Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
124 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.42% | — | Snowplow Stream Collector | 3/4/2025 | 17/6/2026 | This vulnerability affects Snowplow Collector 3.x before 3.3.0 (unless it’s set up behind a reverse proxy that establishes payload limits). It involves sending very large payloads to the Collector and can render it unresponsive to the rest of the requests. As a result, data would not enter the pipeline and would be… | |
| Analizada | Media (6.5) | 0.40% | — | Snowplow Iglu Server | 3/4/2025 | 17/6/2026 | An issue was discovered in Iglu Server 0.13.0 and below. It is similar to CVE-2024-47214, but involves an authenticated endpoint. It can render Iglu Server completely unresponsive. If the operation of Iglu Server is not restored, event processing in the pipeline would eventually halt. | |
| Analizada | Alta (7.5) | 0.42% | — | Snowplow Snowbridge | 3/4/2025 | 17/6/2026 | An issue was discovered in Snowbridge setups sending data to Google Tag Manager Server Side. It involves attaching an invalid GTM SS preview header to events, causing them to be retried indefinitely. As a result, the performance of forwarding events to GTM SS overall can be affected (latency, throughput). | |
| Analizada | Alta (7.5) | 0.42% | — | Snowplow Iglu Server | 3/4/2025 | 17/6/2026 | An issue was discovered in Iglu Server 0.13.0 and below. It is similar to CVE-2024-47212, but involves a different kind of malicious payload. As above, it can render Iglu Server completely unresponsive. If the operation of Iglu Server is not restored, event processing in the pipeline would eventually halt. | |
| Analizada | Alta (7.5) | 0.42% | — | Snowplow Enrich | 3/4/2025 | 17/6/2026 | An issue was discovered affecting Enrich 5.1.0 and below. It involves sending a maliciously crafted Snowplow event to the pipeline. Upon receiving this event and trying to validate it, Enrich crashes and attempts to restart indefinitely. As a result, event processing would be halted. | |
| Analizada | Alta (7.5) | 0.42% | — | Snowplow Iglu Server | 3/4/2025 | 17/6/2026 | An issue was discovered in Iglu Server 0.13.0 and below. It involves sending very large payloads to a particular API endpoint of Iglu Server and can render it completely unresponsive. If the operation of Iglu Server is not restored, event processing in the pipeline would eventually halt. | |
| Aplazada | Alta (7.1) | 0.29% | — | Tribulant Software Snow StormAI | 3/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tribulant Software Snow Storm snow-storm allows Reflected XSS.This issue affects Snow Storm: from n/a through <= 1.4.6. | |
| Aplazada | Alta (7.5) | 0.65% | — | VannaAISnowflakeAIPalletsprojects FlaskAI | 20/3/2025 | 17/6/2026 | Vanna v0.6.3 is vulnerable to SQL injection via Snowflake database in its file staging operations using the `PUT` and `COPY` commands. This vulnerability allows unauthenticated remote users to read arbitrary local files on the victim server, such as `/etc/passwd`, by exploiting the exposed SQL queries through a Python… | |
| Analizada | Baja (3.3) | 0.12% | — | Snowflake Jdbc | 13/3/2025 | 17/6/2026 | Snowflake, a platform for using artificial intelligence in the context of cloud computing, has a vulnerability in the Snowflake JDBC driver ("Driver") in versions 3.0.13 through 3.23.0 of the driver. When the logging level was set to DEBUG, the Driver would log locally the client-side encryption master key of the… | |
| Analizada | Media (5.5) | 0.14% | — | Snowflake Connector | 29/1/2025 | 17/6/2026 | The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Snowflake discovered and remediated a vulnerability in the Snowflake Connector for Python. On Linux systems, when temporary credential caching is enabled, the… | |
| Analizada | Alta (7.8) | 0.25% | — | Snowflake Connector | 29/1/2025 | 17/6/2026 | The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Snowflake discovered and remediated a vulnerability in the Snowflake Connector for Python. The OCSP response cache uses pickle as the serialization format,… | |
| Analizada | Alta (7) | 0.33% | — | Snowflake Connector | 29/1/2025 | 17/6/2026 | The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Snowflake discovered and remediated a vulnerability in the Snowflake Connector for Python. A function from the snowflake.connector.pandas_tools module is… | |
