Перейти к содержимому
Noroxi

Записи SMARTBEAR

23 опубликованных записей вендора smartbear.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
7
С записью об исправлении
39,1 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

23 записей
  • CVE-2020-12835
    43В плане

    An issue was discovered in SmartBear ReadyAPI SoapUI Pro 3.2.5.

    КритическаяCVSS 9,8Эксплойта нетEPSS 13 %

    smartbear · readyapi20 мая 2020 г.

  • CVE-2019-17495
    41В плане

    A Cascading Style Sheets (CSS) injection vulnerability in Swagger UI before 3.23.11 allows attackers to use the Relative Path Overwrite (RPO

    КритическаяCVSS 9,8Proof of conceptEPSS 6 %

    smartbear · swagger ui10 окт. 2019 г.

  • CVE-2014-1202
    39Наблюдать

    The WSDL/WADL import functionality in SoapUI before 4.6.4 allows remote attackers to execute arbitrary Java code via a crafted request param

    КритическаяCVSS 9,3Proof of conceptEPSS 8 %

    eviware · soapui24 янв. 2014 г.

  • CVE-2023-22889
    39Наблюдать

    SmartBear Zephyr Enterprise through 7.15.0 mishandles user-defined input during report generation.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    smartbear · zephyr enterprise8 мар. 2023 г.

  • CVE-2018-20580
    38Наблюдать

    The WSDL import functionality in SmartBear ReadyAPI 2.5.0 and 2.6.0 allows remote attackers to execute arbitrary Java code via a crafted req

    ВысокаяCVSS 8,8Proof of conceptEPSS 10 %

    smartbear · readyapi3 мая 2019 г.

  • CVE-2020-26118
    36Наблюдать

    In SmartBear Collaborator Server through 13.3.13302, use of the Google Web Toolkit (GWT) API introduces a post-authentication Java deseriali

    ВысокаяCVSS 8,8Эксплойта нетEPSS 4 %

    smartbear · collaborator11 янв. 2021 г.

  • CVE-2019-12180
    32Наблюдать

    An issue was discovered in SmartBear ReadyAPI through 2.8.2 and 3.0.0 and SoapUI through 5.5.

    ВысокаяCVSS 7,8Proof of conceptEPSS 5 %

    smartbear · readyapi5 февр. 2020 г.

  • CVE-2023-22891
    32Наблюдать

    There exists a privilege escalation vulnerability in SmartBear Zephyr Enterprise through 7.15.0 that could be exploited by authorized users

    ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %

    smartbear · zephyr enterprise8 мар. 2023 г.

  • CVE-2017-16670
    31Наблюдать

    The project import functionality in SoapUI 5.3.0 allows remote attackers to execute arbitrary Java code via a crafted request parameter in a

    ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %

    smartbear · soapui19 февр. 2018 г.

  • CVE-2024-7565
    31Наблюдать

    SMARTBEAR SoapUI unpackageAll Directory Traversal Remote Code Execution Vulnerability

    ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %

    smartbear · soapui22 нояб. 2024 г.

  • CVE-2018-25031
    30Наблюдать

    Swagger UI 4.1.2 and earlier could allow a remote attacker to conduct spoofing attacks.

    СредняяCVSS 4,3Proof of conceptEPSS 42 %

    smartbear · swagger ui11 мар. 2022 г.

  • CVE-2023-22890
    30Наблюдать

    SmartBear Zephyr Enterprise through 7.15.0 allows unauthenticated users to upload large files, which could exhaust the local drive space, ca

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    smartbear · zephyr enterprise8 мар. 2023 г.

  • CVE-2023-22892
    30Наблюдать

    There exists an information disclosure vulnerability in SmartBear Zephyr Enterprise through 7.15.0 that could be exploited by unauthenticate

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    smartbear · zephyr enterprise8 мар. 2023 г.

  • CVE-2021-21363
    28Наблюдать

    Generator Web Application: Local Privilege Escalation Vulnerability via System Temp Directory

    ВысокаяCVSS 7,0Эксплойта нетEPSS 0 %

    smartbear · swagger-codegen10 мар. 2021 г.

  • CVE-2025-29157
    26Наблюдать

    An issue in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via accessing a non-existent endpoint/cart, the server retur

    СредняяCVSS 6,5Эксплойта нетEPSS 1 %

    smartbear · swagger petstore25 сент. 2025 г.

  • CVE-2025-29155
    26Наблюдать

    An issue in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via the DELETE endpoint

    СредняяCVSS 6,5Эксплойта нетEPSS 0 %

    smartbear · swagger petstore25 сент. 2025 г.

  • CVE-2016-1000229
    25Наблюдать

    swagger-ui has XSS in key names

    СредняяCVSS 6,1Proof of conceptEPSS 4 %

    smartbear · swagger-ui20 дек. 2019 г.

  • CVE-2021-46708
    24Наблюдать

    The swagger-ui-dist package before 4.1.3 for Node.js could allow a remote attacker to hijack the clicking action of the victim.

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    smartbear · swagger-ui-dist11 мар. 2022 г.

  • CVE-2016-5682
    24Наблюдать

    Swagger-UI before 2.2.1 has XSS via the Default field in the Definitions section.

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    smartbear · swagger-ui9 апр. 2017 г.

  • CVE-2021-41657
    24Наблюдать

    SmartBear CodeCollaborator v6.1.6102 was discovered to contain a vulnerability in the web UI which would allow an attacker to conduct a clic

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    smartbear · collaborator10 мар. 2022 г.

  • CVE-2025-29156
    24Наблюдать

    Cross Site Scripting vulnerability in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via a crafted script to the /api/v

    СредняяCVSS 6,1Эксплойта нетEPSS 0 %

    smartbear · swagger petstore25 сент. 2025 г.

  • CVE-2024-22207
    22Наблюдать

    Default swagger-ui configuration exposes all files in the module

    СредняяCVSS 5,3Proof of conceptEPSS 2 %

    smartbear · swagger ui15 янв. 2024 г.

  • CVE-2021-21364
    22Наблюдать

    Generated Code Contains Local Information Disclosure Vulnerability

    СредняяCVSS 5,5Эксплойта нетEPSS 0 %

    smartbear · swagger-codegen10 мар. 2021 г.