEs