Skip to content
Noroxi

Snowflake records

38 published records for vendor snowflake.

All records

38 records
  • Snowflake CLI Server-Side Request Forgery via Arbitrary URL Fetch in !source/!load

    CriticalCVSS 9.6No exploitEPSS 0%

    snowflake · snowflake cliJun 29, 2026

  • Snowflake Golang Driver vulnerable to Command Injection

    HighCVSS 8.8No exploitEPSS 2%

    snowflake · gosnowflakeJun 8, 2023

  • Snowflake NodeJS Driver vulnerable to Command Injection

    HighCVSS 8.8No exploitEPSS 2%

    snowflake · snowflake connectorJun 8, 2023

  • Snowflake Python Connector vulnerable to Command Injection

    HighCVSS 8.8Proof of conceptEPSS 2%

    snowflake · snowflake connectorJun 8, 2023

  • Snowflake JDBC vulnerable to command injection via SSO URL authentication

    HighCVSS 8.8No exploitEPSS 2%

    snowflake · snowflake jdbcApr 14, 2023

  • Snowflake Connector vulnerable to Command Injection

    HighCVSS 8.8No exploitEPSS 1%

    snowflake · snowflake connectorJun 8, 2023

  • Snowflake CLI Arbitrary Code Execution via Snowpark Annotation Processor Template Injection

    HighCVSS 8.8No exploitEPSS 1%

    snowflake · snowflake cliJun 29, 2026

  • Snowflake CLI SQL Injection Through Improper Neutralization of User-Controlled Input

    HighCVSS 8.8No exploitEPSS 0%

    snowflake · snowflake cliJun 29, 2026

  • Snowflake CLI SQL Injection Through Improper Neutralization of Parameters in Secret Creation and SPCS Service Log Commands

    HighCVSS 8.0No exploitEPSS 0%

    snowflake · snowflake cliJun 29, 2026

  • Snowflake JDBC allows an untrusted search path on Windows

    HighCVSS 7.8No exploitEPSS 0%

    snowflake · snowflake jdbcJan 29, 2025

  • Elevation of privilege in Snowflake Hive MetaStore Connector Helper script

    HighCVSS 7.8No exploitEPSS 0%

    snowflake · snowflake hive metastore connectorMar 15, 2024

  • The Snowflake Connector for Python uses insecure deserialization of the OCSP response cache

    HighCVSS 7.8No exploitEPSS 0%

    snowflake · snowflake connectorJan 29, 2025

  • CVE-2010-0798
    30Monitor

    SQL injection vulnerability in the T3BLOG extension 0.6.2 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands vi

    HighCVSS 7.5No exploitEPSS 1%

    typo3 · typo3Mar 2, 2010

  • Exponential ReDoS in snowflake-connector-python leads to denial of service

    HighCVSS 7.5No exploitEPSS 1%

    snowflake · snowflake connectorNov 9, 2022

  • Snowflake Connector .NET does not properly check the Certificate Revocation List (CRL)

    HighCVSS 7.5No exploitEPSS 0%

    snowflake · snowflake connectorDec 22, 2023

  • Snowflake Connector for Python has an SQL Injection in write_pandas

    HighCVSS 7.0No exploitEPSS 0%

    snowflake · snowflake connectorJan 29, 2025

  • NodeJS Driver for Snowflake has race condition when checking access to Easy Logging configuration file

    HighCVSS 7.0No exploitEPSS 0%

    snowflake · snowflake connectorApr 28, 2025

  • Snowflake Connector for .NET has race condition when checking access to Easy Logging configuration file

    HighCVSS 7.0No exploitEPSS 0%

    snowflake · snowflake connectorApr 28, 2025

  • Go Snowflake Driver has race condition when checking access to Easy Logging configuration file

    HighCVSS 7.0No exploitEPSS 0%

    snowflake · gosnowflakeApr 28, 2025

  • Streamlit directory traversal vulnerability

    MediumCVSS 6.5No exploitEPSS 2%

    snowflake · streamlitAug 1, 2022

  • Streamlit Path Traversal Security Vulnerability on Windows

    MediumCVSS 6.5No exploitEPSS 1%

    snowflake · streamlitAug 12, 2024

  • Snowflake CLI Arbitrary Local File Read and Exfiltration Through Improper File Path Restriction

    MediumCVSS 6.3No exploitEPSS 0%

    snowflake · snowflake cliJun 29, 2026

  • Streamlit Cross-site Scripting vulnerability

    MediumCVSS 6.1No exploitEPSS 0%

    snowflake · streamlitMar 16, 2023

  • Snowflake JDBC driver versions >= 3.2.6 and <= 3.19.1 have an Incorrect Security Setting that can result in data being uploaded to an encryp

    MediumCVSS 5.9No exploitEPSS 0%

    snowflake · snowflake jdbcOct 30, 2024

  • Snowflake Connector for Python has sensitive data in logs

    MediumCVSS 5.5No exploitEPSS 0%

    snowflake · snowflake connectorOct 24, 2024