Checkmarx

First CVE: May 14, 2024Active for: 2 years
13
CVEs Published
More CVEs Published than 31% of tracked CNAs
4.3
Avg CVEs / Year
More Avg CVEs / Year than 29% of tracked CNAs
6.5
Avg CVSS Score
Higher Avg CVSS Score than 25% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by Checkmarx as a CNA, 0.0% affect products that Checkmarx develops as a vendor.

100.0%
Self-reported: 0Third-party: 13

Of all the CVEs published that affect products developed by Checkmarx, 0.0% are self-published by Checkmarx as a CNA.

100.0%
Self-published: 0Published by other CNAs: 1

Trends Over Time

The number and severity of CVEs published by Checkmarx over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 14, 2024
2 years ago
Most Recent CVE
Jun 17, 2026
37 days ago

Top CVEs

All CVEs published by Checkmarx as a CNA, regardless of affected vendor or product.

13 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The mikecao/flight PHP framework in versions prior to v1.2 is vulnerable to Denial of Service (DoS) attacks due to eager loading of request bodies in the Request class constructor.
Sep 3, 20257.525NONO
The NPM package `braces`, versions prior to 3.0.3, fails to limit the number of characters it can handle, which could lead to Memory Exhaustion. In `lib/parse.js,` if a malicious u
May 14, 20247.525NONO
Cross-site request forgery (CSRF) in NewsItemApiController in SimplCommerce prior to commit 6233d73e allows an unauthenticated remote attacker to create or modify news items as an
Jun 17, 20266.924NONO
Stored cross-site scripting (XSS) in NewsItemApiController In SimplCommerce prior to commit 6142d3b5 allows an authenticated administrator to execute arbitrary JavaScript via the S
Jun 17, 20266.224NONO
UltiMaker Cura slicer versions 5.7.0-beta.1 through 5.7.2 are vulnerable to code injection via the 3MF format reader (/plugins/ThreeMFReader.py). The vulnerability arises from impr
Sep 3, 20247.824NONO
Users with "User:edit" and "Self:api" permissions can promote or demote themselves or other users by performing changes to the group's memberships via API call.This issue affects s
Jun 14, 20248.123NONO
`sanitize-html` prior to version 2.0.0-beta is vulnerable to Cross-site Scripting (XSS). The `sanitizeHtml()` function in `index.js` does not sanitize content when using the custom
Sep 8, 20256.122NONO
'sanitize-html' prior to version 1.0.3 is vulnerable to Cross-site Scripting (XSS). The function 'naughtyHref' doesn't properly validate the hyperreference (`href`) attribute in an
Sep 8, 20256.121NONO
ThingsBoard in versions prior to v4.2.1 allows an authenticated user to upload malicious SVG images via the "Image Gallery", leading to a Stored Cross-Site Scripting (XSS) vulnerab
Oct 17, 20255.420NONO
Marked prior to version 0.3.17 is vulnerable to a Regular Expression Denial of Service (ReDoS) attack due to catastrophic backtracking in several regular expressions used for parsi
May 23, 20257.520NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA13 CVEs
Severity distribution among all CVEs352,294 CVEs
MediumHigh
Attack Vector
Local1 (7.7%)
Network12 (92.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low13 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None6 (46.2%)
Unknown0 (0.0%)
Required5 (38.5%)
Privileges Required
Low2 (15.4%)
High2 (15.4%)
None9 (69.2%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (13 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by Checkmarx as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Checkmarx as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs