Sqlite
Sqlite: vulnerabilidades y CVE
Sqlite tiene 75 vulnerabilidades publicadas, 12 de ellas en los últimos 12 meses. 9 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE75
Últimos 12 meses12
Críticas9
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-55650 | Media (4.4) | 0.19% | — | 15 sept 2026 | Outerbase Studio is a lightweight browser-based database GUI supporting PostgreSQL, MySQL, and SQLite. In version 0.10.2 and earlier, TextComponent in src/components/chart/index.tsx renders unsanitized Text Widget… |
| CVE-2026-54629 | Alta (7.5) | 0.97% | — | 14 sept 2026 | Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server exposes file-backed SQLite virtual table modules such as csv_reader and log_reader through its MySQL-compatible server port without… |
| CVE-2026-50006 | Crítica (9.1) | 0.97% | — | 14 sept 2026 | Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server forwards unauthenticated SQL from its MySQL-compatible server port to SQLite without restricting ATTACH DATABASE filesystem… |
| CVE-2026-39113 | Media (4) | 0.19% | — | 25 ago 2026 | Buffer Overflow vulnerability in SQLite affected version source snapshots/builds containing Fossil check-in 8bdc0d485e3ad0c7a1e818da66f106951d496b05cbe61d12c2c448f2f24b6d5d (Git mirror… |
| CVE-2026-46421 | Crítica (9.3) | 0.52% | — | 15 jul 2026 | The SAP Cloud Application Programming Model is a tool for building enterprise-grade cloud applications, and cap-js/cds-dbs is the monorepo for SQL database services for that tool. On April 29, 2026, compromised versions… |
| CVE-2026-50813 | Media (6.1) | 0.16% | — | 8 jul 2026 | An issue in SQLite before Fossil check-in 869a51ae84df allows a local attacker to obtain sensitive information via the Session Extension changeset concat/changegroup merge path |
| CVE-2026-50812 | Media (5.5) | 0.16% | — | 8 jul 2026 | A NULL pointer dereference in the SQLite Session Extension in SQLite 3.53.1 and SQLite trunk builds before check-in e807d4e3798efd53 allows an attacker who can supply a malformed changeset blob to cause a denial of… |
| CVE-2026-53949 | Media (5.3) | 0.36% | — | 24 jun 2026 | Ghost is a Node.js content management system. From 5.46.1 until 6.21.2, the validation applied to filters on the public API endpoints could be partially bypassed, making it possible to reveal private fields via a brute… |
| CVE-2026-11824 | Alta (8.5) | 0.18% | — | 9 jun 2026 | SQLite before 3.53.2 contains a heap-based buffer overflow vulnerability in the FTS5 full-text search extension that allows attackers to cause a crash or execute arbitrary code by supplying a crafted database with… |
| CVE-2026-11822 | Alta (8.5) | 0.29% | — | 9 jun 2026 | SQLite before 3.53.2 contains memory corruption vulnerabilities in the FTS5 full-text search extension that allow attackers to cause process crashes, memory exhaustion, or arbitrary code execution by supplying a crafted… |
| CVE-2025-71316 | Crítica (9.2) | 0.38% | — | 4 jun 2026 | SQLite 'sqldiff.exe' does not securely handle the way the Microsoft Windows C runtime converts Unicode characters to ANSI codepages. An attacker could use the '-L' option to load an arbitrary DLL with a crafted command… |
| CVE-2025-70873 | Alta (7.5) | 0.30% | — | 12 mar 2026 | An information disclosure issue in the zipfileInflate function in the zipfile extension in SQLite v3.51.1 and earlier allows attackers to obtain heap memory via supplying a crafted ZIP file. |
| CVE-2025-7458 | Media (6.9) | 0.24% | — | 29 jul 2025 | An integer overflow in the sqlite3KeyInfoFromExprList function in SQLite versions 3.39.2 through 3.41.1 allows an attacker with the ability to execute arbitrary SQL statements to cause a denial of service or disclose… |
| CVE-2025-4049 | Alta (8.6) | 0.16% | — | 21 jul 2025 | Use of hard-coded, the same among all vulnerable installations SQLite credentials vulnerability in SIGNUM-NET FARA allows to read and manipulate local-stored database.This issue affects FARA: through 5.0.80.34. |
