Export CSV

Products

1 vendor
VendorProductsCVEsKEVAvg EPSSWorst Severity
35039.2%HIGH

Related CVEs

5
CVE IDDescriptionSeverityCVSSKEVEPSSPublished
CVE-2025-29157An issue in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via accessing a non-existent endpoint/cart, the server returns a 404-error page exposing sensitive information including the Servlet name (default) and server versionMEDIUM6.538.7%Sep 25, 2025
CVE-2025-29156Cross Site Scripting vulnerability in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via a crafted script to the /api/v3/petMEDIUM6.126.9%Sep 25, 2025
CVE-2025-29155An issue in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via the DELETE endpointMEDIUM6.532.0%Sep 25, 2025
CVE-2024-7565SMARTBEAR SoapUI unpackageAll Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of SMARTBEAR SoapUI. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the unpackageAll function. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-19060.HIGH7.859.3%Nov 22, 2024
CVE-2024-22207fastify-swagger-ui is a Fastify plugin for serving Swagger UI. Prior to 2.1.0, the default configuration of `@fastify/swagger-ui` without `baseDir` set will lead to all files in the module's directory being exposed via http routes served by the module. The vulnerability is fixed in v2.1.0. Setting the `baseDir` option can also work around this vulnerability.MEDIUM5.3Jan 15, 2024