Synopsys develops a specialized portfolio of software-assurance and supply-chain security tools—including Coverity, Black Duck Hub, and Code Dx—that are embedded in development pipelines and governance workflows across enterprises. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, and recur through weakness classes centered on web-application input handling (cross-site scripting, forced browsing), credential exposure, and certificate validation that reflect the authentication and data-protection demands of these management platforms. Defenders should prioritize patching these development-tier tools, since compromise of a security scanner or supply-chain gateway can undermine downstream trust; current severity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Synopsys, Inc. over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-3800HIGH CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when the user authenticates with --client-credentials flag. A local | Aug 5, 2019 | 7.8 | 26 | NO | NO |
CVE-2020-27589HIGH Synopsys hub-rest-api-python (aka blackduck on PyPI) version 0.0.25 - 0.0.52 does not validate SSL certificates in certain cases. | Nov 6, 2020 | 7.5 | 25 | NO | NO |
CVE-2023-2158CRITICAL Code Dx versions prior to 2023.4.2 are vulnerable to user impersonation attack where a malicious actor is able to gain access to another user's account by crafting a custom "Rememb | Apr 27, 2023 | 9.8 | 24 | NO | NO |
CVE-2023-23849MEDIUM Versions of Coverity Connect prior to 2022.12.0 are vulnerable to an unauthenticated Cross-Site Scripting vulnerability. Any web service hosted on the same sub domain can set a coo | Feb 6, 2023 | 6.1 | 21 | NO | NO |
CVE-2022-30278MEDIUM A vulnerability in Black Duck Hub’s embedded MadCap Flare documentation files could allow an unauthenticated remote attacker to conduct a cross-site scripting attack. The vulnerabi | May 10, 2022 | 6.1 | 21 | NO | NO |
CVE-2023-1663MEDIUM Coverity versions prior to 2023.3.2 are vulnerable to forced browsing, which exposes authenticated resources to unauthorized actors. The root cause of this vulnerability is an inse | Mar 29, 2023 | 5.3 | 19 | NO | NO |
CVE-2024-0226MEDIUM Synopsys Seeker versions prior to 2023.12.0 are vulnerable to a stored cross-site scripting vulnerability through a specially crafted payload. | Jan 9, 2024 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Synopsys, Inc..
Media articles that mention a CVE ID that affects a product developed by Synopsys, Inc. — matched by CVE ID, not by vendor name.