Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
124 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.12% | — | Snowsoftware Snow Inventory Agent | 8/2/2024 | 17/6/2026 | Improper Verification of Cryptographic Signature vulnerability in Snow Software Inventory Agent on MacOS, Snow Software Inventory Agent on Windows, Snow Software Inventory Agent on Linux allows File Manipulation through Snow Update Packages.This issue affects Inventory Agent: through 6.12.0; Inventory Agent: through… | |
| Modificada | Media (5.5) | 0.16% | — | Snowsoftware Snow Inventory Agent | 8/2/2024 | 17/6/2026 | Authentication Bypass by Spoofing vulnerability in Snow Software Snow Inventory Agent on Windows allows Signature Spoof.This issue affects Snow Inventory Agent: through 6.14.5. Customers advised to upgrade to version 7.0 | |
| Modificada | Alta (7.5) | 0.35% | — | Snowflake Connector | 22/12/2023 | 17/6/2026 | The Snowflake .NET driver provides an interface to the Microsoft .NET open source software framework for developing applications. Snowflake recently received a report about a vulnerability in the Snowflake Connector .NET where the checks against the Certificate Revocation List (CRL) were not performed where the… | |
| Modificada | Media (4.8) | 0.33% | — | Snowsoftware Snow License Manager | 11/8/2023 | 17/6/2026 | Cross site scripting vulnerability in web portal in Snow Software License Manager from version 9.0.0 up to and including 9.30.1 on Windows allows an authenticated user with high privileges to trigger cross site scripting attack via the web browser | |
| Modificada | Alta (7.2) | 0.56% | — | Snowsoftware Snow License Manager | 11/8/2023 | 17/6/2026 | Blind SQL injection in a service running in Snow Software license manager from version 8.0.0 up to and including 9.30.1 on Windows allows a logged in user with high privileges to inject SQL commands via the web portal. | |
| Modificada | Crítica (9.1) | 1.5% | — | 2inc Snow Monkey Forms | 28/6/2023 | 17/6/2026 | Directory traversal vulnerability in Snow Monkey Forms v5.1.1 and earlier allows a remote unauthenticated attacker to delete arbitrary files on the server. | |
| Modificada | Alta (8.8) | 1.8% | 💥 PoC | Snowflake Connector | 8/6/2023 | 17/6/2026 | The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Versions prior to 3.0.2 are vulnerable to command injection via single sign-on(SSO) browser URL authentication. In order to exploit the potential for command… | |
| Modificada | Alta (8.8) | 1.9% | — | Snowflake Connector | 8/6/2023 | 17/6/2026 | snowflake-connector-nodejs, a NodeJS driver for Snowflake, is vulnerable to command injection via single sign on (SSO) browser URL authentication in versions prior to 1.6.21. In order to exploit the potential for command injection, an attacker would need to be successful in (1) establishing a malicious resource and… | |
| Modificada | Alta (8.8) | 1.4% | — | Snowflake Connector | 8/6/2023 | 17/6/2026 | snowflake-connector-net, the Snowflake Connector for .NET, is vulnerable to command injection prior to version 2.0.18 via SSO URL authentication. In order to exploit the potential for command injection, an attacker would need to be successful in (1) establishing a malicious resource and (2) redirecting users to… | |
| Modificada | Alta (8.8) | 2.0% | — | Gosnowflake | 8/6/2023 | 17/6/2026 | gosnowflake is th Snowflake Golang driver. Prior to version 1.6.19, a command injection vulnerability exists in the Snowflake Golang driver via single sign-on (SSO) browser URL authentication. In order to exploit the potential for command injection, an attacker would need to be successful in (1) establishing a… | |
| Modificada | Crítica (9.8) | 2.0% | — | Snow Monkey Forms Project Snow Monkey Forms | 23/5/2023 | 17/6/2026 | Directory traversal vulnerability in Snow Monkey Forms versions v5.0.6 and earlier allows a remote unauthenticated attacker to obtain sensitive information, alter the website, or cause a denial-of-service (DoS) condition. | |
| Modificada | Media (4.3) | 0.38% | — | Snowsoftware Snow License Manager | 17/5/2023 | 17/6/2026 | Data leakage in Adobe connector in Snow Software SPE 9.27.0 on Windows allows privileged user to observe other users data. | |
| Modificada | Alta (8.8) | 1.7% | — | Snowflake Jdbc | 14/4/2023 | 17/6/2026 | Snowflake JDBC provides a JDBC type 4 driver that supports core functionality, allowing Java program to connect to Snowflake. Users of the Snowflake JDBC driver were vulnerable to a command injection vulnerability. An attacker could set up a malicious, publicly accessible server which responds to the SSO URL with an… | |
| Modificada | Media (6.1) | 0.41% | — | Snowflake Streamlit | 16/3/2023 | 17/6/2026 | Streamlit, software for turning data scripts into web applications, had a cross-site scripting (XSS) vulnerability in versions 0.63.0 through 0.80.0. Users of hosted Streamlit app(s) were vulnerable to a reflected XSS vulnerability. An attacker could craft a malicious URL with Javascript payloads to a Streamlit app.… | |
| Modificada | Alta (8.8) | 0.20% | — | AMD Genoa FirmwareAMD Hygon 1 FirmwareAMD Hygon 2 FirmwareAMD Hygon 3 Firmware+35 | 15/11/2022 | 17/6/2026 | Incorrect pointer checks within the the FwBlockServiceSmm driver can allow arbitrary RAM modifications During review of the FwBlockServiceSmm driver, certain instances of SpiAccessLib could be tricked into writing 0xff to arbitrary system and SMRAM addresses. Fixed in: INTEL Purley-R: 05.21.51.0048 Whitley:… | |
| Analizada | Alta (7.5) | 0.86% | — | Snowflake Connector | 9/11/2022 | 17/6/2026 | An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the snowflake-connector-python PyPI package, when an attacker is able to supply arbitrary input to the undocumented get_file_transfer_type method | |
| Modificada | Media (6.5) | 1.7% | — | Snowflake Streamlit | 1/8/2022 | 17/6/2026 | Streamlit is a data oriented application development framework for python. Users hosting Streamlit app(s) that use custom components are vulnerable to a directory traversal attack that could leak data from their web server file-system such as: server logs, world readable files, and potentially other sensitive… | |
| Modificada | Alta (7.8) | 0.23% | — | Snowsoftware Snow License Manager | 18/5/2022 | 17/6/2026 | SLM has an issue with Windows Unquoted/Trusted Service Paths Security Issue. All installations version 9.x.x prior to 9.20.1 should be patched. | |
| Modificada | Alta (7.8) | 0.25% | — | Snowsoftware Snow Inventory Java Scanner | 16/2/2022 | 17/6/2026 | A vulnerability in Snow Inventory Java Scanner allows an attacker to run malicious code at a higher level of privileges. This issue affects: SNOW Snow Inventory Java Scanner 1.0 | |
| Modificada | Media (6.5) | 0.91% | — | Jenkins Snow Commander | 15/2/2022 | 17/6/2026 | Missing permission checks in Jenkins Snow Commander Plugin 1.10 and earlier allow attackers with Overall/Read permission to connect to an attacker-specified webserver using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins. | |
| Modificada | Alta (8.8) | 0.66% | — | Jenkins Snow Commander | 15/2/2022 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Snow Commander Plugin 1.10 and earlier allows attackers to connect to an attacker-specified webserver using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins. | |
| Analizada | Crítica (10) | 100% | ⚠ Explotación activa💥 Exploit | Siemens 6bk1602-0aa12-0tp0 FirmwareSiemens 6bk1602-0aa22-0tp0 FirmwareSiemens 6bk1602-0aa32-0tp0 FirmwareSiemens 6bk1602-0aa42-0tp0 Firmware+139 | 10/12/2021 | 11/8/2026 | Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can… | |
| Modificada | Media (6.1) | 0.25% | — | Snowsoftware Snow Inventory Agent | 3/11/2021 | 17/6/2026 | A vulnerability in Snow Snow Agent for Windows allows a non-admin user to cause arbitrary deletion of files. This issue affects: Snow Snow Agent for Windows version 5.0.0 to 6.7.1 on Windows. | |
| Modificada | Alta (7.8) | 0.48% | — | Snowsoftware Snow Inventory Agent | 23/2/2021 | 17/6/2026 | Snow Inventory Agent through 6.7.0 on Windows uses CPUID to report on processor types and versions that may be deployed and in use across an IT environment. A privilege-escalation vulnerability exists if CPUID is enabled, and thus it should be disabled via configuration settings. | |
| Modificada | Alta (7.5) | 1.4% | — | Snowhaze | 14/11/2019 | 17/6/2026 | SnowHaze before 2.6.6 is sometimes too late to honor a per-site JavaScript blocking setting, which leads to unintended JavaScript execution via a chain of webpage redirections targeted to the user's browser configuration. |