| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-39610 | WordPress WpXmas-Snow plugin <= 1.1 - Broken Access Control vulnerability | Pankaj Kumar | WpXmas-Snow | - | - | 2026-04-08 08:30:24 | Deep Dive |
| CVE-2026-35037 | Ech0 affected by unauthenticated SSRF in GetWebsiteTitle allows access to internal services and cloud metadata | lin-snow | Ech0 | High | 7.2 | 2026-04-06 16:56:55 | Deep Dive |
| CVE-2026-35036 | Ech0 Affected by Unauthenticated Server-Side Request Forgery in Website Preview Feature | lin-snow | Ech0 | High | 7.5 | 2026-04-06 16:55:48 | Deep Dive |
| CVE-2026-33638 | Ech0 authenticated user-list exposed data via public `/api/allusers` endpoint | lin-snow | Ech0 | Medium | 5.3 | 2026-03-26 20:52:40 | Deep Dive |
| CVE-2026-1056 | Snow Monkey Forms <= 12.0.3 - Unauthenticated Arbitrary File Deletion via Path Traversal | inc2734 | Snow Monkey Forms | Critical | 9.8 | 2026-01-28 12:28:37 | Deep Dive |
| CVE-2025-69065 | WordPress Snow Mountain theme <= 1.4.3 - Local File Inclusion vulnerability | AncoraThemes | Snow Mountain | - | - | 2026-01-22 16:52:23 | Deep Dive |
| CVE-2025-64294 | WordPress WP Snow Effect plugin <= 1.1.19 - Broken Access Control vulnerability | d3wp | WP Snow Effect | Medium | 5.3 | 2025-11-03 13:09:39 | Deep Dive |
| CVE-2025-10137 | Snow Monkey <= 29.1.5 - Unauthenticated Blind Server-Side Request Forgery | inc2734 | Snow Monkey | Medium | 5.4 | 2025-09-26 06:43:29 | Deep Dive |
| CVE-2024-58265 | snow crate 安全漏洞 | mcginty | snow | Low | 3.1 | 2025-07-27 00:00:00 | Deep Dive |
| CVE-2025-30858 | WordPress Snow Storm plugin <= 1.4.6 - Reflected Cross Site Scripting (XSS) vulnerability | Tribulant Software | Snow Storm | High | 7.1 | 2025-04-03 13:27:08 | Deep Dive |
| CVE-2024-4129 | Authentication bypass in Snow License Manager | Snow Software AB | Snow License Manager | High | 8.8 | 2024-05-10 06:55:53 | Deep Dive |
| CVE-2024-1150 | Improper validation of update packages | Snow Software | Inventory Agent | High | 7.8 | 2024-02-08 13:06:17 | Deep Dive |
| CVE-2024-1149 | Improper validation of update packages | Snow Software | Inventory Agent | High | 7.8 | 2024-02-08 13:01:04 | Deep Dive |
| CVE-2023-7169 | Impersonate vendor signed Powershell scripts | Snow Software | Snow Inventory Agent | Medium | 6.0 | 2024-02-08 12:59:41 | Deep Dive |
| CVE-2023-3937 | Cross site scripting vulnerabilities in Snow License Manager | Snow Software | Snow License Manager | Medium | 4.8 | 2023-08-11 11:28:30 | Deep Dive |
| CVE-2023-3864 | SQL injection vulnerability in Snow License Manager | Snow Software | SLM | High | 7.2 | 2023-08-11 11:24:06 | Deep Dive |
| CVE-2023-32623 | WordPress Plugin Snow Monkey Forms 路径遍历漏洞 | Monkey Wrench Inc. | Snow Monkey Forms | 超危 | - | 2023-06-28 04:16:56 | Deep Dive |
| CVE-2023-28413 | WordPress plugin Snow Monkey Forms 路径遍历漏洞 | Monkey Wrench Inc. | Snow Monkey Forms | 超危 | - | 2023-05-23 00:00:00 | Deep Dive |
| CVE-2023-2679 | Data leakage in Adobe connector for SPE edition of SLM | Snow Software | SPE SLM | Medium | 4.1 | 2023-05-17 12:55:58 | Deep Dive |
| CVE-2022-0883 | Windows Unquoted/Trusted Service Paths | SNOW | Snow License Manager | High | 7.3 | 2022-05-18 16:37:50 | Deep Dive |