Vulnerability index

Browse CVEs

20 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Swagger Petstore MEDIUM 6.5
CVE-2025-29157

An issue in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via accessing a non-existent endpoint/cart, the server returns a 404-…

No fix yet
Fix from $1,600 2025-09-25
Swagger Petstore MEDIUM 6.1
CVE-2025-29156

Cross Site Scripting vulnerability in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via a crafted script to the /api/v3/pet

Mitigation only
Fix from $1,600 2025-09-25
Swagger Petstore MEDIUM 6.5
CVE-2025-29155

An issue in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via the DELETE endpoint

No fix yet
Fix from $1,600 2025-09-25
Soapui HIGH 7.8
CVE-2024-7565

SMARTBEAR SoapUI unpackageAll Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrar…

Mitigation only
Fix from $1,950 2024-11-22
Swagger Ui MEDIUM 5.3
CVE-2024-22207

fastify-swagger-ui is a Fastify plugin for serving Swagger UI. Prior to 2.1.0, the default configuration of `@fastify/swagger-ui` without `baseDir` …

Fix: 2.1.0+
Fix from $1,600 2024-01-15
Zephyr Enterprise CRITICAL 9.8
CVE-2023-22889

SmartBear Zephyr Enterprise through 7.15.0 mishandles user-defined input during report generation. This could lead to remote code execution by unauth…

Fix: after 7.15
Fix from $2,300 2023-03-08
Zephyr Enterprise HIGH 8.1
CVE-2023-22891

There exists a privilege escalation vulnerability in SmartBear Zephyr Enterprise through 7.15.0 that could be exploited by authorized users to reset …

Fix: after 7.15
Fix from $1,950 2023-03-08
Zephyr Enterprise HIGH 7.5
CVE-2023-22890

SmartBear Zephyr Enterprise through 7.15.0 allows unauthenticated users to upload large files, which could exhaust the local drive space, causing a d…

Fix: after 7.15
Fix from $1,950 2023-03-08
Zephyr Enterprise HIGH 7.5
CVE-2023-22892

There exists an information disclosure vulnerability in SmartBear Zephyr Enterprise through 7.15.0 that could be exploited by unauthenticated users t…

Fix: after 7.15
Fix from $1,950 2023-03-08
Swagger Ui Dist MEDIUM 6.1
CVE-2021-46708

The swagger-ui-dist package before 4.1.3 for Node.js could allow a remote attacker to hijack the clicking action of the victim. By persuading a victi…

Fix: 4.1.3+
Fix from $1,600 2022-03-11
Collaborator MEDIUM 6.1
CVE-2021-41657

SmartBear CodeCollaborator v6.1.6102 was discovered to contain a vulnerability in the web UI which would allow an attacker to conduct a clickjacking …

No fix yet
Fix from $1,600 2022-03-10
Swagger Codegen MEDIUM 5.5
CVE-2021-21364

swagger-codegen is an open-source project which contains a template-driven engine to generate documentation, API clients and server stubs in differen…

Fix: 2.4.19+
Fix from $1,600 2021-03-11
Swagger Codegen HIGH 7.0
CVE-2021-21363

swagger-codegen is an open-source project which contains a template-driven engine to generate documentation, API clients and server stubs in differen…

Fix: 2.4.19+
Fix from $1,950 2021-03-11
Collaborator HIGH 8.8
CVE-2020-26118

In SmartBear Collaborator Server through 13.3.13302, use of the Google Web Toolkit (GWT) API introduces a post-authentication Java deserialization vu…

Fix: after 13.3.13302
Fix from $1,950 2021-01-11
Readyapi CRITICAL 9.8
CVE-2020-12835EPSS 13%

An issue was discovered in SmartBear ReadyAPI SoapUI Pro 3.2.5. Due to unsafe use of an Java RMI based protocol in an unsafe configuration, an attack…

No fix yet
Fix from $2,300 2020-05-20
Readyapi HIGH 7.8
CVE-2019-12180

An issue was discovered in SmartBear ReadyAPI through 2.8.2 and 3.0.0 and SoapUI through 5.5. When opening a project, the Groovy "Load Script" is aut…

Fix: after 5.5
Fix from $1,950 2020-02-05
Swagger Ui CRITICAL 9.8
CVE-2019-17495EPSS 6%

A Cascading Style Sheets (CSS) injection vulnerability in Swagger UI before 3.23.11 allows attackers to use the Relative Path Overwrite (RPO) techniq…

Fix: 3.23.11+
Fix from $2,300 2019-10-10
Readyapi HIGH 8.8
CVE-2018-20580EPSS 10%

The WSDL import functionality in SmartBear ReadyAPI 2.5.0 and 2.6.0 allows remote attackers to execute arbitrary Java code via a crafted request para…

No fix yet
Fix from $1,950 2019-05-03
Soapui HIGH 7.8
CVE-2017-16670

The project import functionality in SoapUI 5.3.0 allows remote attackers to execute arbitrary Java code via a crafted request parameter in a WSDL pro…

No fix yet
Fix from $1,950 2018-02-19
Swagger Ui MEDIUM 6.1
CVE-2016-5682

Swagger-UI before 2.2.1 has XSS via the Default field in the Definitions section.

Fix: 2.2.1+
Fix from $1,600 2017-04-10