CVE Tools

Snyk

6 CVEs tracked since 2020. Since Feb 2020, none of them reached CISA KEV.

Snyk CVEs per month

Feb 2020 to Feb 2020. Point at a month, or focus the strip and use the arrow keys.
Snyk CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2020-0260

Products

The products that kept showing up in Snyk's monthly top three, with their CVEs summed over those months.

  1. Bodymen11 month
  2. Component-flatten11 month
  3. Dot-object11 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Snyk.

  1. CVE-2026-75486Synk Sweater Comb < 3.8.8 Command Injection via .vervet.yaml Branch Name8.0
  2. CVE-2025-6624Versions of the package snyk before 1.1297.3 are vulnerable to Insertion of Sensitive Information into Log File through local Snyk CLI debug logs. Container Registry credentials provided via enviro...7.2
  3. CVE-2024-21571Snyk has identified a remote code execution (RCE) vulnerability in all versions of Code Agent. The vulnerability enables an attacker to execute arbitrary code within the Code Agent container. Explo...8.1
  4. CVE-2024-48963The package Snyk CLI before 1.1294.0 is vulnerable to Code Injection when scanning an untrusted PHP project. The vulnerability can be triggered if Snyk test is run inside the untrusted project due ...7.5
  5. CVE-2024-48964The package Snyk CLI before 1.1294.0 is vulnerable to Code Injection when scanning an untrusted Gradle project. The vulnerability can be triggered if Snyk test is run inside the untrusted project d...7.5
  6. CVE-2023-1767The Snyk Advisor website (https://snyk.io/advisor/) was vulnerable to a stored XSS prior to 28th March 2023. A feature of Snyk Advisor is to display the contents of a scanned package's Readme on it...4.3
  7. CVE-2023-1065This vulnerability in the Snyk Kubernetes Monitor can result in irrelevant data being posted to a Snyk Organization, which could in turn obfuscate other, relevant, security issues. It does not expo...6.5
  8. CVE-2022-24441Code Injection5.8
  9. CVE-2022-22984Command Injection5.0
  10. CVE-2022-40764Snyk CLI before 1.996.0 allows arbitrary command execution, affecting Snyk IDE plugins and the snyk npm package. Exploitation could follow from the common practice of viewing untrusted files in the...7.8
  11. CVE-2020-7649Directory Traversal4.9
  12. CVE-2019-10797Netty in WSO2 transport-http before v6.3.1 is vulnerable to HTTP Response Splitting due to HTTP Header validation being disabled.6.5
  13. CVE-2019-10791promise-probe before 0.10.0 allows remote attackers to perform a command injection attack. The file, outputFile and options functions can be controlled by users without any sanitization.9.8
  14. CVE-2019-10793dot-object before 2.1.3 is vulnerable to Prototype Pollution. The set function could be tricked into adding or modifying properties of Object.prototype using a __proto__ payload.6.3
  15. CVE-2019-10792bodymen before 1.1.1 is vulnerable to Prototype Pollution. The handler function could be tricked into adding or modifying properties of Object.prototype using a __proto__ payload.6.3

The record

Peak rank
#65 in Feb 2020
Busiest month shown
Feb 2020, 6 CVEs
Months with a KEV entry
0 since Feb 2020
Monthly snapshots
1 since 2020
Snyk's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store