Known Vulnerabilities for products from Smartbear
Listed below are 19 of the newest known vulnerabilities associated with the vendor "Smartbear".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2024-22207 json | 5.3 - MEDIUM | 2024-01-15 | 2024-01-23 | |
| CVE-2023-22892 json | There exists an information disclosure vulnerability in SmartBear Zephyr Enterprise through 7.15.0 that could be exploited by... | 7.5 - HIGH | 2023-03-08 | 2023-03-14 |
| CVE-2023-22891 json | There exists a privilege escalation vulnerability in SmartBear Zephyr Enterprise through 7.15.0 that could be exploited by au... | 8.1 - HIGH | 2023-03-08 | 2023-03-16 |
| CVE-2023-22890 json | SmartBear Zephyr Enterprise through 7.15.0 allows unauthenticated users to upload large files, which could exhaust the local ... | 7.5 - HIGH | 2023-03-08 | 2023-03-14 |
| CVE-2023-22889 json | SmartBear Zephyr Enterprise through 7.15.0 mishandles user-defined input during report generation. This could lead to remote ... | 9.8 - CRITICAL | 2023-03-08 | 2023-03-14 |
| CVE-2021-46708 json | The swagger-ui-dist package before 4.1.3 for Node.js could allow a remote attacker to hijack the clicking action of the victi... | 6.1 - MEDIUM | 2022-03-11 | 2023-03-28 |
| CVE-2021-41657 json | SmartBear CodeCollaborator v6.1.6102 was discovered to contain a vulnerability in the web UI which would allow an attacker to... | Not Provided | 2022-03-10 | 2026-07-09 |
| CVE-2021-21364 json | swagger-codegen is an open-source project which contains a template-driven engine to generate documentation, API clients and ... | 5.5 - MEDIUM | 2021-03-11 | 2022-10-21 |
| CVE-2021-21363 json | swagger-codegen is an open-source project which contains a template-driven engine to generate documentation, API clients and ... | 7 - HIGH | 2021-03-11 | 2021-03-18 |
| CVE-2020-26118 json | In SmartBear Collaborator Server through 13.3.13302, use of the Google Web Toolkit (GWT) API introduces a post-authentication... | 8.8 - HIGH | 2021-01-11 | 2021-07-21 |
| CVE-2020-12835 json | An issue was discovered in SmartBear ReadyAPI SoapUI Pro 3.2.5. Due to unsafe use of an Java RMI based protocol in an unsafe ... | 9.8 - CRITICAL | 2020-05-20 | 2021-07-21 |
| CVE-2019-17495 json | A Cascading Style Sheets (CSS) injection vulnerability in Swagger UI before 3.23.11 allows attackers to use the Relative Path... | 9.8 - CRITICAL | 2019-10-10 | 2023-11-07 |
| CVE-2019-12180 json | An issue was discovered in SmartBear ReadyAPI through 2.8.2 and 3.0.0 and SoapUI through 5.5. When opening a project, the Gro... | 7.8 - HIGH | 2020-02-05 | 2020-08-24 |
| CVE-2018-25031 json | Swagger UI before 4.1.3 could allow a remote attacker to conduct spoofing attacks. By persuading a victim to open a crafted U... | 4.3 - MEDIUM | 2022-03-11 | 2022-06-03 |
| CVE-2018-20580 json | The WSDL import functionality in SmartBear ReadyAPI 2.5.0 and 2.6.0 allows remote attackers to execute arbitrary Java code vi... | 8.8 - HIGH | 2019-05-03 | 2019-05-14 |
| CVE-2017-16670 json | The project import functionality in SoapUI 5.3.0 allows remote attackers to execute arbitrary Java code via a crafted request... | 7.8 - HIGH | 2018-02-19 | 2018-03-19 |
| CVE-2016-1000229 json | swagger-ui has XSS in key names | 6.1 - MEDIUM | 2019-12-20 | 2019-12-31 |
| CVE-2016-5682 json | Swagger-UI before 2.2.1 has XSS via the Default field in the Definitions section. | Not Provided | 2017-04-10 | 2025-04-20 |
| CVE-2014-1202 json | The WSDL/WADL import functionality in SoapUI before 4.6.4 allows remote attackers to execute arbitrary Java code via a crafte... | Not Provided | 2014-01-25 | 2026-04-29 |
Known software with vulnerabilities from Smartbear
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Smartbear | Aqtime | 7.10.380.86 |
| Application | Smartbear | Collaborator | 12.3.12304 |
| Application | Smartbear | Readyapi | 1.0 |
| Application | Smartbear | Soapui | 1.0 |
| Application | Smartbear | Swagger-codegen | 2.1.1 |
| Application | Smartbear | Swagger-ui | - |
| Application | Smartbear | Swagger Codegen | 2.0.13 |
| Application | Smartbear | Swagger Ui | 1.0 |