Snowflake records
38 published records for vendor snowflake.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 7
- With a fix record
- 89.5%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')5
- CWE-532 Insertion of Sensitive Information into Log File4
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')4
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-276 Incorrect Default Permissions3
- CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition3
The weakness classes this vendor ships most often: where to look.
CWEAll records
38 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
38Monitor | CVE-2026-13751No exploit | Snowflake CLI Server-Side Request Forgery via Arbitrary URL Fetch in !source/!loadsnowflake · snowflake cli · CWE-829 | Critical9.6 | — | 0.2% | Jun 29, 2026 |
36Monitor | CVE-2023-34231No exploit | Snowflake Golang Driver vulnerable to Command Injectionsnowflake · gosnowflake · CWE-77 | High8.8 | — | 2.0% | Jun 8, 2023 |
36Monitor | CVE-2023-34232No exploit | Snowflake NodeJS Driver vulnerable to Command Injectionsnowflake · snowflake connector · CWE-77 | High8.8 | — | 1.9% | Jun 8, 2023 |
36Monitor | CVE-2023-34233Proof of concept | Snowflake Python Connector vulnerable to Command Injectionsnowflake · snowflake connector · CWE-77 | High8.8 | — | 1.8% | Jun 8, 2023 |
36Monitor | CVE-2023-30535No exploit | Snowflake JDBC vulnerable to command injection via SSO URL authenticationsnowflake · snowflake jdbc · CWE-20 | High8.8 | — | 1.7% | Apr 14, 2023 |
35Monitor | CVE-2023-34230No exploit | Snowflake Connector vulnerable to Command Injectionsnowflake · snowflake connector · CWE-77 | High8.8 | — | 1.4% | Jun 8, 2023 |
35Monitor | CVE-2026-13749No exploit | Snowflake CLI Arbitrary Code Execution via Snowpark Annotation Processor Template Injectionsnowflake · snowflake cli · CWE-94 | High8.8 | — | 0.5% | Jun 29, 2026 |
35Monitor | CVE-2026-13744No exploit | Snowflake CLI SQL Injection Through Improper Neutralization of User-Controlled Inputsnowflake · snowflake cli · CWE-89 | High8.8 | — | 0.5% | Jun 29, 2026 |
32Monitor | CVE-2026-13752No exploit | Snowflake CLI SQL Injection Through Improper Neutralization of Parameters in Secret Creation and SPCS Service Log Commandssnowflake · snowflake cli · CWE-89 | High8.0 | — | 0.3% | Jun 29, 2026 |
31Monitor | CVE-2025-24789No exploit | Snowflake JDBC allows an untrusted search path on Windowssnowflake · snowflake jdbc · CWE-426 | High7.8 | — | 0.3% | Jan 29, 2025 |
31Monitor | CVE-2024-28851No exploit | Elevation of privilege in Snowflake Hive MetaStore Connector Helper scriptsnowflake · snowflake hive metastore connector · CWE-269 | High7.8 | — | 0.3% | Mar 15, 2024 |
31Monitor | CVE-2025-24794No exploit | The Snowflake Connector for Python uses insecure deserialization of the OCSP response cachesnowflake · snowflake connector · CWE-502 | High7.8 | — | 0.3% | Jan 29, 2025 |
30Monitor | CVE-2010-0798No exploit | SQL injection vulnerability in the T3BLOG extension 0.6.2 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands vitypo3 · typo3 · CWE-89 | High7.5 | — | 1.1% | Mar 2, 2010 |
30Monitor | CVE-2022-42965No exploit | Exponential ReDoS in snowflake-connector-python leads to denial of servicesnowflake · snowflake connector · CWE-1333 | High7.5 | — | 0.9% | Nov 9, 2022 |
