Vulnerability index

Browse CVEs

20 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2025-29157 An issue in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via accessing a non-existent endpoint/cart, the server returns a 404-… Swagger Petstore No fix yet Fix from $1,6002025-09-25 MEDIUM 6.1 CVE-2025-29156 Cross Site Scripting vulnerability in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via a crafted script to the /api/v3/pet Swagger Petstore Mitigation only Fix from $1,6002025-09-25 MEDIUM 6.5 CVE-2025-29155 An issue in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via the DELETE endpoint Swagger Petstore No fix yet Fix from $1,6002025-09-25 HIGH 7.8 CVE-2024-7565 SMARTBEAR SoapUI unpackageAll Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrar… Soapui Mitigation only Fix from $1,9502024-11-22 MEDIUM 5.3 CVE-2024-22207 fastify-swagger-ui is a Fastify plugin for serving Swagger UI. Prior to 2.1.0, the default configuration of `@fastify/swagger-ui` without `baseDir` … Swagger Ui 2.1.0+ Fix from $1,6002024-01-15 CRITICAL 9.8 CVE-2023-22889 SmartBear Zephyr Enterprise through 7.15.0 mishandles user-defined input during report generation. This could lead to remote code execution by unauth… Zephyr Enterprise after 7.15 Fix from $2,3002023-03-08 HIGH 8.1 CVE-2023-22891 There exists a privilege escalation vulnerability in SmartBear Zephyr Enterprise through 7.15.0 that could be exploited by authorized users to reset … Zephyr Enterprise after 7.15 Fix from $1,9502023-03-08 HIGH 7.5 CVE-2023-22890 SmartBear Zephyr Enterprise through 7.15.0 allows unauthenticated users to upload large files, which could exhaust the local drive space, causing a d… Zephyr Enterprise after 7.15 Fix from $1,9502023-03-08 HIGH 7.5 CVE-2023-22892 There exists an information disclosure vulnerability in SmartBear Zephyr Enterprise through 7.15.0 that could be exploited by unauthenticated users t… Zephyr Enterprise after 7.15 Fix from $1,9502023-03-08 MEDIUM 6.1 CVE-2021-46708 The swagger-ui-dist package before 4.1.3 for Node.js could allow a remote attacker to hijack the clicking action of the victim. By persuading a victi… Swagger Ui Dist 4.1.3+ Fix from $1,6002022-03-11 MEDIUM 6.1 CVE-2021-41657 SmartBear CodeCollaborator v6.1.6102 was discovered to contain a vulnerability in the web UI which would allow an attacker to conduct a clickjacking … Collaborator No fix yet Fix from $1,6002022-03-10 MEDIUM 5.5 CVE-2021-21364 swagger-codegen is an open-source project which contains a template-driven engine to generate documentation, API clients and server stubs in differen… Swagger Codegen 2.4.19+ Fix from $1,6002021-03-11 HIGH 7.0 CVE-2021-21363 swagger-codegen is an open-source project which contains a template-driven engine to generate documentation, API clients and server stubs in differen… Swagger Codegen 2.4.19+ Fix from $1,9502021-03-11 HIGH 8.8 CVE-2020-26118 In SmartBear Collaborator Server through 13.3.13302, use of the Google Web Toolkit (GWT) API introduces a post-authentication Java deserialization vu… Collaborator after 13.3.13302 Fix from $1,9502021-01-11 CRITICAL 9.8 CVE-2020-12835EPSS 13% An issue was discovered in SmartBear ReadyAPI SoapUI Pro 3.2.5. Due to unsafe use of an Java RMI based protocol in an unsafe configuration, an attack… Readyapi No fix yet Fix from $2,3002020-05-20 HIGH 7.8 CVE-2019-12180 An issue was discovered in SmartBear ReadyAPI through 2.8.2 and 3.0.0 and SoapUI through 5.5. When opening a project, the Groovy "Load Script" is aut… Readyapi after 5.5 Fix from $1,9502020-02-05 CRITICAL 9.8 CVE-2019-17495EPSS 6% A Cascading Style Sheets (CSS) injection vulnerability in Swagger UI before 3.23.11 allows attackers to use the Relative Path Overwrite (RPO) techniq… Swagger Ui 3.23.11+ Fix from $2,3002019-10-10 HIGH 8.8 CVE-2018-20580EPSS 10% The WSDL import functionality in SmartBear ReadyAPI 2.5.0 and 2.6.0 allows remote attackers to execute arbitrary Java code via a crafted request para… Readyapi No fix yet Fix from $1,9502019-05-03 HIGH 7.8 CVE-2017-16670 The project import functionality in SoapUI 5.3.0 allows remote attackers to execute arbitrary Java code via a crafted request parameter in a WSDL pro… Soapui No fix yet Fix from $1,9502018-02-19 MEDIUM 6.1 CVE-2016-5682 Swagger-UI before 2.2.1 has XSS via the Default field in the Definitions section. Swagger Ui 2.2.1+ Fix from $1,6002017-04-10