Записи SMARTBEAR
23 опубликованных записей вендора smartbear.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 7
- С записью об исправлении
- 39,1 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-94 Improper Control of Generation of Code ('Code Injection')3
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-1021 Improper Restriction of Rendered UI Layers or Frames2
- CWE-20 Improper Input Validation2
- CWE-502 Deserialization of Untrusted Data2
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
23 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
43В плане | CVE-2020-12835Эксплойта нет | An issue was discovered in SmartBear ReadyAPI SoapUI Pro 3.2.5.smartbear · readyapi · CWE-502 | Критическая9,8 | — | 13,0 % | 20 мая 2020 г. |
41В плане | CVE-2019-17495Proof of concept | A Cascading Style Sheets (CSS) injection vulnerability in Swagger UI before 3.23.11 allows attackers to use the Relative Path Overwrite (RPOsmartbear · swagger ui · CWE-352 | Критическая9,8 | — | 5,7 % | 10 окт. 2019 г. |
39Наблюдать | CVE-2014-1202Proof of concept | The WSDL/WADL import functionality in SoapUI before 4.6.4 allows remote attackers to execute arbitrary Java code via a crafted request parameviware · soapui · CWE-94 | Критическая9,3 | — | 7,7 % | 24 янв. 2014 г. |
39Наблюдать | CVE-2023-22889Эксплойта нет | SmartBear Zephyr Enterprise through 7.15.0 mishandles user-defined input during report generation.smartbear · zephyr enterprise · CWE-94 | Критическая9,8 | — | 1,3 % | 8 мар. 2023 г. |
38Наблюдать | CVE-2018-20580Proof of concept | The WSDL import functionality in SmartBear ReadyAPI 2.5.0 and 2.6.0 allows remote attackers to execute arbitrary Java code via a crafted reqsmartbear · readyapi · CWE-20 | Высокая8,8 | — | 9,8 % | 3 мая 2019 г. |
36Наблюдать | CVE-2020-26118Эксплойта нет | In SmartBear Collaborator Server through 13.3.13302, use of the Google Web Toolkit (GWT) API introduces a post-authentication Java deserialismartbear · collaborator · CWE-502 | Высокая8,8 | — | 3,8 % | 11 янв. 2021 г. |
32Наблюдать | CVE-2019-12180Proof of concept | An issue was discovered in SmartBear ReadyAPI through 2.8.2 and 3.0.0 and SoapUI through 5.5.smartbear · readyapi | Высокая7,8 | — | 4,8 % | 5 февр. 2020 г. |
32Наблюдать | CVE-2023-22891Эксплойта нет | There exists a privilege escalation vulnerability in SmartBear Zephyr Enterprise through 7.15.0 that could be exploited by authorized users smartbear · zephyr enterprise · CWE-863 | Высокая8,1 | — | 0,5 % | 8 мар. 2023 г. |
31Наблюдать | CVE-2017-16670Эксплойта нет | The project import functionality in SoapUI 5.3.0 allows remote attackers to execute arbitrary Java code via a crafted request parameter in asmartbear · soapui · CWE-94 | Высокая7,8 | — | 1,6 % | 19 февр. 2018 г. |
31Наблюдать | CVE-2024-7565Эксплойта нет | SMARTBEAR SoapUI unpackageAll Directory Traversal Remote Code Execution Vulnerabilitysmartbear · soapui · CWE-22 | Высокая7,8 | — | 1,0 % | 22 нояб. 2024 г. |
30Наблюдать | CVE-2018-25031Proof of concept | Swagger UI 4.1.2 and earlier could allow a remote attacker to conduct spoofing attacks.smartbear · swagger ui · CWE-20 | Средняя4,3 | — | 42,3 % | 11 мар. 2022 г. |
30Наблюдать | CVE-2023-22890Эксплойта нет | SmartBear Zephyr Enterprise through 7.15.0 allows unauthenticated users to upload large files, which could exhaust the local drive space, casmartbear · zephyr enterprise · CWE-434 | Высокая7,5 | — | 0,6 % | 8 мар. 2023 г. |
