Synopsys records
7 published records for vendor synopsys.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 14.3%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-295 Improper Certificate Validation1
- CWE-321 Use of Hard-coded Cryptographic Key1
- CWE-425 Direct Request ('Forced Browsing')1
- CWE-522 Insufficiently Protected Credentials1
The weakness classes this vendor ships most often: where to look.
CWEAll records
7 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2023-2158No exploit | Impersonation through User-Controlled Tokensynopsys · code dx · CWE-321 | Critical9.8 | — | 0.6% | Apr 27, 2023 |
32Monitor | CVE-2019-3800No exploit | CF CLI writes the client id and secret to config filepivotal · cloud foundry command line interface · CWE-522 | High7.8 | — | 2.1% | Aug 5, 2019 |
30Monitor | CVE-2020-27589No exploit | Synopsys hub-rest-api-python (aka blackduck on PyPI) version 0.0.25 - 0.0.52 does not validate SSL certificates in certain cases.synopsys · hub-rest-api-python · CWE-295 | High7.5 | — | 1.1% | Nov 6, 2020 |
24Monitor | CVE-2023-23849No exploit | Versions of Coverity Connect prior to 2022.12.0 are vulnerable to an unauthenticated Cross-Site Scripting vulnerability.synopsys · coverity · CWE-79 | Medium6.1 | — | 1.3% | Feb 6, 2023 |
24Monitor | CVE-2022-30278No exploit | A vulnerability in Black Duck Hub’s embedded MadCap Flare documentation files could allow an unauthenticated remote attacker to conduct a crsynopsys · black duck hub · CWE-79 | Medium6.1 | — | 0.8% | May 10, 2022 |
21Monitor | CVE-2023-1663No exploit | Authenticated Resources Accessible via Forced Browsingsynopsys · coverity · CWE-425 | Medium5.3 | — | 0.4% | Mar 29, 2023 |
21Monitor | CVE-2024-0226No exploit | Stored Cross-Site Scripting in Synopsys Seekersynopsys · seeker · CWE-79 | Medium5.4 | — | 0.3% | Jan 9, 2024 |
- CVE-2023-215839Monitor
Impersonation through User-Controlled Token
CriticalCVSS 9.8No exploitEPSS 1%synopsys · code dxApr 27, 2023
- CVE-2019-380032Monitor
CF CLI writes the client id and secret to config file
HighCVSS 7.8No exploitEPSS 2%pivotal · cloud foundry command line interfaceAug 5, 2019
- CVE-2020-2758930Monitor
Synopsys hub-rest-api-python (aka blackduck on PyPI) version 0.0.25 - 0.0.52 does not validate SSL certificates in certain cases.
HighCVSS 7.5No exploitEPSS 1%synopsys · hub-rest-api-pythonNov 6, 2020
- CVE-2023-2384924Monitor
Versions of Coverity Connect prior to 2022.12.0 are vulnerable to an unauthenticated Cross-Site Scripting vulnerability.
MediumCVSS 6.1No exploitEPSS 1%synopsys · coverityFeb 6, 2023
- CVE-2022-3027824Monitor
A vulnerability in Black Duck Hub’s embedded MadCap Flare documentation files could allow an unauthenticated remote attacker to conduct a cr
MediumCVSS 6.1No exploitEPSS 1%synopsys · black duck hubMay 10, 2022
- CVE-2023-166321Monitor
Authenticated Resources Accessible via Forced Browsing
MediumCVSS 5.3No exploitEPSS 0%synopsys · coverityMar 29, 2023
- CVE-2024-022621Monitor
Stored Cross-Site Scripting in Synopsys Seeker
MediumCVSS 5.4No exploitEPSS 0%synopsys · seekerJan 9, 2024