Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

m-files

About This Vendor

m-files is a technology vendor producing software and infrastructure products. As a software provider, m-files's broad product portfolio across multiple domains—including operating systems, cloud infrastructure, enterprise applications, databases, networking, and security tools—creates a large attack surface. Additionally, long support cycles, widespread deployment, and continuous feature development contribute to the accumulation of discovered vulnerabilities over time. Major vendors typically report higher CVE counts not necessarily due to inferior security, but because of greater exposure to security research, responsible disclosure practices, and the sheer complexity of maintaining multiple product lines and legacy systems. Regular security assessments and patching of m-files's products are critical for organizations running their software in production environments.

Vulnerability Trends for This Vendor

SecUtils has indexed 61 known vulnerabilities from m-files. This includes 1 critical-severity issue and 20 high-severity issues that represent significant risk. These vulnerabilities affect 10 distinct products across m-files's portfolio, demonstrating the breadth of the vendor's product ecosystem and the importance of comprehensive patch management strategies. Disclosure dates span from 2021 through 2026, reflecting sustained security scrutiny over multiple years. Organizations deploying m-files products should maintain active vulnerability monitoring, prioritize critical patches, and implement compensating controls where patches cannot be applied immediately.

ID Date Published Last Modified Severity (CVSSv3) Severity (CVSSv2) Exploit Available
CVE-2021-37254 2021-10-28 2026-06-17 7.5 5.0 Likely
CVE-2021-37253 2021-12-05 2026-06-17 7.5 7.8 Likely
CVE-2021-41807 2022-01-18 2026-06-17 7.5 5.0 Likely
CVE-2021-41808 2022-01-18 2026-06-17 2.0 1.9 Unknown
CVE-2021-41809 2022-01-18 2026-06-17 3.5 4.0 Likely
CVE-2021-41810 2022-05-02 2026-06-17 5.2 3.5 Unknown
CVE-2022-39016 2022-10-31 2026-06-17 8.2 - -
CVE-2022-39017 2022-10-31 2026-06-17 8.2 - -
CVE-2022-39018 2022-10-31 2026-06-17 8.2 - -
CVE-2022-39019 2022-10-31 2026-06-17 6.3 - -
CVE-2022-1606 2022-11-30 2026-06-17 2.4 - -
CVE-2022-1911 2022-11-30 2026-06-17 5.3 - -
CVE-2022-4270 2022-12-02 2026-06-17 2.0 - -
CVE-2022-4264 2022-12-09 2026-06-17 6.5 - -
CVE-2022-4858 2022-12-30 2026-06-17 4.4 - -
CVE-2022-4861 2022-12-30 2026-06-17 4.8 - -
CVE-2022-3284 2023-03-06 2026-06-17 6.5 - -
CVE-2022-4862 2023-03-06 2026-06-17 5.0 - -
CVE-2023-0213 2023-03-29 2026-06-17 8.8 - -
CVE-2023-0382 2023-04-05 2026-06-17 6.5 - -
CVE-2023-0383 2023-04-20 2026-06-17 7.5 - -
CVE-2023-0384 2023-04-20 2026-06-17 6.5 - -
CVE-2023-2112 2023-04-20 2026-06-17 3.6 - -
CVE-2023-2480 2023-05-25 2026-06-17 7.5 - -
CVE-2023-3405 2023-06-27 2026-06-17 7.5 - -
CVE-2023-3406 2023-08-25 2026-06-17 7.7 - -
CVE-2023-3425 2023-08-25 2026-06-17 6.5 - -
CVE-2023-2325 2023-10-20 2026-06-17 7.3 - -
CVE-2023-5523 2023-10-20 2026-06-17 8.6 - -
CVE-2023-5524 2023-10-20 2026-06-17 8.2 - -
CVE-2023-6117 2023-11-22 2026-06-17 5.7 - -
CVE-2023-6189 2023-11-22 2026-06-17 4.3 - -
CVE-2023-6239 2023-11-28 2026-06-17 5.4 - -
CVE-2023-6910 2023-12-20 2026-06-17 6.5 - -
CVE-2023-6912 2023-12-20 2026-06-17 7.5 - -
CVE-2024-0563 2024-02-23 2026-06-17 4.3 - -
CVE-2023-4479 2024-03-04 2026-06-17 7.3 - -
CVE-2024-4056 2024-04-26 2026-06-17 7.5 - -
CVE-2024-5142 2024-05-24 2026-06-17 5.4 - -
CVE-2024-6124 2024-07-29 2026-06-17 5.4 - -
CVE-2024-6881 2024-07-29 2026-06-17 5.4 - -
CVE-2024-6789 2024-08-27 2026-06-17 6.5 - -
CVE-2024-9174 2024-10-02 2026-06-17 5.4 - -
CVE-2024-10126 2024-11-20 2026-06-17 4.3 - -
CVE-2024-10127 2024-11-20 2026-06-17 9.8 - -
CVE-2025-0619 2025-01-23 2026-06-17 4.9 - -
CVE-2025-0635 2025-01-23 2026-06-17 7.5 - -
CVE-2025-0648 2025-01-23 2026-06-17 4.9 - -
CVE-2025-3086 2025-04-04 2026-06-17 7.1 - -
CVE-2025-3087 2025-04-04 2026-06-17 5.4 - -
CVE-2025-5964 2025-06-15 2026-06-17 6.5 - -
CVE-2025-2091 2025-06-16 2026-06-17 5.4 - -
CVE-2025-9826 2025-09-15 2026-06-17 5.4 - -
CVE-2025-11681 2025-11-17 2026-06-17 6.5 - -
CVE-2025-14318 2025-12-18 2026-06-17 4.3 - -
CVE-2025-14267 2025-12-19 2026-06-17 4.9 - -
CVE-2026-0663 2026-01-21 2026-06-17 4.9 - -
CVE-2026-0932 2026-04-01 2026-06-17 7.3 - -
CVE-2026-0931 2026-08-05 2026-08-31 - - -
CVE-2026-18371 2026-08-19 2026-08-31 - - -
CVE-2026-18372 2026-08-19 2026-08-31 - - -

How SecUtils Normalizes Vendor Data

SecUtils aggregates National Vulnerability Database (NVD) and MITRE records for m-files by normalizing vendor identifiers across diverse data sources, mapping vendor names to their associated product lines, and collecting all known vulnerabilities under a unified vendor context. For every CVE associated with m-files's products, we extract and structure Common Platform Enumeration (CPE) data, Common Weakness Enumeration (CWE) categories, CVSS severity metrics, and reference links to enable rapid vulnerability identification and asset correlation. This record contains no exploit code, proof-of-concept instructions, or attack methodologies—only defensive intelligence necessary for patch management, risk assessment, and vendor vulnerability tracking.