Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2528▼ 418 respecto a la semana anterior
Críticas / altas1311▲ 21 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)99▼ 428 respecto a la semana anterior
–

8 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.3)0.28%—Swagger UIAIWso2 API PublisherAI6/8/202629/9/2026
The Swagger UI Try-out console within the API Publisher documentation allows an external Swagger API definition URL to be loaded, overriding the existing API definitions within the Publisher portal. By exploiting this vulnerability, malicious actors can deceive users into interacting with these overwritten API…
AnalizadaMedia (5.4)0.22%—Vinayjain Embed Swagger UI30/1/202517/6/2026
The Embed Swagger UI plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpsgui' shortcode in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with…
ModificadaMedia (5.3)2.3%—Smartbear Swagger UI15/1/202417/6/2026
fastify-swagger-ui is a Fastify plugin for serving Swagger UI. Prior to 2.1.0, the default configuration of `@fastify/swagger-ui` without `baseDir` set will lead to all files in the module's directory being exposed via http routes served by the module. The vulnerability is fixed in v2.1.0. Setting the `baseDir` option…
ModificadaMedia (6.1)1.5%—Smartbear Swagger-ui-dist11/3/202217/6/2026
The swagger-ui-dist package before 4.1.3 for Node.js could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the…
ModificadaMedia (4.3)42%—Smartbear Swagger UI11/3/202217/6/2026
Swagger UI 4.1.2 and earlier could allow a remote attacker to conduct spoofing attacks. By persuading a victim to open a crafted URL, an attacker could exploit this vulnerability to display remote OpenAPI definitions. Note: This was originally claimed to be resolved in 4.1.3. However, third parties have indicated this…
ModificadaMedia (6.1)4.0%—Smartbear Swagger-uiRedhat Jboss FuseRedhat Openshift20/12/201917/6/2026
swagger-ui has XSS in key names
ModificadaCrítica (9.8)5.7%—Smartbear Swagger UIOracle Banking ApisOracle Banking Digital ExperienceOracle Banking Platform+210/10/201917/6/2026
A Cascading Style Sheets (CSS) injection vulnerability in Swagger UI before 3.23.11 allows attackers to use the Relative Path Overwrite (RPO) technique to perform CSS-based input field value exfiltration, such as exfiltration of a CSRF token value. In other words, this product intentionally allows the embedding of…
ModificadaMedia (6.1)1.0%—Smartbear Swagger-ui10/4/201717/6/2026
Swagger-UI before 2.2.1 has XSS via the Default field in the Definitions section.