İçeriğe atla
Noroxi

smartbear kayıtları

smartbear üreticisine ait 23 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
7
Düzeltme kaydı olan
%39,1
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

23 kayıt
  • CVE-2020-12835
    43Planlayın

    An issue was discovered in SmartBear ReadyAPI SoapUI Pro 3.2.5.

    KritikCVSS 9,8İstismar yokEPSS %13

    smartbear · readyapi20 May 2020

  • CVE-2019-17495
    41Planlayın

    A Cascading Style Sheets (CSS) injection vulnerability in Swagger UI before 3.23.11 allows attackers to use the Relative Path Overwrite (RPO

    KritikCVSS 9,8Kavram kanıtıEPSS %6

    smartbear · swagger ui10 Eki 2019

  • CVE-2014-1202
    39İzleyin

    The WSDL/WADL import functionality in SoapUI before 4.6.4 allows remote attackers to execute arbitrary Java code via a crafted request param

    KritikCVSS 9,3Kavram kanıtıEPSS %8

    eviware · soapui24 Oca 2014

  • CVE-2023-22889
    39İzleyin

    SmartBear Zephyr Enterprise through 7.15.0 mishandles user-defined input during report generation.

    KritikCVSS 9,8İstismar yokEPSS %1

    smartbear · zephyr enterprise8 Mar 2023

  • CVE-2018-20580
    38İzleyin

    The WSDL import functionality in SmartBear ReadyAPI 2.5.0 and 2.6.0 allows remote attackers to execute arbitrary Java code via a crafted req

    YüksekCVSS 8,8Kavram kanıtıEPSS %10

    smartbear · readyapi3 May 2019

  • CVE-2020-26118
    36İzleyin

    In SmartBear Collaborator Server through 13.3.13302, use of the Google Web Toolkit (GWT) API introduces a post-authentication Java deseriali

    YüksekCVSS 8,8İstismar yokEPSS %4

    smartbear · collaborator11 Oca 2021

  • CVE-2019-12180
    32İzleyin

    An issue was discovered in SmartBear ReadyAPI through 2.8.2 and 3.0.0 and SoapUI through 5.5.

    YüksekCVSS 7,8Kavram kanıtıEPSS %5

    smartbear · readyapi5 Şub 2020

  • CVE-2023-22891
    32İzleyin

    There exists a privilege escalation vulnerability in SmartBear Zephyr Enterprise through 7.15.0 that could be exploited by authorized users

    YüksekCVSS 8,1İstismar yokEPSS %1

    smartbear · zephyr enterprise8 Mar 2023

  • CVE-2017-16670
    31İzleyin

    The project import functionality in SoapUI 5.3.0 allows remote attackers to execute arbitrary Java code via a crafted request parameter in a

    YüksekCVSS 7,8İstismar yokEPSS %2

    smartbear · soapui19 Şub 2018

  • CVE-2024-7565
    31İzleyin

    SMARTBEAR SoapUI unpackageAll Directory Traversal Remote Code Execution Vulnerability

    YüksekCVSS 7,8İstismar yokEPSS %1

    smartbear · soapui22 Kas 2024

  • CVE-2018-25031
    30İzleyin

    Swagger UI 4.1.2 and earlier could allow a remote attacker to conduct spoofing attacks.

    OrtaCVSS 4,3Kavram kanıtıEPSS %42

    smartbear · swagger ui11 Mar 2022

  • CVE-2023-22890
    30İzleyin

    SmartBear Zephyr Enterprise through 7.15.0 allows unauthenticated users to upload large files, which could exhaust the local drive space, ca

    YüksekCVSS 7,5İstismar yokEPSS %1

    smartbear · zephyr enterprise8 Mar 2023

  • CVE-2023-22892
    30İzleyin

    There exists an information disclosure vulnerability in SmartBear Zephyr Enterprise through 7.15.0 that could be exploited by unauthenticate

    YüksekCVSS 7,5İstismar yokEPSS %1

    smartbear · zephyr enterprise8 Mar 2023

  • CVE-2021-21363
    28İzleyin

    Generator Web Application: Local Privilege Escalation Vulnerability via System Temp Directory

    YüksekCVSS 7,0İstismar yokEPSS %0

    smartbear · swagger-codegen10 Mar 2021

  • CVE-2025-29157
    26İzleyin

    An issue in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via accessing a non-existent endpoint/cart, the server retur

    OrtaCVSS 6,5İstismar yokEPSS %1

    smartbear · swagger petstore25 Eyl 2025

  • CVE-2025-29155
    26İzleyin

    An issue in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via the DELETE endpoint

    OrtaCVSS 6,5İstismar yokEPSS %0

    smartbear · swagger petstore25 Eyl 2025

  • swagger-ui has XSS in key names

    OrtaCVSS 6,1Kavram kanıtıEPSS %4

    smartbear · swagger-ui20 Ara 2019

  • CVE-2021-46708
    24İzleyin

    The swagger-ui-dist package before 4.1.3 for Node.js could allow a remote attacker to hijack the clicking action of the victim.

    OrtaCVSS 6,1İstismar yokEPSS %1

    smartbear · swagger-ui-dist11 Mar 2022

  • CVE-2016-5682
    24İzleyin

    Swagger-UI before 2.2.1 has XSS via the Default field in the Definitions section.

    OrtaCVSS 6,1İstismar yokEPSS %1

    smartbear · swagger-ui9 Nis 2017

  • CVE-2021-41657
    24İzleyin

    SmartBear CodeCollaborator v6.1.6102 was discovered to contain a vulnerability in the web UI which would allow an attacker to conduct a clic

    OrtaCVSS 6,1İstismar yokEPSS %1

    smartbear · collaborator10 Mar 2022

  • CVE-2025-29156
    24İzleyin

    Cross Site Scripting vulnerability in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via a crafted script to the /api/v

    OrtaCVSS 6,1İstismar yokEPSS %0

    smartbear · swagger petstore25 Eyl 2025

  • CVE-2024-22207
    22İzleyin

    Default swagger-ui configuration exposes all files in the module

    OrtaCVSS 5,3Kavram kanıtıEPSS %2

    smartbear · swagger ui15 Oca 2024

  • CVE-2021-21364
    22İzleyin

    Generated Code Contains Local Information Disclosure Vulnerability

    OrtaCVSS 5,5İstismar yokEPSS %0

    smartbear · swagger-codegen10 Mar 2021