30Monitor | CVE-2023-51662No exploit | Snowflake Connector .NET does not properly check the Certificate Revocation List (CRL)snowflake · snowflake connector · CWE-295 | High7.5 | — | 0.3% | Dec 22, 2023 |
28Monitor | CVE-2025-24793No exploit | Snowflake Connector for Python has an SQL Injection in write_pandassnowflake · snowflake connector · CWE-89 | High7.0 | — | 0.3% | Jan 29, 2025 |
28Monitor | CVE-2025-46328No exploit | NodeJS Driver for Snowflake has race condition when checking access to Easy Logging configuration filesnowflake · snowflake connector · CWE-367 | High7.0 | — | 0.2% | Apr 28, 2025 |
28Monitor | CVE-2025-46326No exploit | Snowflake Connector for .NET has race condition when checking access to Easy Logging configuration filesnowflake · snowflake connector · CWE-367 | High7.0 | — | 0.2% | Apr 28, 2025 |
28Monitor | CVE-2025-46327No exploit | Go Snowflake Driver has race condition when checking access to Easy Logging configuration filesnowflake · gosnowflake · CWE-367 | High7.0 | — | 0.1% | Apr 28, 2025 |
27Monitor | CVE-2022-35918No exploit | Streamlit directory traversal vulnerabilitysnowflake · streamlit · CWE-22 | Medium6.5 | — | 1.7% | Aug 1, 2022 |
26Monitor | CVE-2024-42474No exploit | Streamlit Path Traversal Security Vulnerability on Windowssnowflake · streamlit · CWE-22 | Medium6.5 | — | 0.6% | Aug 12, 2024 |
25Monitor | CVE-2026-13748No exploit | Snowflake CLI Arbitrary Local File Read and Exfiltration Through Improper File Path Restrictionsnowflake · snowflake cli · CWE-22 | Medium6.3 | — | 0.2% | Jun 29, 2026 |
24Monitor | CVE-2023-27494No exploit | Streamlit Cross-site Scripting vulnerabilitysnowflake · streamlit · CWE-79 | Medium6.1 | — | 0.4% | Mar 16, 2023 |
23Monitor | CVE-2024-43382No exploit | Snowflake JDBC driver versions >= 3.2.6 and <= 3.19.1 have an Incorrect Security Setting that can result in data being uploaded to an encrypsnowflake · snowflake jdbc · CWE-326 | Medium5.9 | — | 0.2% | Oct 30, 2024 |
22Monitor | CVE-2024-49750No exploit | Snowflake Connector for Python has sensitive data in logssnowflake · snowflake connector · CWE-532 | Medium5.5 | — | 0.2% | Oct 24, 2024 |
- CVE-2026-1375138Monitor
Snowflake CLI Server-Side Request Forgery via Arbitrary URL Fetch in !source/!load
CriticalCVSS 9.6No exploitEPSS 0%snowflake · snowflake cliJun 29, 2026
- CVE-2023-3423136Monitor
Snowflake Golang Driver vulnerable to Command Injection
HighCVSS 8.8No exploitEPSS 2%snowflake · gosnowflakeJun 8, 2023
- CVE-2023-3423236Monitor
Snowflake NodeJS Driver vulnerable to Command Injection
HighCVSS 8.8No exploitEPSS 2%snowflake · snowflake connectorJun 8, 2023
- CVE-2023-3423336Monitor
Snowflake Python Connector vulnerable to Command Injection
HighCVSS 8.8Proof of conceptEPSS 2%snowflake · snowflake connectorJun 8, 2023
- CVE-2023-3053536Monitor
Snowflake JDBC vulnerable to command injection via SSO URL authentication
HighCVSS 8.8No exploitEPSS 2%snowflake · snowflake jdbcApr 14, 2023
- CVE-2023-3423035Monitor
Snowflake Connector vulnerable to Command Injection
HighCVSS 8.8No exploitEPSS 1%snowflake · snowflake connectorJun 8, 2023
- CVE-2026-1374935Monitor
Snowflake CLI Arbitrary Code Execution via Snowpark Annotation Processor Template Injection
