Checkmarx
First CVE: May 14, 2024Active for: 2 years
13
CVEs Published
More CVEs Published than 31% of tracked CNAs
4.3
Avg CVEs / Year
More Avg CVEs / Year than 29% of tracked CNAs
6.5
Avg CVSS Score
Higher Avg CVSS Score than 25% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Self-Reporting Analysis
Of all the CVEs published by Checkmarx as a CNA, 0.0% affect products that Checkmarx develops as a vendor.
100.0%
Self-reported: 0Third-party: 13
Of all the CVEs published that affect products developed by Checkmarx, 0.0% are self-published by Checkmarx as a CNA.
100.0%
Self-published: 0Published by other CNAs: 1
Trends Over Time
The number and severity of CVEs published by Checkmarx over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 14, 2024
2 years ago
Most Recent CVE
Jun 17, 2026
37 days ago
Top CVEs
All CVEs published by Checkmarx as a CNA, regardless of affected vendor or product.
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-125127HIGH The mikecao/flight PHP framework in versions prior to v1.2 is vulnerable to Denial of Service (DoS) attacks due to eager loading of request bodies in the Request class constructor. | Sep 3, 2025 | 7.5 | 25 | NO | NO |
CVE-2024-4068HIGH The NPM package `braces`, versions prior to 3.0.3, fails to limit the number of characters it can handle, which could lead to Memory Exhaustion. In `lib/parse.js,` if a malicious u | May 14, 2024 | 7.5 | 25 | NO | NO |
CVE-2026-9591MEDIUM Cross-site request forgery (CSRF) in NewsItemApiController in SimplCommerce prior to commit 6233d73e allows an unauthenticated remote attacker to create or modify news items as an | Jun 17, 2026 | 6.9 | 24 | NO | NO |
CVE-2026-11975MEDIUM Stored cross-site scripting (XSS) in NewsItemApiController In SimplCommerce prior to commit 6142d3b5 allows an authenticated administrator to execute arbitrary JavaScript via the S | Jun 17, 2026 | 6.2 | 24 | NO | NO |
CVE-2024-8374HIGH UltiMaker Cura slicer versions 5.7.0-beta.1 through 5.7.2 are vulnerable to code injection via the 3MF format reader (/plugins/ThreeMFReader.py). The vulnerability arises from impr | Sep 3, 2024 | 7.8 | 24 | NO | NO |
CVE-2024-5685HIGH Users with "User:edit" and "Self:api" permissions can promote or demote themselves or other users by performing changes to the group's memberships via API call.This issue affects s | Jun 14, 2024 | 8.1 | 23 | NO | NO |
CVE-2019-25225MEDIUM `sanitize-html` prior to version 2.0.0-beta is vulnerable to Cross-site Scripting (XSS). The `sanitizeHtml()` function in `index.js` does not sanitize content when using the custom | Sep 8, 2025 | 6.1 | 22 | NO | NO |
CVE-2014-125128MEDIUM 'sanitize-html' prior to version 1.0.3 is vulnerable to Cross-site Scripting (XSS). The function 'naughtyHref' doesn't properly validate the hyperreference (`href`) attribute in an | Sep 8, 2025 | 6.1 | 21 | NO | NO |
CVE-2025-34281MEDIUM ThingsBoard in versions prior to v4.2.1 allows an authenticated user to upload malicious SVG images via the "Image Gallery", leading to a Stored Cross-Site Scripting (XSS) vulnerab | Oct 17, 2025 | 5.4 | 20 | NO | NO |
CVE-2018-25110HIGH Marked prior to version 0.3.17 is vulnerable to a Regular Expression Denial of Service (ReDoS) attack due to catastrophic backtracking in several regular expressions used for parsi | May 23, 2025 | 7.5 | 20 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA13 CVEs
62%
38%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local1 (7.7%)
Network12 (92.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low13 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None6 (46.2%)
Unknown0 (0.0%)
Required5 (38.5%)
Privileges Required
Low2 (15.4%)
High2 (15.4%)
None9 (69.2%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (13 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by Checkmarx as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Checkmarx as a CNA — matched by CVE ID, not by organization name.