smartbear kayıtları
smartbear üreticisine ait 23 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 7
- Düzeltme kaydı olan
- %39,1
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-94 Improper Control of Generation of Code ('Code Injection')3
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-1021 Improper Restriction of Rendered UI Layers or Frames2
- CWE-20 Improper Input Validation2
- CWE-502 Deserialization of Untrusted Data2
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
23 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
43Planlayın | CVE-2020-12835İstismar yok | An issue was discovered in SmartBear ReadyAPI SoapUI Pro 3.2.5.smartbear · readyapi · CWE-502 | Kritik9,8 | — | %13,0 | 20 May 2020 |
41Planlayın | CVE-2019-17495Kavram kanıtı | A Cascading Style Sheets (CSS) injection vulnerability in Swagger UI before 3.23.11 allows attackers to use the Relative Path Overwrite (RPOsmartbear · swagger ui · CWE-352 | Kritik9,8 | — | %5,7 | 10 Eki 2019 |
39İzleyin | CVE-2014-1202Kavram kanıtı | The WSDL/WADL import functionality in SoapUI before 4.6.4 allows remote attackers to execute arbitrary Java code via a crafted request parameviware · soapui · CWE-94 | Kritik9,3 | — | %7,7 | 24 Oca 2014 |
39İzleyin | CVE-2023-22889İstismar yok | SmartBear Zephyr Enterprise through 7.15.0 mishandles user-defined input during report generation.smartbear · zephyr enterprise · CWE-94 | Kritik9,8 | — | %1,3 | 8 Mar 2023 |
38İzleyin | CVE-2018-20580Kavram kanıtı | The WSDL import functionality in SmartBear ReadyAPI 2.5.0 and 2.6.0 allows remote attackers to execute arbitrary Java code via a crafted reqsmartbear · readyapi · CWE-20 | Yüksek8,8 | — | %9,8 | 3 May 2019 |
36İzleyin | CVE-2020-26118İstismar yok | In SmartBear Collaborator Server through 13.3.13302, use of the Google Web Toolkit (GWT) API introduces a post-authentication Java deserialismartbear · collaborator · CWE-502 | Yüksek8,8 | — | %3,8 | 11 Oca 2021 |
32İzleyin | CVE-2019-12180Kavram kanıtı | An issue was discovered in SmartBear ReadyAPI through 2.8.2 and 3.0.0 and SoapUI through 5.5.smartbear · readyapi | Yüksek7,8 | — | %4,8 | 5 Şub 2020 |
32İzleyin | CVE-2023-22891İstismar yok | There exists a privilege escalation vulnerability in SmartBear Zephyr Enterprise through 7.15.0 that could be exploited by authorized users smartbear · zephyr enterprise · CWE-863 | Yüksek8,1 | — | %0,5 | 8 Mar 2023 |
31İzleyin | CVE-2017-16670İstismar yok | The project import functionality in SoapUI 5.3.0 allows remote attackers to execute arbitrary Java code via a crafted request parameter in asmartbear · soapui · CWE-94 | Yüksek7,8 | — | %1,6 | 19 Şub 2018 |
31İzleyin | CVE-2024-7565İstismar yok | SMARTBEAR SoapUI unpackageAll Directory Traversal Remote Code Execution Vulnerabilitysmartbear · soapui · CWE-22 | Yüksek7,8 | — | %1,0 | 22 Kas 2024 |
30İzleyin | CVE-2018-25031Kavram kanıtı | Swagger UI 4.1.2 and earlier could allow a remote attacker to conduct spoofing attacks.smartbear · swagger ui · CWE-20 | Orta4,3 | — | %42,3 | 11 Mar 2022 |
30İzleyin | CVE-2023-22890İstismar yok | SmartBear Zephyr Enterprise through 7.15.0 allows unauthenticated users to upload large files, which could exhaust the local drive space, casmartbear · zephyr enterprise · CWE-434 | Yüksek7,5 | — | %0,6 | 8 Mar 2023 |
30İzleyin | CVE-2023-22892İstismar yok | There exists an information disclosure vulnerability in SmartBear Zephyr Enterprise through 7.15.0 that could be exploited by unauthenticatesmartbear · zephyr enterprise · CWE-668 | Yüksek7,5 | — | %0,6 | 8 Mar 2023 |
