Skip to content
Noroxi

SMARTBEAR records

23 published records for vendor smartbear.

All records

23 records
  • An issue was discovered in SmartBear ReadyAPI SoapUI Pro 3.2.5.

    CriticalCVSS 9.8No exploitEPSS 13%

    smartbear · readyapiMay 20, 2020

  • A Cascading Style Sheets (CSS) injection vulnerability in Swagger UI before 3.23.11 allows attackers to use the Relative Path Overwrite (RPO

    CriticalCVSS 9.8Proof of conceptEPSS 6%

    smartbear · swagger uiOct 10, 2019

  • CVE-2014-1202
    39Monitor

    The WSDL/WADL import functionality in SoapUI before 4.6.4 allows remote attackers to execute arbitrary Java code via a crafted request param

    CriticalCVSS 9.3Proof of conceptEPSS 8%

    eviware · soapuiJan 24, 2014

  • SmartBear Zephyr Enterprise through 7.15.0 mishandles user-defined input during report generation.

    CriticalCVSS 9.8No exploitEPSS 1%

    smartbear · zephyr enterpriseMar 8, 2023

  • The WSDL import functionality in SmartBear ReadyAPI 2.5.0 and 2.6.0 allows remote attackers to execute arbitrary Java code via a crafted req

    HighCVSS 8.8Proof of conceptEPSS 10%

    smartbear · readyapiMay 3, 2019

  • In SmartBear Collaborator Server through 13.3.13302, use of the Google Web Toolkit (GWT) API introduces a post-authentication Java deseriali

    HighCVSS 8.8No exploitEPSS 4%

    smartbear · collaboratorJan 11, 2021

  • An issue was discovered in SmartBear ReadyAPI through 2.8.2 and 3.0.0 and SoapUI through 5.5.

    HighCVSS 7.8Proof of conceptEPSS 5%

    smartbear · readyapiFeb 5, 2020

  • There exists a privilege escalation vulnerability in SmartBear Zephyr Enterprise through 7.15.0 that could be exploited by authorized users

    HighCVSS 8.1No exploitEPSS 1%

    smartbear · zephyr enterpriseMar 8, 2023

  • The project import functionality in SoapUI 5.3.0 allows remote attackers to execute arbitrary Java code via a crafted request parameter in a

    HighCVSS 7.8No exploitEPSS 2%

    smartbear · soapuiFeb 19, 2018

  • CVE-2024-7565
    31Monitor

    SMARTBEAR SoapUI unpackageAll Directory Traversal Remote Code Execution Vulnerability

    HighCVSS 7.8No exploitEPSS 1%

    smartbear · soapuiNov 22, 2024

  • Swagger UI 4.1.2 and earlier could allow a remote attacker to conduct spoofing attacks.

    MediumCVSS 4.3Proof of conceptEPSS 42%

    smartbear · swagger uiMar 11, 2022

  • SmartBear Zephyr Enterprise through 7.15.0 allows unauthenticated users to upload large files, which could exhaust the local drive space, ca

    HighCVSS 7.5No exploitEPSS 1%

    smartbear · zephyr enterpriseMar 8, 2023

  • There exists an information disclosure vulnerability in SmartBear Zephyr Enterprise through 7.15.0 that could be exploited by unauthenticate

    HighCVSS 7.5No exploitEPSS 1%

    smartbear · zephyr enterpriseMar 8, 2023

  • Generator Web Application: Local Privilege Escalation Vulnerability via System Temp Directory

    HighCVSS 7.0No exploitEPSS 0%

    smartbear · swagger-codegenMar 10, 2021

  • An issue in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via accessing a non-existent endpoint/cart, the server retur

    MediumCVSS 6.5No exploitEPSS 1%

    smartbear · swagger petstoreSep 25, 2025

  • An issue in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via the DELETE endpoint

    MediumCVSS 6.5No exploitEPSS 0%

    smartbear · swagger petstoreSep 25, 2025

  • swagger-ui has XSS in key names

    MediumCVSS 6.1Proof of conceptEPSS 4%

    smartbear · swagger-uiDec 20, 2019

  • The swagger-ui-dist package before 4.1.3 for Node.js could allow a remote attacker to hijack the clicking action of the victim.

    MediumCVSS 6.1No exploitEPSS 1%

    smartbear · swagger-ui-distMar 11, 2022

  • CVE-2016-5682
    24Monitor

    Swagger-UI before 2.2.1 has XSS via the Default field in the Definitions section.

    MediumCVSS 6.1No exploitEPSS 1%

    smartbear · swagger-uiApr 9, 2017

  • SmartBear CodeCollaborator v6.1.6102 was discovered to contain a vulnerability in the web UI which would allow an attacker to conduct a clic

    MediumCVSS 6.1No exploitEPSS 1%

    smartbear · collaboratorMar 10, 2022

  • Cross Site Scripting vulnerability in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via a crafted script to the /api/v

    MediumCVSS 6.1No exploitEPSS 0%

    smartbear · swagger petstoreSep 25, 2025

  • Default swagger-ui configuration exposes all files in the module

    MediumCVSS 5.3Proof of conceptEPSS 2%

    smartbear · swagger uiJan 15, 2024

  • Generated Code Contains Local Information Disclosure Vulnerability

    MediumCVSS 5.5No exploitEPSS 0%

    smartbear · swagger-codegenMar 10, 2021