Synopsys, Inc.
First CVE: Jun 8, 2021Active for: 5 years
55
CVEs Published
More CVEs Published than 60% of tracked CNAs
9.2
Avg CVEs / Year
More Avg CVEs / Year than 50% of tracked CNAs
7.0
Avg CVSS Score
Higher Avg CVSS Score than 43% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Trends Over Time
The number and severity of CVEs published by Synopsys, Inc. over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 8, 2021
5 years ago
Most Recent CVE
Mar 27, 2026
119 days ago
Top CVEs
All CVEs published by Synopsys, Inc. as a CNA, regardless of affected vendor or product.
55 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-25826CRITICAL Due to insufficient validation of parameters passed to the legacy HTTP query API, it is possible to inject crafted OS commands into multiple parameters and execute malicious code o | May 3, 2023 | 9.8 | 54 | NO | YES |
CVE-2022-45481CRITICAL The default configuration of Lazy Mouse does not require a password, allowing remote unauthenticated users to execute arbitrary code with no prior authorization or authentication. | Dec 5, 2022 | 9.8 | 32 | NO | NO |
CVE-2022-45477CRITICAL Telepad allows remote unauthenticated users to send instructions to the server to execute arbitrary code without any previous authorization or authentication. CVSS:3.1/AV:N/AC:L/PR | Dec 5, 2022 | 9.8 | 32 | NO | NO |
CVE-2022-45479CRITICAL PC Keyboard allows remote unauthenticated users to send instructions to the server to execute arbitrary code without any previous authorization or authentication. CVSS:3.1/AV:N/AC: | Dec 5, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-45482CRITICAL Lazy Mouse server enforces weak password requirements and doesn't implement rate limiting, allowing remote unauthenticated users to easily and quickly brute force the PIN and execu | Dec 2, 2022 | 9.8 | 31 | NO | NO |
CVE-2021-33177HIGH The Bulk Modifications functionality in Nagios XI versions prior to 5.8.5 is vulnerable to SQL injection. Exploitation requires the malicious actor to be authenticated to the vulne | Oct 14, 2021 | 8.8 | 31 | NO | NO |
CVE-2026-1496CRITICAL Vulnerable versions of Coverity Connect lack an error handler in the authentication logic for command line tooling that makes it vulnerable to an authentication bypass. A malicious | Mar 27, 2026 | 9.3 | 29 | NO | NO |
CVE-2024-5184CRITICAL The EmailGPT service contains a prompt injection vulnerability. The service uses an API service that allows a malicious user to inject a direct prompt and take over the service log | Jun 5, 2024 | 9.1 | 29 | NO | NO |
CVE-2023-2453HIGH There is insufficient sanitization of tainted file names that are directly concatenated with a path that is subsequently passed to a ‘require_once’ statement. This allows arbitrary | Sep 5, 2023 | 8.8 | 28 | NO | NO |
CVE-2022-43945HIGH The Linux kernel NFSD implementation prior to versions 5.19.17 and 6.0.2 are vulnerable to buffer overflow. NFSD tracks the number of pages held by each NFSD thread by combining th | Nov 4, 2022 | 7.5 | 28 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA55 CVEs
40%
42%
15%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network52 (94.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network3 (5.5%)
Attack Complexity
Low49 (89.1%)
High6 (10.9%)
Unknown0 (0.0%)
User Interaction
None46 (83.6%)
Unknown0 (0.0%)
Required9 (16.4%)
Privileges Required
Low21 (38.2%)
High5 (9.1%)
None29 (52.7%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (55 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
1.8% of CVEs· 91st percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by Synopsys, Inc. as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Synopsys, Inc. as a CNA — matched by CVE ID, not by organization name.