Snowflake kayıtları
snowflake üreticisine ait 38 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 7
- Düzeltme kaydı olan
- %89,5
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')5
- CWE-532 Insertion of Sensitive Information into Log File4
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')4
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-276 Incorrect Default Permissions3
- CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition3
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
38 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
38İzleyin | CVE-2026-13751İstismar yok | Snowflake CLI Server-Side Request Forgery via Arbitrary URL Fetch in !source/!loadsnowflake · snowflake cli · CWE-829 | Kritik9,6 | — | %0,2 | 29 Haz 2026 |
36İzleyin | CVE-2023-34231İstismar yok | Snowflake Golang Driver vulnerable to Command Injectionsnowflake · gosnowflake · CWE-77 | Yüksek8,8 | — | %2,0 | 8 Haz 2023 |
36İzleyin | CVE-2023-34232İstismar yok | Snowflake NodeJS Driver vulnerable to Command Injectionsnowflake · snowflake connector · CWE-77 | Yüksek8,8 | — | %1,9 | 8 Haz 2023 |
36İzleyin | CVE-2023-34233Kavram kanıtı | Snowflake Python Connector vulnerable to Command Injectionsnowflake · snowflake connector · CWE-77 | Yüksek8,8 | — | %1,8 | 8 Haz 2023 |
36İzleyin | CVE-2023-30535İstismar yok | Snowflake JDBC vulnerable to command injection via SSO URL authenticationsnowflake · snowflake jdbc · CWE-20 | Yüksek8,8 | — | %1,7 | 14 Nis 2023 |
35İzleyin | CVE-2023-34230İstismar yok | Snowflake Connector vulnerable to Command Injectionsnowflake · snowflake connector · CWE-77 | Yüksek8,8 | — | %1,4 | 8 Haz 2023 |
35İzleyin | CVE-2026-13749İstismar yok | Snowflake CLI Arbitrary Code Execution via Snowpark Annotation Processor Template Injectionsnowflake · snowflake cli · CWE-94 | Yüksek8,8 | — | %0,5 | 29 Haz 2026 |
35İzleyin | CVE-2026-13744İstismar yok | Snowflake CLI SQL Injection Through Improper Neutralization of User-Controlled Inputsnowflake · snowflake cli · CWE-89 | Yüksek8,8 | — | %0,5 | 29 Haz 2026 |
32İzleyin | CVE-2026-13752İstismar yok | Snowflake CLI SQL Injection Through Improper Neutralization of Parameters in Secret Creation and SPCS Service Log Commandssnowflake · snowflake cli · CWE-89 | Yüksek8,0 | — | %0,3 | 29 Haz 2026 |
31İzleyin | CVE-2025-24789İstismar yok | Snowflake JDBC allows an untrusted search path on Windowssnowflake · snowflake jdbc · CWE-426 | Yüksek7,8 | — | %0,3 | 29 Oca 2025 |
31İzleyin | CVE-2024-28851İstismar yok | Elevation of privilege in Snowflake Hive MetaStore Connector Helper scriptsnowflake · snowflake hive metastore connector · CWE-269 | Yüksek7,8 | — | %0,3 | 15 Mar 2024 |
31İzleyin | CVE-2025-24794İstismar yok | The Snowflake Connector for Python uses insecure deserialization of the OCSP response cachesnowflake · snowflake connector · CWE-502 | Yüksek7,8 | — | %0,3 | 29 Oca 2025 |
30İzleyin | CVE-2010-0798İstismar yok | SQL injection vulnerability in the T3BLOG extension 0.6.2 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands vitypo3 · typo3 · CWE-89 | Yüksek7,5 | — | %1,1 | 2 Mar 2010 |
30İzleyin | CVE-2022-42965İstismar yok | Exponential ReDoS in snowflake-connector-python leads to denial of servicesnowflake · snowflake connector · CWE-1333 | Yüksek7,5 | — | %0,9 | 9 Kas 2022 |
