CVE Tools

Sonarsource

3 CVEs tracked since 2013. Since Dec 2013, none of them reached CISA KEV.

Sonarsource CVEs per month

Dec 2013 to Oct 2020. Point at a month, or focus the strip and use the arrow keys.
Sonarsource CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2013-1210
2014-01null or fewer
2014-02null or fewer
2014-03null or fewer
2014-04null or fewer
2014-05null or fewer
2014-06null or fewer
2014-07null or fewer
2014-08null or fewer
2014-09null or fewer
2014-10null or fewer
2014-11null or fewer
2014-12null or fewer
2015-01null or fewer
2015-02null or fewer
2015-03null or fewer
2015-04null or fewer
2015-05null or fewer
2015-06null or fewer
2015-07null or fewer
2015-08null or fewer
2015-09null or fewer
2015-10null or fewer
2015-11null or fewer
2015-12null or fewer
2016-01null or fewer
2016-02null or fewer
2016-03null or fewer
2016-04null or fewer
2016-05null or fewer
2016-06null or fewer
2016-07null or fewer
2016-08null or fewer
2016-09null or fewer
2016-10null or fewer
2016-11null or fewer
2016-12null or fewer
2017-01null or fewer
2017-02null or fewer
2017-03null or fewer
2017-04null or fewer
2017-05null or fewer
2017-06null or fewer
2017-07null or fewer
2017-08null or fewer
2017-09null or fewer
2017-10null or fewer
2017-11null or fewer
2017-12null or fewer
2018-01null or fewer
2018-02null or fewer
2018-03null or fewer
2018-04null or fewer
2018-05null or fewer
2018-06null or fewer
2018-07null or fewer
2018-08null or fewer
2018-09null or fewer
2018-10null or fewer
2018-11null or fewer
2018-12null or fewer
2019-01null or fewer
2019-02null or fewer
2019-03null or fewer
2019-04null or fewer
2019-05null or fewer
2019-06null or fewer
2019-07null or fewer
2019-08null or fewer
2019-09null or fewer
2019-10null or fewer
2019-11null or fewer
2019-12null or fewer
2020-01null or fewer
2020-02null or fewer
2020-03null or fewer
2020-04null or fewer
2020-05null or fewer
2020-06null or fewer
2020-07null or fewer
2020-08null or fewer
2020-09null or fewer
2020-1020

Products

The products that kept showing up in Sonarsource's monthly top three, with their CVEs summed over those months.

  1. Sonarqube21 month
  2. Jenkins Plugin11 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Sonarsource.

  1. CVE-2025-62292In SonarQube before 25.6, 2025.3 Commercial, and 2025.1.3 LTA, authenticated low-privileged users can query the /api/v2/users-management/users endpoint and obtain user fields intended for administr...4.3
  2. CVE-2025-59844Argument injection vulnerability in SonarQube Scan Action—
  3. CVE-2025-58178Command Injection via sonarqube-scan-action GitHub Action7.8
  4. CVE-2024-47911In SonarSource SonarQube 10.4 through 10.5 before 10.6, a vulnerability was discovered in the authorizations/group-memberships API endpoint that allows SonarQube users with the administrator role t...6.7
  5. CVE-2024-38460In SonarQube before 10.4 and 9.9.4 LTA, encrypted values generated using the Settings Encryption feature are potentially exposed in cleartext as part of the URL parameters in the logs (such as Sona...4.9
  6. CVE-2023-33265In Hazelcast through 5.0.4, 5.1 through 5.1.6, and 5.2 through 5.2.3, executor services don't check client permissions properly, allowing authenticated users to execute tasks on members without the...8.8
  7. CVE-2023-33264In Hazelcast through 5.0.4, 5.1 through 5.1.6, and 5.2 through 5.2.3, configuration routines don't mask passwords in the member configuration properly. This allows Hazelcast Management Center users...4.3
  8. CVE-2022-45868The web-based admin console in H2 Database Engine before 2.2.220 can be started via the CLI with the argument -webAdminPassword, which allows the user to specify the password in cleartext for the w...8.4
  9. CVE-2022-45047Apache MINA SSHD: Java unsafe deserialization vulnerability9.8
  10. CVE-2022-40152Stack Buffer Overflow in Woodstox6.5
  11. CVE-2022-24823Local Information Disclosure Vulnerability in io.netty:netty-codec-http5.5
  12. CVE-2021-43797HTTP fails to validate against control chars in header names which may lead to HTTP request smuggling6.5
  13. CVE-2021-37137The Snappy frame decoder function doesn't restrict the chunk length which may lead to excessive memory usage. Beside this it also may buffer reserved skippable chunks until the whole chunk was rece...7.5
  14. CVE-2020-28491Denial of Service (DoS)7.5
  15. CVE-2020-35193The official sonarqube docker images before alpine (Alpine specific) contain a blank password for a root user. System using the sonarqube docker container deployed by affected versions of the docke...9.8

The record

Peak rank
#145 in Dec 2013
Busiest month shown
Oct 2020, 2 CVEs
Months with a KEV entry
0 since Dec 2013
Monthly snapshots
2 since 2013
Sonarsource's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store