28İzleyin | CVE-2021-21363İstismar yok | Generator Web Application: Local Privilege Escalation Vulnerability via System Temp Directorysmartbear · swagger-codegen · CWE-378 | Yüksek7,0 | — | %0,4 | 10 Mar 2021 |
26İzleyin | CVE-2025-29157İstismar yok | An issue in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via accessing a non-existent endpoint/cart, the server retursmartbear · swagger petstore · CWE-77 | Orta6,5 | — | %0,5 | 25 Eyl 2025 |
26İzleyin | CVE-2025-29155İstismar yok | An issue in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via the DELETE endpointsmartbear · swagger petstore · CWE-77 | Orta6,5 | — | %0,4 | 25 Eyl 2025 |
25İzleyin | CVE-2016-1000229Kavram kanıtı | swagger-ui has XSS in key namessmartbear · swagger-ui · CWE-79 | Orta6,1 | — | %4,0 | 20 Ara 2019 |
24İzleyin | CVE-2021-46708İstismar yok | The swagger-ui-dist package before 4.1.3 for Node.js could allow a remote attacker to hijack the clicking action of the victim.smartbear · swagger-ui-dist · CWE-1021 | Orta6,1 | — | %1,5 | 11 Mar 2022 |
24İzleyin | CVE-2016-5682İstismar yok | Swagger-UI before 2.2.1 has XSS via the Default field in the Definitions section.smartbear · swagger-ui · CWE-79 | Orta6,1 | — | %1,0 | 9 Nis 2017 |
24İzleyin | CVE-2021-41657İstismar yok | SmartBear CodeCollaborator v6.1.6102 was discovered to contain a vulnerability in the web UI which would allow an attacker to conduct a clicsmartbear · collaborator · CWE-1021 | Orta6,1 | — | %0,8 | 10 Mar 2022 |
24İzleyin | CVE-2025-29156İstismar yok | Cross Site Scripting vulnerability in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via a crafted script to the /api/vsmartbear · swagger petstore · CWE-79 | Orta6,1 | — | %0,4 | 25 Eyl 2025 |
22İzleyin | CVE-2024-22207Kavram kanıtı | Default swagger-ui configuration exposes all files in the modulesmartbear · swagger ui · CWE-1188 | Orta5,3 | — | %2,3 | 15 Oca 2024 |
22İzleyin | CVE-2021-21364İstismar yok | Generated Code Contains Local Information Disclosure Vulnerabilitysmartbear · swagger-codegen · CWE-200 | Orta5,5 | — | %0,3 | 10 Mar 2021 |
- CVE-2020-1283543Planlayın
An issue was discovered in SmartBear ReadyAPI SoapUI Pro 3.2.5.
KritikCVSS 9,8İstismar yokEPSS %13smartbear · readyapi20 May 2020
- CVE-2019-1749541Planlayın
A Cascading Style Sheets (CSS) injection vulnerability in Swagger UI before 3.23.11 allows attackers to use the Relative Path Overwrite (RPO
KritikCVSS 9,8Kavram kanıtıEPSS %6smartbear · swagger ui10 Eki 2019
- CVE-2014-120239İzleyin
The WSDL/WADL import functionality in SoapUI before 4.6.4 allows remote attackers to execute arbitrary Java code via a crafted request param
KritikCVSS 9,3Kavram kanıtıEPSS %8eviware · soapui24 Oca 2014
- CVE-2023-2288939İzleyin
SmartBear Zephyr Enterprise through 7.15.0 mishandles user-defined input during report generation.
KritikCVSS 9,8İstismar yokEPSS %1smartbear · zephyr enterprise8 Mar 2023
- CVE-2018-2058038İzleyin
The WSDL import functionality in SmartBear ReadyAPI 2.5.0 and 2.6.0 allows remote attackers to execute arbitrary Java code via a crafted req
YüksekCVSS 8,8Kavram kanıtıEPSS %10smartbear · readyapi3 May 2019
- CVE-2020-2611836İzleyin
In SmartBear Collaborator Server through 13.3.13302, use of the Google Web Toolkit (GWT) API introduces a post-authentication Java deseriali
YüksekCVSS 8,8İstismar yokEPSS %4smartbear · collaborator11 Oca 2021
- CVE-2019-1218032İzleyin
An issue was discovered in SmartBear ReadyAPI through 2.8.2 and 3.0.0 and SoapUI through 5.5.
