Snyk
First CVE: Jul 25, 2018Active for: 8 years
866
CVEs Published
More CVEs Published than 90% of tracked CNAs
96.2
Avg CVEs / Year
More Avg CVEs / Year than 90% of tracked CNAs
8.0
Avg CVSS Score
Higher Avg CVSS Score than 86% of tracked CNAs
0.1%
In CISA KEV
Higher KEV Rate than 79% of tracked CNAs
Self-Reporting Analysis
Of all the CVEs published by Snyk as a CNA, 0.9% affect products that Snyk develops as a vendor.
99.1%
Self-reported: 8Third-party: 858
Of all the CVEs published that affect products developed by Snyk, 80.0% are self-published by Snyk as a CNA.
80.0%
20.0%
Self-published: 8Published by other CNAs: 2
Trends Over Time
The number and severity of CVEs published by Snyk over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 25, 2018
7 years ago
Most Recent CVE
Jul 21, 2026
3 days ago
Top CVEs
All CVEs published by Snyk as a CNA, regardless of affected vendor or product.
866 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-10758CRITICAL mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the `toBSON` method. A misuse of the `vm` dependency to perform `exec` commands in a non- | Dec 24, 2019 | 9.9 | 97 | YES | YES |
CVE-2021-23758CRITICAL All versions of package ajaxpro.2 are vulnerable to Deserialization of Untrusted Data due to the possibility of deserialization of arbitrary .NET classes, which can be abused to ga | Dec 3, 2021 | 9.8 | 86 | NO | YES |
CVE-2020-28429CRITICAL All versions of package geojson2kml are vulnerable to Command Injection via the index.js file. PoC: var a =require("geojson2kml"); a("./","& touch JHU",function(){}) | Feb 23, 2021 | 9.8 | 74 | NO | YES |
CVE-2020-7774CRITICAL The package y18n before 3.2.2, 4.0.1 and 5.0.5, is vulnerable to Prototype Pollution. | Nov 17, 2020 | 9.8 | 70 | NO | NO |
CVE-2022-25765CRITICAL The package pdfkit from 0.0.0 are vulnerable to Command Injection where the URL is not properly sanitized. | Sep 9, 2022 | 9.8 | 52 | NO | NO |
CVE-2021-23450CRITICAL All versions of package dojo are vulnerable to Prototype Pollution via the setObject function. | Dec 17, 2021 | 9.8 | 51 | NO | NO |
CVE-2021-23394CRITICAL The package studio-42/elfinder before 2.1.58 are vulnerable to Remote Code Execution (RCE) via execution of PHP code in a .phar file. NOTE: This only applies if the server parses . | Jun 13, 2021 | 9.8 | 51 | NO | YES |
CVE-2021-23337HIGH Lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function. | Feb 15, 2021 | 7.2 | 49 | NO | YES |
CVE-2025-1302CRITICAL Versions of the package jsonpath-plus before 10.3.0 are vulnerable to Remote Code Execution (RCE) due to improper input sanitization. An attacker can execute aribitrary code on the | Feb 15, 2025 | 9.8 | 47 | NO | YES |
CVE-2025-1025HIGH Versions of the package cockpit-hq/cockpit before 2.4.1 are vulnerable to Arbitrary File Upload where an attacker can use different extension to bypass the upload filter. | Feb 5, 2025 | 7.5 | 47 | NO | YES |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA866 CVEs
26%
36%
38%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local47 (5.4%)
Network818 (94.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (0.1%)
Attack Complexity
Low824 (95.2%)
High42 (4.8%)
Unknown0 (0.0%)
User Interaction
None715 (82.6%)
Unknown0 (0.0%)
Required151 (17.4%)
Privileges Required
Low96 (11.1%)
High20 (2.3%)
None750 (86.6%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (866 CVEs).
CISA KEV
1 CVE
0.1% of CVEs· 79th percentile
Metasploit
1 CVE
0.1% of CVEs· 78th percentile
Nuclei
7 CVEs
0.8% of CVEs· 79th percentile
ExploitDB
3 CVEs
0.3% of CVEs· 75th percentile
Social Chatter
An overview of all social media posts that mention a CVE ID published by Snyk as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Snyk as a CNA — matched by CVE ID, not by organization name.