Synopsys

    Dashboard / Vendors

    Products: 6
    Vulnerabilities: 7
    Known Exploited: 0
    1
    Critical Level Threats
    2
    High Level Threats
    4
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2024-0226

    Stored Cross-Site Scripting in Synopsys Seeker

    Last Modified: Nov 21, 2024
    Published: Jan 09, 2024

    CVE-2023-2158

    Impersonation through User-Controlled Token

    Last Modified: Jan 31, 2025
    Published: Apr 27, 2023

    CVE-2023-1663

    Authenticated Resources Accessible via Forced Browsing

    Last Modified: Feb 12, 2025
    Published: Mar 29, 2023

    CVE-2023-23849

    Versions of Coverity Connect prior to 2022.12.0 are vulnerable to an unauthenticated Cross-Site Scripting vulnerability. Any web service hosted on the same sub domain can set a cookie for the whole subdomain which can be used to bypass other mitigations in place for malicious purposes. CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/RL:O/RC:C

    Last Modified: Mar 25, 2025
    Published: Feb 06, 2023

    CVE-2022-30278

    A vulnerability in Black Duck Hub’s embedded MadCap Flare documentation files could allow an unauthenticated remote attacker to conduct a cross-site scripting attack. The vulnerability is due to improper validation of user-supplied input to MadCap Flare's framework embedded within Black Duck Hub's Help Documentation to supply content. An attacker could exploit this vulnerability by convincing a user to click a link designed to pass malicious input to the interface. A successful exploit could allow the attacker to conduct cross-site scripting attacks and gain access to sensitive browser-based information.

    Last Modified: Nov 21, 2024
    Published: May 10, 2022
    Items Per Page