HighCVSS 8.8No exploitEPSS 1%snowflake · snowflake cliJun 29, 2026
- CVE-2026-1374435Monitor
Snowflake CLI SQL Injection Through Improper Neutralization of User-Controlled Input
HighCVSS 8.8No exploitEPSS 0%snowflake · snowflake cliJun 29, 2026
- CVE-2026-1375232Monitor
Snowflake CLI SQL Injection Through Improper Neutralization of Parameters in Secret Creation and SPCS Service Log Commands
HighCVSS 8.0No exploitEPSS 0%snowflake · snowflake cliJun 29, 2026
- CVE-2025-2478931Monitor
Snowflake JDBC allows an untrusted search path on Windows
HighCVSS 7.8No exploitEPSS 0%snowflake · snowflake jdbcJan 29, 2025
- CVE-2024-2885131Monitor
Elevation of privilege in Snowflake Hive MetaStore Connector Helper script
HighCVSS 7.8No exploitEPSS 0%snowflake · snowflake hive metastore connectorMar 15, 2024
- CVE-2025-2479431Monitor
The Snowflake Connector for Python uses insecure deserialization of the OCSP response cache
HighCVSS 7.8No exploitEPSS 0%snowflake · snowflake connectorJan 29, 2025
- CVE-2010-079830Monitor
SQL injection vulnerability in the T3BLOG extension 0.6.2 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands vi
HighCVSS 7.5No exploitEPSS 1%typo3 · typo3Mar 2, 2010
- CVE-2022-4296530Monitor
Exponential ReDoS in snowflake-connector-python leads to denial of service
HighCVSS 7.5No exploitEPSS 1%snowflake · snowflake connectorNov 9, 2022
- CVE-2023-5166230Monitor
Snowflake Connector .NET does not properly check the Certificate Revocation List (CRL)
HighCVSS 7.5No exploitEPSS 0%snowflake · snowflake connectorDec 22, 2023
- CVE-2025-2479328Monitor
Snowflake Connector for Python has an SQL Injection in write_pandas
HighCVSS 7.0No exploitEPSS 0%snowflake · snowflake connectorJan 29, 2025
- CVE-2025-4632828Monitor
NodeJS Driver for Snowflake has race condition when checking access to Easy Logging configuration file
HighCVSS 7.0No exploitEPSS 0%snowflake · snowflake connectorApr 28, 2025
- CVE-2025-4632628Monitor
Snowflake Connector for .NET has race condition when checking access to Easy Logging configuration file
HighCVSS 7.0No exploitEPSS 0%snowflake · snowflake connectorApr 28, 2025
- CVE-2025-4632728Monitor
Go Snowflake Driver has race condition when checking access to Easy Logging configuration file
HighCVSS 7.0No exploitEPSS 0%snowflake · gosnowflakeApr 28, 2025
- CVE-2022-3591827Monitor
Streamlit directory traversal vulnerability
MediumCVSS 6.5No exploitEPSS 2%snowflake · streamlitAug 1, 2022
- CVE-2024-4247426Monitor
Streamlit Path Traversal Security Vulnerability on Windows
MediumCVSS 6.5No exploitEPSS 1%snowflake · streamlitAug 12, 2024
- CVE-2026-1374825Monitor
Snowflake CLI Arbitrary Local File Read and Exfiltration Through Improper File Path Restriction
MediumCVSS 6.3No exploitEPSS 0%snowflake · snowflake cliJun 29, 2026
- CVE-2023-2749424Monitor
Streamlit Cross-site Scripting vulnerability
MediumCVSS 6.1No exploitEPSS 0%snowflake · streamlitMar 16, 2023
- CVE-2024-4338223Monitor
Snowflake JDBC driver versions >= 3.2.6 and <= 3.19.1 have an Incorrect Security Setting that can result in data being uploaded to an encryp
MediumCVSS 5.9No exploitEPSS 0%snowflake · snowflake jdbcOct 30, 2024
- CVE-2024-4975022Monitor
Snowflake Connector for Python has sensitive data in logs
MediumCVSS 5.5No exploitEPSS 0%snowflake · snowflake connectorOct 24, 2024