30İzleyin | CVE-2023-51662İstismar yok | Snowflake Connector .NET does not properly check the Certificate Revocation List (CRL)snowflake · snowflake connector · CWE-295 | Yüksek7,5 | — | %0,3 | 22 Ara 2023 |
28İzleyin | CVE-2025-24793İstismar yok | Snowflake Connector for Python has an SQL Injection in write_pandassnowflake · snowflake connector · CWE-89 | Yüksek7,0 | — | %0,3 | 29 Oca 2025 |
28İzleyin | CVE-2025-46328İstismar yok | NodeJS Driver for Snowflake has race condition when checking access to Easy Logging configuration filesnowflake · snowflake connector · CWE-367 | Yüksek7,0 | — | %0,2 | 28 Nis 2025 |
28İzleyin | CVE-2025-46326İstismar yok | Snowflake Connector for .NET has race condition when checking access to Easy Logging configuration filesnowflake · snowflake connector · CWE-367 | Yüksek7,0 | — | %0,2 | 28 Nis 2025 |
28İzleyin | CVE-2025-46327İstismar yok | Go Snowflake Driver has race condition when checking access to Easy Logging configuration filesnowflake · gosnowflake · CWE-367 | Yüksek7,0 | — | %0,1 | 28 Nis 2025 |
27İzleyin | CVE-2022-35918İstismar yok | Streamlit directory traversal vulnerabilitysnowflake · streamlit · CWE-22 | Orta6,5 | — | %1,7 | 1 Ağu 2022 |
26İzleyin | CVE-2024-42474İstismar yok | Streamlit Path Traversal Security Vulnerability on Windowssnowflake · streamlit · CWE-22 | Orta6,5 | — | %0,6 | 12 Ağu 2024 |
25İzleyin | CVE-2026-13748İstismar yok | Snowflake CLI Arbitrary Local File Read and Exfiltration Through Improper File Path Restrictionsnowflake · snowflake cli · CWE-22 | Orta6,3 | — | %0,2 | 29 Haz 2026 |
24İzleyin | CVE-2023-27494İstismar yok | Streamlit Cross-site Scripting vulnerabilitysnowflake · streamlit · CWE-79 | Orta6,1 | — | %0,4 | 16 Mar 2023 |
23İzleyin | CVE-2024-43382İstismar yok | Snowflake JDBC driver versions >= 3.2.6 and <= 3.19.1 have an Incorrect Security Setting that can result in data being uploaded to an encrypsnowflake · snowflake jdbc · CWE-326 | Orta5,9 | — | %0,2 | 30 Eki 2024 |
22İzleyin | CVE-2024-49750İstismar yok | Snowflake Connector for Python has sensitive data in logssnowflake · snowflake connector · CWE-532 | Orta5,5 | — | %0,2 | 24 Eki 2024 |
- CVE-2026-1375138İzleyin
Snowflake CLI Server-Side Request Forgery via Arbitrary URL Fetch in !source/!load
KritikCVSS 9,6İstismar yokEPSS %0snowflake · snowflake cli29 Haz 2026
- CVE-2023-3423136İzleyin
Snowflake Golang Driver vulnerable to Command Injection
YüksekCVSS 8,8İstismar yokEPSS %2snowflake · gosnowflake8 Haz 2023
- CVE-2023-3423236İzleyin
Snowflake NodeJS Driver vulnerable to Command Injection
YüksekCVSS 8,8İstismar yokEPSS %2snowflake · snowflake connector8 Haz 2023
- CVE-2023-3423336İzleyin
Snowflake Python Connector vulnerable to Command Injection
YüksekCVSS 8,8Kavram kanıtıEPSS %2snowflake · snowflake connector8 Haz 2023
- CVE-2023-3053536İzleyin
Snowflake JDBC vulnerable to command injection via SSO URL authentication
YüksekCVSS 8,8İstismar yokEPSS %2snowflake · snowflake jdbc14 Nis 2023
- CVE-2023-3423035İzleyin
Snowflake Connector vulnerable to Command Injection
YüksekCVSS 8,8İstismar yokEPSS %1snowflake · snowflake connector8 Haz 2023
- CVE-2026-1374935İzleyin
Snowflake CLI Arbitrary Code Execution via Snowpark Annotation Processor Template Injection
YüksekCVSS 8,8İstismar yokEPSS %1snowflake · snowflake cli29 Haz 2026
