Dingflow develops a niche workflow and data-management product called SNOW, which has surfaced vulnerabilities centered on SQL injection and improper input sanitization. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dingflow over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-25168MEDIUM SQL injection vulnerability in snow snow v.2.0.0 allows a remote attacker to execute arbitrary code via the dataScope parameter of the system/role/list interface. | Mar 22, 2024 | 6.3 | 19 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dingflow.
Media articles that mention a CVE ID that affects a product developed by Dingflow — matched by CVE ID, not by vendor name.