hoverfly records
3 published records for vendor hoverfly.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-20 Improper Input Validation1
The weakness classes this vendor ships most often: where to look.
CWEAll records
3 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
47Plan | CVE-2024-45388Proof of concept | Arbitrary file read in the `/api/v2/simulation` endpoint in hoverfly (`GHSL-2023-274`)hoverfly · hoverfly · CWE-200 | High7.5 | — | 55.6% | Sep 2, 2024 |
42Plan | CVE-2025-54123Proof of concept | Hoverfly vulnerable to remote code execution at `/api/v2/hoverfly/middleware` endpoint due to insecure middleware implementationhoverfly · hoverfly · CWE-20 | Critical9.8 | — | 10.5% | Sep 10, 2025 |
31Monitor | CVE-2025-54376No exploit | Hoverfly's WebSocket endpoint `/api/v2/ws/logs` reachable without authentication even when --auth is enabled.hoverfly · hoverfly · CWE-200 | High7.8 | — | 0.7% | Sep 10, 2025 |
- CVE-2024-4538847Plan
Arbitrary file read in the `/api/v2/simulation` endpoint in hoverfly (`GHSL-2023-274`)
HighCVSS 7.5Proof of conceptEPSS 56%hoverfly · hoverflySep 2, 2024
- CVE-2025-5412342Plan
Hoverfly vulnerable to remote code execution at `/api/v2/hoverfly/middleware` endpoint due to insecure middleware implementation
CriticalCVSS 9.8Proof of conceptEPSS 11%hoverfly · hoverflySep 10, 2025
- CVE-2025-5437631Monitor
Hoverfly's WebSocket endpoint `/api/v2/ws/logs` reachable without authentication even when --auth is enabled.
HighCVSS 7.8No exploitEPSS 1%hoverfly · hoverflySep 10, 2025