YüksekCVSS 7,8Kavram kanıtıEPSS %5smartbear · readyapi5 Şub 2020
- CVE-2023-2289132İzleyin
There exists a privilege escalation vulnerability in SmartBear Zephyr Enterprise through 7.15.0 that could be exploited by authorized users
YüksekCVSS 8,1İstismar yokEPSS %1smartbear · zephyr enterprise8 Mar 2023
- CVE-2017-1667031İzleyin
The project import functionality in SoapUI 5.3.0 allows remote attackers to execute arbitrary Java code via a crafted request parameter in a
YüksekCVSS 7,8İstismar yokEPSS %2smartbear · soapui19 Şub 2018
- CVE-2024-756531İzleyin
SMARTBEAR SoapUI unpackageAll Directory Traversal Remote Code Execution Vulnerability
YüksekCVSS 7,8İstismar yokEPSS %1smartbear · soapui22 Kas 2024
- CVE-2018-2503130İzleyin
Swagger UI 4.1.2 and earlier could allow a remote attacker to conduct spoofing attacks.
OrtaCVSS 4,3Kavram kanıtıEPSS %42smartbear · swagger ui11 Mar 2022
- CVE-2023-2289030İzleyin
SmartBear Zephyr Enterprise through 7.15.0 allows unauthenticated users to upload large files, which could exhaust the local drive space, ca
YüksekCVSS 7,5İstismar yokEPSS %1smartbear · zephyr enterprise8 Mar 2023
- CVE-2023-2289230İzleyin
There exists an information disclosure vulnerability in SmartBear Zephyr Enterprise through 7.15.0 that could be exploited by unauthenticate
YüksekCVSS 7,5İstismar yokEPSS %1smartbear · zephyr enterprise8 Mar 2023
- CVE-2021-2136328İzleyin
Generator Web Application: Local Privilege Escalation Vulnerability via System Temp Directory
YüksekCVSS 7,0İstismar yokEPSS %0smartbear · swagger-codegen10 Mar 2021
- CVE-2025-2915726İzleyin
An issue in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via accessing a non-existent endpoint/cart, the server retur
OrtaCVSS 6,5İstismar yokEPSS %1smartbear · swagger petstore25 Eyl 2025
- CVE-2025-2915526İzleyin
An issue in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via the DELETE endpoint
OrtaCVSS 6,5İstismar yokEPSS %0smartbear · swagger petstore25 Eyl 2025
- CVE-2016-100022925İzleyin
swagger-ui has XSS in key names
OrtaCVSS 6,1Kavram kanıtıEPSS %4smartbear · swagger-ui20 Ara 2019
- CVE-2021-4670824İzleyin
The swagger-ui-dist package before 4.1.3 for Node.js could allow a remote attacker to hijack the clicking action of the victim.
OrtaCVSS 6,1İstismar yokEPSS %1smartbear · swagger-ui-dist11 Mar 2022
- CVE-2016-568224İzleyin
Swagger-UI before 2.2.1 has XSS via the Default field in the Definitions section.
OrtaCVSS 6,1İstismar yokEPSS %1smartbear · swagger-ui9 Nis 2017
- CVE-2021-4165724İzleyin
SmartBear CodeCollaborator v6.1.6102 was discovered to contain a vulnerability in the web UI which would allow an attacker to conduct a clic
OrtaCVSS 6,1İstismar yokEPSS %1smartbear · collaborator10 Mar 2022
- CVE-2025-2915624İzleyin
Cross Site Scripting vulnerability in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via a crafted script to the /api/v
OrtaCVSS 6,1İstismar yokEPSS %0smartbear · swagger petstore25 Eyl 2025
- CVE-2024-2220722İzleyin
Default swagger-ui configuration exposes all files in the module
OrtaCVSS 5,3Kavram kanıtıEPSS %2smartbear · swagger ui15 Oca 2024
- CVE-2021-2136422İzleyin
Generated Code Contains Local Information Disclosure Vulnerability
OrtaCVSS 5,5İstismar yokEPSS %0smartbear · swagger-codegen10 Mar 2021