30Наблюдать | CVE-2023-22892Эксплойта нет | There exists an information disclosure vulnerability in SmartBear Zephyr Enterprise through 7.15.0 that could be exploited by unauthenticatesmartbear · zephyr enterprise · CWE-668 | Высокая7,5 | — | 0,6 % | 8 мар. 2023 г. |
28Наблюдать | CVE-2021-21363Эксплойта нет | Generator Web Application: Local Privilege Escalation Vulnerability via System Temp Directorysmartbear · swagger-codegen · CWE-378 | Высокая7,0 | — | 0,4 % | 10 мар. 2021 г. |
26Наблюдать | CVE-2025-29157Эксплойта нет | An issue in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via accessing a non-existent endpoint/cart, the server retursmartbear · swagger petstore · CWE-77 | Средняя6,5 | — | 0,5 % | 25 сент. 2025 г. |
26Наблюдать | CVE-2025-29155Эксплойта нет | An issue in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via the DELETE endpointsmartbear · swagger petstore · CWE-77 | Средняя6,5 | — | 0,4 % | 25 сент. 2025 г. |
25Наблюдать | CVE-2016-1000229Proof of concept | swagger-ui has XSS in key namessmartbear · swagger-ui · CWE-79 | Средняя6,1 | — | 4,0 % | 20 дек. 2019 г. |
24Наблюдать | CVE-2021-46708Эксплойта нет | The swagger-ui-dist package before 4.1.3 for Node.js could allow a remote attacker to hijack the clicking action of the victim.smartbear · swagger-ui-dist · CWE-1021 | Средняя6,1 | — | 1,5 % | 11 мар. 2022 г. |
24Наблюдать | CVE-2016-5682Эксплойта нет | Swagger-UI before 2.2.1 has XSS via the Default field in the Definitions section.smartbear · swagger-ui · CWE-79 | Средняя6,1 | — | 1,0 % | 9 апр. 2017 г. |
24Наблюдать | CVE-2021-41657Эксплойта нет | SmartBear CodeCollaborator v6.1.6102 was discovered to contain a vulnerability in the web UI which would allow an attacker to conduct a clicsmartbear · collaborator · CWE-1021 | Средняя6,1 | — | 0,8 % | 10 мар. 2022 г. |
24Наблюдать | CVE-2025-29156Эксплойта нет | Cross Site Scripting vulnerability in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via a crafted script to the /api/vsmartbear · swagger petstore · CWE-79 | Средняя6,1 | — | 0,4 % | 25 сент. 2025 г. |
22Наблюдать | CVE-2024-22207Proof of concept | Default swagger-ui configuration exposes all files in the modulesmartbear · swagger ui · CWE-1188 | Средняя5,3 | — | 2,3 % | 15 янв. 2024 г. |
22Наблюдать | CVE-2021-21364Эксплойта нет | Generated Code Contains Local Information Disclosure Vulnerabilitysmartbear · swagger-codegen · CWE-200 | Средняя5,5 | — | 0,3 % | 10 мар. 2021 г. |
- CVE-2020-1283543В плане
An issue was discovered in SmartBear ReadyAPI SoapUI Pro 3.2.5.
КритическаяCVSS 9,8Эксплойта нетEPSS 13 %smartbear · readyapi20 мая 2020 г.
- CVE-2019-1749541В плане
A Cascading Style Sheets (CSS) injection vulnerability in Swagger UI before 3.23.11 allows attackers to use the Relative Path Overwrite (RPO
КритическаяCVSS 9,8Proof of conceptEPSS 6 %smartbear · swagger ui10 окт. 2019 г.
- CVE-2014-120239Наблюдать
The WSDL/WADL import functionality in SoapUI before 4.6.4 allows remote attackers to execute arbitrary Java code via a crafted request param
КритическаяCVSS 9,3Proof of conceptEPSS 8 %eviware · soapui24 янв. 2014 г.
- CVE-2023-2288939Наблюдать
SmartBear Zephyr Enterprise through 7.15.0 mishandles user-defined input during report generation.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %smartbear · zephyr enterprise8 мар. 2023 г.
- CVE-2018-2058038Наблюдать
The WSDL import functionality in SmartBear ReadyAPI 2.5.0 and 2.6.0 allows remote attackers to execute arbitrary Java code via a crafted req
ВысокаяCVSS 8,8Proof of conceptEPSS 10 %smartbear · readyapi3 мая 2019 г.