| Analizada | Media (5.5) | 0.14% | — | Snowflake Connector | 29/1/2025 | 17/6/2026 | snowflake-connector-net is the Snowflake Connector for .NET. Snowflake discovered and remediated a vulnerability in the Snowflake Connector for .NET in which files downloaded from stages are temporarily placed in a world-readable local directory, making them accessible to unauthorized users on the same machine. This… | |
| Analizada | Media (5.5) | 0.19% | — | Snowflake Jdbc | 29/1/2025 | 17/6/2026 | Snowflake JDBC provides a JDBC type 4 driver that supports core functionality, allowing Java program to connect to Snowflake. Snowflake discovered and remediated a vulnerability in the Snowflake JDBC Driver. On Linux systems, when temporary credential caching is enabled, the Snowflake JDBC Driver will cache temporary… | |
| Analizada | Alta (7.8) | 0.26% | — | Snowflake Jdbc | 29/1/2025 | 17/6/2026 | Snowflake JDBC provides a JDBC type 4 driver that supports core functionality, allowing Java program to connect to Snowflake. Snowflake discovered and remediated a vulnerability in the Snowflake JDBC Driver. When the EXTERNALBROWSER authentication method is used on Windows, an attacker with write access to a directory… | |
| Analizada | Media (5.5) | 0.15% | — | Snowflake Connector | 29/1/2025 | 17/6/2026 | snowflake-connector-nodejs is a NodeJS driver for Snowflake. Snowflake discovered and remediated a vulnerability in the Snowflake NodeJS Driver. File permissions checks of the temporary credential cache could be bypassed by an attacker with write access to the local cache directory. This vulnerability affects versions… | |
| Aplazada | Media (4.4) | 0.13% | — | Snowflake PHP PDO DriverAI | 29/1/2025 | 17/6/2026 | Snowflake PHP PDO Driver is a driver that uses the PHP Data Objects (PDO) extension to connect to the Snowflake database. Snowflake discovered and remediated a vulnerability in the Snowflake PHP PDO Driver where executing unsupported queries like PUT or GET on stages causes a signed-to-unsigned conversion error that… | |
| Aplazada | Alta (7.1) | 0.20% | — | Isnowfy My-related-postsAI | 16/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in isnowfy my-related-posts my-related-posts allows Stored XSS.This issue affects my-related-posts: from n/a through <= 1.1. | |
| Analizada | Media (5.9) | 0.18% | — | Snowflake Jdbc | 30/10/2024 | 17/6/2026 | Snowflake JDBC driver versions >= 3.2.6 and <= 3.19.1 have an Incorrect Security Setting that can result in data being uploaded to an encrypted stage without the additional layer of protection provided by client side encryption. | |
| Analizada | Media (5.5) | 0.20% | — | Snowflake Connector | 24/10/2024 | 17/6/2026 | The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Prior to version 3.12.3, when the logging level was set by the user to DEBUG, the Connector could have logged Duo passcodes (when specified via the `passcode`… | |
| Analizada | Media (6.5) | 0.57% | — | Snowflake Streamlit | 12/8/2024 | 17/6/2026 | Streamlit is a data oriented application development framework for python. Snowflake Streamlit open source addressed a security vulnerability via the static file sharing feature. Users of hosted Streamlit app(s) on Windows were vulnerable to a path traversal vulnerability when the static file sharing feature is… | |
| Aplazada | Alta (8.8) | 0.48% | — | Snowsoftware Snow License ManagerAI | 14/5/2024 | 17/6/2026 | Improper Authentication vulnerability in Snow Software AB Snow License Manager on Windows allows a networked attacker to perform an Authentication Bypass if Active Directory Authentication is enabled.This issue affects Snow License Manager: from 9.33.2 through 9.34.0. | |
| Analizada | Media (6.3) | 0.64% | — | Dingflow Snow | 22/3/2024 | 17/6/2026 | SQL injection vulnerability in snow snow v.2.0.0 allows a remote attacker to execute arbitrary code via the dataScope parameter of the system/role/list interface. | |
| Analizada | Alta (7.8) | 0.25% | — | Snowflake Hive Metastore Connector | 15/3/2024 | 17/6/2026 | The Snowflake Hive metastore connector provides an easy way to query Hive-managed data via Snowflake. Snowflake Hive MetaStore Connector has addressed a potential elevation of privilege vulnerability in a `helper script` for the Hive MetaStore Connector. A malicious insider without admin privileges could, in theory,… | |
| Modificada | Media (5.5) | 0.12% | — | Snowsoftware Snow Inventory Agent | 8/2/2024 | 17/6/2026 | Improper Verification of Cryptographic Signature vulnerability in Snow Software Inventory Agent on Unix allows File Manipulation through Snow Update Packages.This issue affects Inventory Agent: through 7.3.1. |