Skip to main content
0-Doubt
NewsInvestorsQuestionnairesDeveloperHelp
AnonymousSign in
0-Doubt — neutral IT/Security research
BrowseResellersCertified analystsRFI/RFP questionnairesHow trust worksHelp & FAQAPI
  1. Home/
  2. Checkmarx/
  3. Checkmarx Secrets Detection

Checkmarx Secrets Detection

AI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Secure coding rating: 0/100How this score is computedA product with no known CVEs starts at a neutral score and climbs the longer it goes without one; a product with known CVEs is penalized by severity instead. This one has 6 known CVEs (vendor-level match — see the CVE list below) and is tracked as ~39 days old in our catalog (a stand-in for real release date, which we don't track). The platform admin controls the formula's weights.

Detects hardcoded secrets in code repos, commits, and containers

by Checkmarx · checkmarx.com · source ↗

Known CVEs (6)About this listSourced from the public NVD database, matched by vendor name. Shown here at the vendor level — we don't track per-product/version data, so a listed CVE may affect a different product from this vendor, not necessarily this one. “New” means published within the last 30 days. “Actively exploited” means CISA's Known Exploited Vulnerabilities (KEV) catalog confirms real-world exploitation, not just a theoretical severity score.

RSS ⇢
  • CVE-2026-42994 ↗CRITICAL 9.82026

    Bitwarden CLI 2026.4.0 from 2026-04-22T21:57Z to 2026-04-22T23:30Z, when obtained from npm, had embedded malicious code. This is related to a Checkmarx supply chain incident.

  • CVE-2023-35142 ↗HIGH 8.12023

    Jenkins Checkmarx Plugin 2022.4.3 and earlier disables SSL/TLS validation for connections to the Checkmarx server by default.

  • CVE-2022-46684 ↗MEDIUM 5.42022

    Jenkins Checkmarx Plugin 2022.3.3 and earlier does not escape values returned from the Checkmarx service API before inserting them into HTML reports, resulting in a stored cross-site scripting (XSS) v…

  • CVE-2022-25201 ↗MEDIUM 6.52022

    Missing permission checks in Jenkins Checkmarx Plugin 2022.1.2 and earlier allow attackers with Overall/Read permission to connect to an attacker-specified webserver using attacker-specified credentia…

  • CVE-2022-25200 ↗HIGH 8.82022

    A cross-site request forgery (CSRF) vulnerability in Jenkins Checkmarx Plugin 2022.1.2 and earlier allows attackers to connect to an attacker-specified webserver using attacker-specified credentials I…

  • CVE-2014-8778 ↗HIGH 9.02015

    Checkmarx CxSAST (formerly CxSuite) before 7.1.8 allows remote authenticated users to bypass the CxQL sandbox protection mechanism and execute arbitrary C# code by asserting the (1) System.Security.Pe…

Materials

0

No datasheets, whitepapers, case studies, videos, or demos linked yet.

Other Secrets Detection products

see all →
  • Apiiro Secrets Security · Apiiro
  • BitPatrol · BitPatrol
  • Corgea Secret Scanning · Corgea
  • Cycode Secrets Detection and Scanning · Cycode
  • Datadog Code Security Secret Scanning · Datadog
  • Detectors · Truffle Security
  • GitGuardian Non-Human Identity security · GitGuardian
  • Infisical Radar · Infisical