- CVE-2020-2611836Наблюдать
In SmartBear Collaborator Server through 13.3.13302, use of the Google Web Toolkit (GWT) API introduces a post-authentication Java deseriali
ВысокаяCVSS 8,8Эксплойта нетEPSS 4 %smartbear · collaborator11 янв. 2021 г.
- CVE-2019-1218032Наблюдать
An issue was discovered in SmartBear ReadyAPI through 2.8.2 and 3.0.0 and SoapUI through 5.5.
ВысокаяCVSS 7,8Proof of conceptEPSS 5 %smartbear · readyapi5 февр. 2020 г.
- CVE-2023-2289132Наблюдать
There exists a privilege escalation vulnerability in SmartBear Zephyr Enterprise through 7.15.0 that could be exploited by authorized users
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %smartbear · zephyr enterprise8 мар. 2023 г.
- CVE-2017-1667031Наблюдать
The project import functionality in SoapUI 5.3.0 allows remote attackers to execute arbitrary Java code via a crafted request parameter in a
ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %smartbear · soapui19 февр. 2018 г.
- CVE-2024-756531Наблюдать
SMARTBEAR SoapUI unpackageAll Directory Traversal Remote Code Execution Vulnerability
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %smartbear · soapui22 нояб. 2024 г.
- CVE-2018-2503130Наблюдать
Swagger UI 4.1.2 and earlier could allow a remote attacker to conduct spoofing attacks.
СредняяCVSS 4,3Proof of conceptEPSS 42 %smartbear · swagger ui11 мар. 2022 г.
- CVE-2023-2289030Наблюдать
SmartBear Zephyr Enterprise through 7.15.0 allows unauthenticated users to upload large files, which could exhaust the local drive space, ca
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %smartbear · zephyr enterprise8 мар. 2023 г.
- CVE-2023-2289230Наблюдать
There exists an information disclosure vulnerability in SmartBear Zephyr Enterprise through 7.15.0 that could be exploited by unauthenticate
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %smartbear · zephyr enterprise8 мар. 2023 г.
- CVE-2021-2136328Наблюдать
Generator Web Application: Local Privilege Escalation Vulnerability via System Temp Directory
ВысокаяCVSS 7,0Эксплойта нетEPSS 0 %smartbear · swagger-codegen10 мар. 2021 г.
- CVE-2025-2915726Наблюдать
An issue in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via accessing a non-existent endpoint/cart, the server retur
СредняяCVSS 6,5Эксплойта нетEPSS 1 %smartbear · swagger petstore25 сент. 2025 г.
- CVE-2025-2915526Наблюдать
An issue in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via the DELETE endpoint
СредняяCVSS 6,5Эксплойта нетEPSS 0 %smartbear · swagger petstore25 сент. 2025 г.
- CVE-2016-100022925Наблюдать
swagger-ui has XSS in key names
СредняяCVSS 6,1Proof of conceptEPSS 4 %smartbear · swagger-ui20 дек. 2019 г.
- CVE-2021-4670824Наблюдать
The swagger-ui-dist package before 4.1.3 for Node.js could allow a remote attacker to hijack the clicking action of the victim.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %smartbear · swagger-ui-dist11 мар. 2022 г.
- CVE-2016-568224Наблюдать
Swagger-UI before 2.2.1 has XSS via the Default field in the Definitions section.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %smartbear · swagger-ui9 апр. 2017 г.
- CVE-2021-4165724Наблюдать
SmartBear CodeCollaborator v6.1.6102 was discovered to contain a vulnerability in the web UI which would allow an attacker to conduct a clic
СредняяCVSS 6,1Эксплойта нетEPSS 1 %smartbear · collaborator10 мар. 2022 г.
- CVE-2025-2915624Наблюдать
Cross Site Scripting vulnerability in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via a crafted script to the /api/v
СредняяCVSS 6,1Эксплойта нетEPSS 0 %smartbear · swagger petstore25 сент. 2025 г.
- CVE-2024-2220722Наблюдать
Default swagger-ui configuration exposes all files in the module
СредняяCVSS 5,3Proof of conceptEPSS 2 %smartbear · swagger ui15 янв. 2024 г.
- CVE-2021-2136422Наблюдать
Generated Code Contains Local Information Disclosure Vulnerability
СредняяCVSS 5,5Эксплойта нетEPSS 0 %smartbear · swagger-codegen10 мар. 2021 г.