Snowflake Connector
Vendor:
First CVE: Nov 9, 2022 · Active for 3 years
13
Total CVEs
More Total CVEs than 92% of tracked products
3.3
Avg CVEs / Year
Higher CVE frequency than 84% of tracked products
7.1
Avg CVSS
Higher Avg CVSS than 45% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Snowflake Connector over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 9, 2022
3 years ago
Most Recent CVE
Apr 28, 2025
456 days ago
CVE Severity & Scoring
Snowflake Connector13 CVEs
31%
69%
All CVEs353,173 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local8 (61.5%)
Network5 (38.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (69.2%)
High4 (30.8%)
Unknown0 (0.0%)
User Interaction
None10 (76.9%)
Unknown0 (0.0%)
Required3 (23.1%)
Privileges Required
Low9 (69.2%)
High0 (0.0%)
None4 (30.8%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-34230HIGH snowflake-connector-net, the Snowflake Connector for .NET, is vulnerable to command injection prior to version 2.0.18 via SSO URL authentication. In order to exploit the potential | Jun 8, 2023 | 8.8 | 25 | NO | NO |
CVE-2022-42965HIGH An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the snowflake-connector-python PyPI package, when an attacker is able to supply arbitrary input to t | Nov 9, 2022 | 7.5 | 25 | NO | NO |
CVE-2023-34233HIGH The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Versions prior to 3.0 | Jun 8, 2023 | 8.8 | 24 | NO | NO |
CVE-2023-34232HIGH snowflake-connector-nodejs, a NodeJS driver for Snowflake, is vulnerable to command injection via single sign on (SSO) browser URL authentication in versions prior to 1.6.21. In or | Jun 8, 2023 | 8.8 | 24 | NO | NO |
CVE-2025-24794HIGH The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Snowflake discovered | Jan 29, 2025 | 7.8 | 22 | NO | NO |
CVE-2025-46326HIGH snowflake-connector-net is the Snowflake Connector for .NET. Versions starting from 2.1.2 to before 4.4.1, are vulnerable to a Time-of-Check to Time-of-Use (TOCTOU) race condition. | Apr 28, 2025 | 7.0 | 21 | NO | NO |
CVE-2025-46328HIGH snowflake-connector-nodejs is a NodeJS driver for Snowflake. Versions starting from 1.10.0 to before 2.0.4, are vulnerable to a Time-of-Check to Time-of-Use (TOCTOU) race condition | Apr 28, 2025 | 7.0 | 20 | NO | NO |
CVE-2025-24793HIGH The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Snowflake discovered | Jan 29, 2025 | 7.0 | 20 | NO | NO |
CVE-2023-51662HIGH The Snowflake .NET driver provides an interface to the Microsoft .NET open source software framework for developing applications. Snowflake recently received a report about a vulne | Dec 22, 2023 | 7.5 | 19 | NO | NO |
CVE-2025-24791MEDIUM snowflake-connector-nodejs is a NodeJS driver for Snowflake. Snowflake discovered and remediated a vulnerability in the Snowflake NodeJS Driver. File permissions checks of the temp | Jan 29, 2025 | 5.5 | 18 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (13 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (13 CVEs).
Media Mentions
Signals from CVEs in this product scope (13 CVEs).
Top CNAs Publishing CVEs For Snowflake Connector
Top CWEs
Versions
No cataloged versions.