VYPR
Vendor

Coverity

Products
1
CVEs
6
Across products
6
Status
Private

Products

1

Recent CVEs

6
  • CVE-2026-1496CriMar 27, 2026
    risk 0.60cvss epss 0.00

    Vulnerable versions of Coverity Connect lack an error handler in the authentication logic for command line tooling that makes it vulnerable to an authentication bypass. A malicious actor with access to the /token API endpoint that either knows or guesses a valid username, can…

  • CVE-2024-12021HigMar 31, 2025
    risk 0.55cvss epss 0.00

    Coverity versions prior to 2024.9.0 are vulnerable to stored cross-site scripting (XSS) in various administrative interfaces. The impact of exploitation may result in the compromise of local accounts managed by the Coverity platform as well as other standard impacts resulting…

  • CVE-2023-1663MedMar 29, 2023
    risk 0.42cvss 6.5epss 0.00

    Coverity versions prior to 2023.3.2 are vulnerable to forced browsing, which exposes authenticated resources to unauthorized actors. The root cause of this vulnerability is an insecurely configured servlet mapping for the underlying Apache Tomcat server. As a result, the…

  • CVE-2023-23849MedFeb 6, 2023
    risk 0.40cvss 6.1epss 0.01

    Versions of Coverity Connect prior to 2022.12.0 are vulnerable to an unauthenticated Cross-Site Scripting vulnerability. Any web service hosted on the same sub domain can set a cookie for the whole subdomain which can be used to bypass other mitigations in place for malicious…

  • CVE-2026-8339HigJul 29, 2026
    risk 0.00cvss epss 0.00

    A SQL injection vulnerability exists in the Coverity Connect SOAP API for versions between 2024.6.0 and 2026.3.0 (inclusive). A malicious, authenticated threat actor who sends a specially crafted payload can achieve full read access to database contents and other unauthorized…

  • CVE-2026-8338CriJul 29, 2026
    risk 0.00cvss epss 0.00

    A Spring Security authentication and authorization bypass exists in Coverity Connect versions between 2023.6.0 and 2026.3.0. An unauthenticated malicious threat actor that can send a specially crafted HTTP request is able to bypass authentication and authorization controls on…