Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
36 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 1.5% | — | Smartbear Swagger-ui-dist | 11/3/2022 | 17/6/2026 | The swagger-ui-dist package before 4.1.3 for Node.js could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the… | |
| Modificada | Media (4.3) | 42% | 💥 PoC | Smartbear Swagger UI | 11/3/2022 | 17/6/2026 | Swagger UI 4.1.2 and earlier could allow a remote attacker to conduct spoofing attacks. By persuading a victim to open a crafted URL, an attacker could exploit this vulnerability to display remote OpenAPI definitions. Note: This was originally claimed to be resolved in 4.1.3. However, third parties have indicated this… | |
| Modificada | Media (6.1) | 3.9% | 💥 Exploit | Embed Swagger Project Embed Swagger | 4/2/2022 | 17/6/2026 | The Embed Swagger WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to insufficient escaping/sanitization and validation via the url parameter found in the ~/swagger-iframe.php file which allows attackers to inject arbitrary web scripts onto the page, in versions up to and including 1.0.0. | |
| Modificada | Media (5.5) | 0.28% | — | Smartbear Swagger-codegen | 11/3/2021 | 17/6/2026 | swagger-codegen is an open-source project which contains a template-driven engine to generate documentation, API clients and server stubs in different languages by parsing your OpenAPI / Swagger definition. In swagger-codegen before version 2.4.19, on Unix-Like systems, the system temporary directory is shared between… | |
| Modificada | Alta (7) | 0.41% | — | Smartbear Swagger-codegen | 11/3/2021 | 17/6/2026 | swagger-codegen is an open-source project which contains a template-driven engine to generate documentation, API clients and server stubs in different languages by parsing your OpenAPI / Swagger definition. In swagger-codegen before version 2.4.19, on Unix like systems, the system's temporary directory is shared… | |
| Modificada | Media (6.1) | 4.0% | 💥 PoC | Smartbear Swagger-uiRedhat Jboss FuseRedhat Openshift | 20/12/2019 | 17/6/2026 | swagger-ui has XSS in key names | |
| Modificada | Crítica (9.8) | 5.7% | 💥 PoC | Smartbear Swagger UIOracle Banking ApisOracle Banking Digital ExperienceOracle Banking Platform+2 | 10/10/2019 | 17/6/2026 | A Cascading Style Sheets (CSS) injection vulnerability in Swagger UI before 3.23.11 allows attackers to use the Relative Path Overwrite (RPO) technique to perform CSS-based input field value exfiltration, such as exfiltration of a CSRF token value. In other words, this product intentionally allows the embedding of… | |
| Modificada | Alta (8.8) | 0.78% | — | HTC Customer-link BridgeVolkswagen Customer-link | 2/3/2018 | 17/6/2026 | This vulnerability allows adjacent attackers to inject arbitrary Controller Area Network messages on vulnerable installations of Volkswagen Customer-Link App 1.30 and HTC Customer-Link Bridge. Authentication is not required to exploit this vulnerability. The specific flaw exists within the Customer-Link App and… | |
| Modificada | Alta (8.8) | 1.6% | — | Swagger-codegenSwagger-parser | 27/11/2017 | 17/6/2026 | A vulnerability in Swagger-Parser's version <= 1.0.30 and Swagger codegen version <= 2.2.2 yaml parsing functionality results in arbitrary code being executed when a maliciously crafted yaml Open-API specification is parsed. This in particular, affects the 'generate' and 'validate' command in swagger-codegen (<=… | |
| Modificada | Alta (8.8) | 1.7% | — | Swagger-codegenSwagger-parser | 17/11/2017 | 17/6/2026 | A vulnerability in Swagger-Parser's (version <= 1.0.30) yaml parsing functionality results in arbitrary code being executed when a maliciously crafted yaml Open-API specification is parsed. This in particular, affects the 'generate' and 'validate' command in swagger-codegen (<= 2.2.2) and can lead to arbitrary code… | |
| Modificada | Media (6.1) | 1.0% | — | Smartbear Swagger-ui | 10/4/2017 | 17/6/2026 | Swagger-UI before 2.2.1 has XSS via the Default field in the Definitions section. |