Checkmarx develops static application security testing (SAST) tools centered around its CxSAST code analysis platform, which is embedded in developer workflows and CI/CD pipelines to identify vulnerabilities before deployment. Vulnerabilities in this vendor's own products have centered on code injection flaws, reflecting the complexity of parsing and analyzing diverse code structures within a security-focused analysis engine. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Checkmarx over time
Of all the CVEs published by Checkmarx as a CNA, 0.0% affect products that Checkmarx develops as a vendor.
Of all the CVEs published that affect products developed by Checkmarx, 0.0% are self-published by Checkmarx as a CNA.
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-8778HIGH Checkmarx CxSAST (formerly CxSuite) before 7.1.8 allows remote authenticated users to bypass the CxQL sandbox protection mechanism and execute arbitrary C# code by asserting the (1 | Sep 16, 2015 | 9.0 | 30 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Checkmarx.
Media articles that mention a CVE ID that affects a product developed by Checkmarx — matched by CVE ID, not by vendor name.