Synopsys, Inc.

First CVE: Jun 8, 2021Active for: 5 years
55
CVEs Published
More CVEs Published than 60% of tracked CNAs
9.2
Avg CVEs / Year
More Avg CVEs / Year than 50% of tracked CNAs
7.0
Avg CVSS Score
Higher Avg CVSS Score than 43% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published by Synopsys, Inc. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 8, 2021
5 years ago
Most Recent CVE
Mar 27, 2026
119 days ago

Top CVEs

All CVEs published by Synopsys, Inc. as a CNA, regardless of affected vendor or product.

55 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Due to insufficient validation of parameters passed to the legacy HTTP query API, it is possible to inject crafted OS commands into multiple parameters and execute malicious code o
May 3, 20239.854NOYES
The default configuration of Lazy Mouse does not require a password, allowing remote unauthenticated users to execute arbitrary code with no prior authorization or authentication.
Dec 5, 20229.832NONO
Telepad allows remote unauthenticated users to send instructions to the server to execute arbitrary code without any previous authorization or authentication. CVSS:3.1/AV:N/AC:L/PR
Dec 5, 20229.832NONO
PC Keyboard allows remote unauthenticated users to send instructions to the server to execute arbitrary code without any previous authorization or authentication. CVSS:3.1/AV:N/AC:
Dec 5, 20229.831NONO
Lazy Mouse server enforces weak password requirements and doesn't implement rate limiting, allowing remote unauthenticated users to easily and quickly brute force the PIN and execu
Dec 2, 20229.831NONO
The Bulk Modifications functionality in Nagios XI versions prior to 5.8.5 is vulnerable to SQL injection. Exploitation requires the malicious actor to be authenticated to the vulne
Oct 14, 20218.831NONO
Vulnerable versions of Coverity Connect lack an error handler in the authentication logic for command line tooling that makes it vulnerable to an authentication bypass. A malicious
Mar 27, 20269.329NONO
The EmailGPT service contains a prompt injection vulnerability. The service uses an API service that allows a malicious user to inject a direct prompt and take over the service log
Jun 5, 20249.129NONO
There is insufficient sanitization of tainted file names that are directly concatenated with a path that is subsequently passed to a ‘require_once’ statement. This allows arbitrary
Sep 5, 20238.828NONO
The Linux kernel NFSD implementation prior to versions 5.19.17 and 6.0.2 are vulnerable to buffer overflow. NFSD tracks the number of pages held by each NFSD thread by combining th
Nov 4, 20227.528NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA55 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network52 (94.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network3 (5.5%)
Attack Complexity
Low49 (89.1%)
High6 (10.9%)
Unknown0 (0.0%)
User Interaction
None46 (83.6%)
Unknown0 (0.0%)
Required9 (16.4%)
Privileges Required
Low21 (38.2%)
High5 (9.1%)
None29 (52.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (55 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
1.8% of CVEs· 91st percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by Synopsys, Inc. as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Synopsys, Inc. as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs