Synopsys kayıtları
synopsys üreticisine ait 7 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %14,3
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-295 Improper Certificate Validation1
- CWE-321 Use of Hard-coded Cryptographic Key1
- CWE-425 Direct Request ('Forced Browsing')1
- CWE-522 Insufficiently Protected Credentials1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
7 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2023-2158İstismar yok | Impersonation through User-Controlled Tokensynopsys · code dx · CWE-321 | Kritik9,8 | — | %0,6 | 27 Nis 2023 |
32İzleyin | CVE-2019-3800İstismar yok | CF CLI writes the client id and secret to config filepivotal · cloud foundry command line interface · CWE-522 | Yüksek7,8 | — | %2,1 | 5 Ağu 2019 |
30İzleyin | CVE-2020-27589İstismar yok | Synopsys hub-rest-api-python (aka blackduck on PyPI) version 0.0.25 - 0.0.52 does not validate SSL certificates in certain cases.synopsys · hub-rest-api-python · CWE-295 | Yüksek7,5 | — | %1,1 | 6 Kas 2020 |
24İzleyin | CVE-2023-23849İstismar yok | Versions of Coverity Connect prior to 2022.12.0 are vulnerable to an unauthenticated Cross-Site Scripting vulnerability.synopsys · coverity · CWE-79 | Orta6,1 | — | %1,3 | 6 Şub 2023 |
24İzleyin | CVE-2022-30278İstismar yok | A vulnerability in Black Duck Hub’s embedded MadCap Flare documentation files could allow an unauthenticated remote attacker to conduct a crsynopsys · black duck hub · CWE-79 | Orta6,1 | — | %0,8 | 10 May 2022 |
21İzleyin | CVE-2023-1663İstismar yok | Authenticated Resources Accessible via Forced Browsingsynopsys · coverity · CWE-425 | Orta5,3 | — | %0,4 | 29 Mar 2023 |
21İzleyin | CVE-2024-0226İstismar yok | Stored Cross-Site Scripting in Synopsys Seekersynopsys · seeker · CWE-79 | Orta5,4 | — | %0,3 | 9 Oca 2024 |
- CVE-2023-215839İzleyin
Impersonation through User-Controlled Token
KritikCVSS 9,8İstismar yokEPSS %1synopsys · code dx27 Nis 2023
- CVE-2019-380032İzleyin
CF CLI writes the client id and secret to config file
YüksekCVSS 7,8İstismar yokEPSS %2pivotal · cloud foundry command line interface5 Ağu 2019
- CVE-2020-2758930İzleyin
Synopsys hub-rest-api-python (aka blackduck on PyPI) version 0.0.25 - 0.0.52 does not validate SSL certificates in certain cases.
YüksekCVSS 7,5İstismar yokEPSS %1synopsys · hub-rest-api-python6 Kas 2020
- CVE-2023-2384924İzleyin
Versions of Coverity Connect prior to 2022.12.0 are vulnerable to an unauthenticated Cross-Site Scripting vulnerability.
OrtaCVSS 6,1İstismar yokEPSS %1synopsys · coverity6 Şub 2023
- CVE-2022-3027824İzleyin
A vulnerability in Black Duck Hub’s embedded MadCap Flare documentation files could allow an unauthenticated remote attacker to conduct a cr
OrtaCVSS 6,1İstismar yokEPSS %1synopsys · black duck hub10 May 2022
- CVE-2023-166321İzleyin
Authenticated Resources Accessible via Forced Browsing
OrtaCVSS 5,3İstismar yokEPSS %0synopsys · coverity29 Mar 2023
- CVE-2024-022621İzleyin
Stored Cross-Site Scripting in Synopsys Seeker
OrtaCVSS 5,4İstismar yokEPSS %0synopsys · seeker9 Oca 2024