- CVE-2026-1374435İzleyin
Snowflake CLI SQL Injection Through Improper Neutralization of User-Controlled Input
YüksekCVSS 8,8İstismar yokEPSS %0snowflake · snowflake cli29 Haz 2026
- CVE-2026-1375232İzleyin
Snowflake CLI SQL Injection Through Improper Neutralization of Parameters in Secret Creation and SPCS Service Log Commands
YüksekCVSS 8,0İstismar yokEPSS %0snowflake · snowflake cli29 Haz 2026
- CVE-2025-2478931İzleyin
Snowflake JDBC allows an untrusted search path on Windows
YüksekCVSS 7,8İstismar yokEPSS %0snowflake · snowflake jdbc29 Oca 2025
- CVE-2024-2885131İzleyin
Elevation of privilege in Snowflake Hive MetaStore Connector Helper script
YüksekCVSS 7,8İstismar yokEPSS %0snowflake · snowflake hive metastore connector15 Mar 2024
- CVE-2025-2479431İzleyin
The Snowflake Connector for Python uses insecure deserialization of the OCSP response cache
YüksekCVSS 7,8İstismar yokEPSS %0snowflake · snowflake connector29 Oca 2025
- CVE-2010-079830İzleyin
SQL injection vulnerability in the T3BLOG extension 0.6.2 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands vi
YüksekCVSS 7,5İstismar yokEPSS %1typo3 · typo32 Mar 2010
- CVE-2022-4296530İzleyin
Exponential ReDoS in snowflake-connector-python leads to denial of service
YüksekCVSS 7,5İstismar yokEPSS %1snowflake · snowflake connector9 Kas 2022
- CVE-2023-5166230İzleyin
Snowflake Connector .NET does not properly check the Certificate Revocation List (CRL)
YüksekCVSS 7,5İstismar yokEPSS %0snowflake · snowflake connector22 Ara 2023
- CVE-2025-2479328İzleyin
Snowflake Connector for Python has an SQL Injection in write_pandas
YüksekCVSS 7,0İstismar yokEPSS %0snowflake · snowflake connector29 Oca 2025
- CVE-2025-4632828İzleyin
NodeJS Driver for Snowflake has race condition when checking access to Easy Logging configuration file
YüksekCVSS 7,0İstismar yokEPSS %0snowflake · snowflake connector28 Nis 2025
- CVE-2025-4632628İzleyin
Snowflake Connector for .NET has race condition when checking access to Easy Logging configuration file
YüksekCVSS 7,0İstismar yokEPSS %0snowflake · snowflake connector28 Nis 2025
- CVE-2025-4632728İzleyin
Go Snowflake Driver has race condition when checking access to Easy Logging configuration file
YüksekCVSS 7,0İstismar yokEPSS %0snowflake · gosnowflake28 Nis 2025
- CVE-2022-3591827İzleyin
Streamlit directory traversal vulnerability
OrtaCVSS 6,5İstismar yokEPSS %2snowflake · streamlit1 Ağu 2022
- CVE-2024-4247426İzleyin
Streamlit Path Traversal Security Vulnerability on Windows
OrtaCVSS 6,5İstismar yokEPSS %1snowflake · streamlit12 Ağu 2024
- CVE-2026-1374825İzleyin
Snowflake CLI Arbitrary Local File Read and Exfiltration Through Improper File Path Restriction
OrtaCVSS 6,3İstismar yokEPSS %0snowflake · snowflake cli29 Haz 2026
- CVE-2023-2749424İzleyin
Streamlit Cross-site Scripting vulnerability
OrtaCVSS 6,1İstismar yokEPSS %0snowflake · streamlit16 Mar 2023
- CVE-2024-4338223İzleyin
Snowflake JDBC driver versions >= 3.2.6 and <= 3.19.1 have an Incorrect Security Setting that can result in data being uploaded to an encryp
OrtaCVSS 5,9İstismar yokEPSS %0snowflake · snowflake jdbc30 Eki 2024
- CVE-2024-4975022İzleyin
Snowflake Connector for Python has sensitive data in logs
OrtaCVSS 5,5İstismar yokEPSS %0snowflake · snowflake connector24 Eki 2024