Snyk

First CVE: Jul 25, 2018Active for: 8 years
866
CVEs Published
More CVEs Published than 90% of tracked CNAs
96.2
Avg CVEs / Year
More Avg CVEs / Year than 90% of tracked CNAs
8.0
Avg CVSS Score
Higher Avg CVSS Score than 86% of tracked CNAs
0.1%
In CISA KEV
Higher KEV Rate than 79% of tracked CNAs

Self-Reporting Analysis

Of all the CVEs published by Snyk as a CNA, 0.9% affect products that Snyk develops as a vendor.

99.1%
Self-reported: 8Third-party: 858

Of all the CVEs published that affect products developed by Snyk, 80.0% are self-published by Snyk as a CNA.

80.0%
20.0%
Self-published: 8Published by other CNAs: 2

Trends Over Time

The number and severity of CVEs published by Snyk over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 25, 2018
7 years ago
Most Recent CVE
Jul 21, 2026
3 days ago

Top CVEs

All CVEs published by Snyk as a CNA, regardless of affected vendor or product.

866 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the `toBSON` method. A misuse of the `vm` dependency to perform `exec` commands in a non-
Dec 24, 20199.997YESYES
All versions of package ajaxpro.2 are vulnerable to Deserialization of Untrusted Data due to the possibility of deserialization of arbitrary .NET classes, which can be abused to ga
Dec 3, 20219.886NOYES
All versions of package geojson2kml are vulnerable to Command Injection via the index.js file. PoC: var a =require("geojson2kml"); a("./","& touch JHU",function(){})
Feb 23, 20219.874NOYES
The package y18n before 3.2.2, 4.0.1 and 5.0.5, is vulnerable to Prototype Pollution.
Nov 17, 20209.870NONO
The package pdfkit from 0.0.0 are vulnerable to Command Injection where the URL is not properly sanitized.
Sep 9, 20229.852NONO
All versions of package dojo are vulnerable to Prototype Pollution via the setObject function.
Dec 17, 20219.851NONO
The package studio-42/elfinder before 2.1.58 are vulnerable to Remote Code Execution (RCE) via execution of PHP code in a .phar file. NOTE: This only applies if the server parses .
Jun 13, 20219.851NOYES
Lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function.
Feb 15, 20217.249NOYES
Versions of the package jsonpath-plus before 10.3.0 are vulnerable to Remote Code Execution (RCE) due to improper input sanitization. An attacker can execute aribitrary code on the
Feb 15, 20259.847NOYES
Versions of the package cockpit-hq/cockpit before 2.4.1 are vulnerable to Arbitrary File Upload where an attacker can use different extension to bypass the upload filter.
Feb 5, 20257.547NOYES

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA866 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local47 (5.4%)
Network818 (94.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (0.1%)
Attack Complexity
Low824 (95.2%)
High42 (4.8%)
Unknown0 (0.0%)
User Interaction
None715 (82.6%)
Unknown0 (0.0%)
Required151 (17.4%)
Privileges Required
Low96 (11.1%)
High20 (2.3%)
None750 (86.6%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (866 CVEs).

CISA KEV
1 CVE
0.1% of CVEs· 79th percentile
Metasploit
1 CVE
0.1% of CVEs· 78th percentile
Nuclei
7 CVEs
0.8% of CVEs· 79th percentile
ExploitDB
3 CVEs
0.3% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID published by Snyk as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Snyk as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs