Vulnerabilities

Summary — last 7 days

New vulnerabilities2,731▼ 88 vs. last week
Critical / high1,419▲ 189 vs. last week
New active exploitation (KEV)5▼ 5 vs. last week
Unscored (no CVSS)83▼ 429 vs. last week
–

3 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
Awaiting AnalysisHigh (8.1)0.50%—Snowflake Python APIAI8/12/20269/8/2026
Insufficient input sanitization in Snowflake Python API (`snowflake.core`) versions prior to 1.13.0 allowed confused-deputy privilege escalation through two related weaknesses: path traversal (CWE-22) via unencoded `..` identifier path segments, and HTTP parameter pollution (CWE-141) via unencoded `&`/`#`/`=`…
AnalyzedMedium (6.9)0.11%—Heinlein-support Check MK Python API8/28/20259/25/2026
Improper Certificate Validation in Checkmk Exchange plugin check-mk-api allows attackers in MitM position to intercept traffic.
AnalyzedHigh (7.7)0.38%—Heinlein-support Check MK Python API3/3/20256/17/2026
Insecure deserialization and improper certificate validation in Checkmk Exchange plugin check-mk-api prior to 5.8.1