Vulnerabilities
Summary — last 7 days
New vulnerabilities2,731▼ 88 vs. last week
Critical / high1,419▲ 189 vs. last week
New active exploitation (KEV)5▼ 5 vs. last week
Unscored (no CVSS)83▼ 429 vs. last week
3 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Awaiting Analysis | High (8.1) | 0.50% | — | Snowflake Python APIAI | 8/12/2026 | 9/8/2026 | Insufficient input sanitization in Snowflake Python API (`snowflake.core`) versions prior to 1.13.0 allowed confused-deputy privilege escalation through two related weaknesses: path traversal (CWE-22) via unencoded `..` identifier path segments, and HTTP parameter pollution (CWE-141) via unencoded `&`/`#`/`=`… | |
| Analyzed | Medium (6.9) | 0.11% | — | Heinlein-support Check MK Python API | 8/28/2025 | 9/25/2026 | Improper Certificate Validation in Checkmk Exchange plugin check-mk-api allows attackers in MitM position to intercept traffic. | |
| Analyzed | High (7.7) | 0.38% | — | Heinlein-support Check MK Python API | 3/3/2025 | 6/17/2026 | Insecure deserialization and improper certificate validation in Checkmk Exchange plugin check-mk-api prior to 5.8.1 |