Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2528▼ 418 respecto a la semana anterior
Críticas / altas1311▲ 21 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)99▼ 428 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.28% | — | Swagger UIAIWso2 API PublisherAI | 6/8/2026 | 29/9/2026 | The Swagger UI Try-out console within the API Publisher documentation allows an external Swagger API definition URL to be loaded, overriding the existing API definitions within the Publisher portal. By exploiting this vulnerability, malicious actors can deceive users into interacting with these overwritten API… | |
| Analizada | Media (5.4) | 0.22% | — | Vinayjain Embed Swagger UI | 30/1/2025 | 17/6/2026 | The Embed Swagger UI plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpsgui' shortcode in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Modificada | Media (5.3) | 2.3% | — | Smartbear Swagger UI | 15/1/2024 | 17/6/2026 | fastify-swagger-ui is a Fastify plugin for serving Swagger UI. Prior to 2.1.0, the default configuration of `@fastify/swagger-ui` without `baseDir` set will lead to all files in the module's directory being exposed via http routes served by the module. The vulnerability is fixed in v2.1.0. Setting the `baseDir` option… | |
| Modificada | Media (6.1) | 1.5% | — | Smartbear Swagger-ui-dist | 11/3/2022 | 17/6/2026 | The swagger-ui-dist package before 4.1.3 for Node.js could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the… | |
| Modificada | Media (4.3) | 42% | — | Smartbear Swagger UI | 11/3/2022 | 17/6/2026 | Swagger UI 4.1.2 and earlier could allow a remote attacker to conduct spoofing attacks. By persuading a victim to open a crafted URL, an attacker could exploit this vulnerability to display remote OpenAPI definitions. Note: This was originally claimed to be resolved in 4.1.3. However, third parties have indicated this… | |
| Modificada | Media (6.1) | 4.0% | — | Smartbear Swagger-uiRedhat Jboss FuseRedhat Openshift | 20/12/2019 | 17/6/2026 | swagger-ui has XSS in key names | |
| Modificada | Crítica (9.8) | 5.7% | — | Smartbear Swagger UIOracle Banking ApisOracle Banking Digital ExperienceOracle Banking Platform+2 | 10/10/2019 | 17/6/2026 | A Cascading Style Sheets (CSS) injection vulnerability in Swagger UI before 3.23.11 allows attackers to use the Relative Path Overwrite (RPO) technique to perform CSS-based input field value exfiltration, such as exfiltration of a CSRF token value. In other words, this product intentionally allows the embedding of… | |
| Modificada | Media (6.1) | 1.0% | — | Smartbear Swagger-ui | 10/4/2017 | 17/6/2026 | Swagger-UI before 2.2.1 has XSS via the Default field in the Definitions section. |