| CVE-2025-6965 | Alta (7.2) | 73% | — | 15 jul 2025 | There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corruption issue. We recommend upgrading to… |
| CVE-2025-3277 | Media (6.9) | 0.83% | — | 14 abr 2025 | An integer overflow can be triggered in SQLite’s `concat_ws()` function. The resulting, truncated integer is then used to allocate a buffer. When SQLite then writes the resulting string to the buffer, it uses the… |
| CVE-2025-29088 | Media (5.5) | 0.21% | — | 10 abr 2025 | In SQLite 3.49.0 before 3.49.1, certain argument values to sqlite3_db_config (in the C-language API) can cause a denial of service (application crash). An sz*nBig multiplication is not cast to a 64-bit integer, and… |
| CVE-2025-29087 | Alta (7.5) | 0.51% | — | 7 abr 2025 | In SQLite 3.44.0 through 3.49.0 before 3.49.1, the concat_ws() SQL function can cause memory to be written beyond the end of a malloc-allocated buffer. If the separator argument is attacker-controlled and has a large… |
| CVE-2024-0232 | Media (5.5) | 0.38% | — | 16 ene 2024 | A heap use-after-free issue has been identified in SQLite in the jsonParseAddNodeArray() function in sqlite3.c. This flaw allows a local attacker to leverage a victim to pass specially crafted malicious input to the… |
| CVE-2023-7104 | Alta (7.3) | 1.2% | — | 29 dic 2023 | A vulnerability was found in SQLite SQLite3 up to 3.43.0 and classified as critical. This issue affects the function sessionReadRecord of the file ext/session/sqlite3session.c of the component make alltest Handler. The… |
| CVE-2021-31239 | Alta (7.5) | 2.2% | — | 9 may 2023 | An issue found in SQLite SQLite3 v.3.35.4 that allows a remote attacker to cause a denial of service via the appendvfs.c function. |
| CVE-2022-46908 | Alta (7.3) | 0.44% | — | 12 dic 2022 | SQLite through 3.40.0, when relying on --safe for execution of an untrusted CLI script, does not properly implement the azProhibitedFunctions protection mechanism, and instead allows UDF functions such as WRITEFILE. |
| CVE-2020-35527 | Crítica (9.8) | 1.2% | — | 1 sept 2022 | In SQLite 3.31.1, there is an out of bounds access problem through ALTER TABLE for views that have a nested FROM clause. |
| CVE-2020-35525 | Alta (7.5) | 1.1% | — | 1 sept 2022 | In SQlite 3.31.1, a potential null pointer derreference was found in the INTERSEC query processing. |
| CVE-2022-35737 | Alta (7.5) | 23% | — | 3 ago 2022 | SQLite 1.0.12 through 3.39.x before 3.39.2 sometimes allows an array-bounds overflow if billions of bytes are used in a string argument to a C API. |
| CVE-2021-45346 | Media (4.3) | 1.6% | — | 14 feb 2022 | A Memory Leak vulnerability exists in SQLite Project SQLite3 3.35.1 and 3.37.0 via maliciously crafted SQL Queries (made via editing the Database File), it is possible to query a record, and leak subsequent bytes of… |
| CVE-2021-36690 | Alta (7.5) | 3.9% | — | 24 ago 2021 | A segmentation fault can occur in the sqlite3.exe command-line component of SQLite 3.36.0 via the idxGetTableInfo function when there is a crafted SQL query. NOTE: the vendor disputes the relevance of this report… |
| CVE-2021-20227 | Media (5.5) | 0.50% | — | 23 mar 2021 | A flaw was found in SQLite's SELECT query functionality (src/select.c). This flaw allows an attacker who is capable of running SQL queries locally on the SQLite database to cause a denial of service or possible code… |
| CVE-2020-15358 | Media (5.5) | 1.0% | — | 27 jun 2020 | In SQLite before 3.32.3, select.c mishandles query-flattener optimization, leading to a multiSelectOrderBy heap overflow because of misuse of transitive properties for constant propagation. |
| CVE-2020-13871 | Alta (7.5) | 4.4% | — | 6 jun 2020 | SQLite 3.32.2 has a use-after-free in resetAccumulator in select.c because the parse tree rewrite for window functions is too late. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.