Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2535▼ 358 respecto a la semana anterior
Críticas / altas1338▲ 66 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 6 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

128 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.9)0.24%—Sqlite29/7/202517/6/2026
An integer overflow in the sqlite3KeyInfoFromExprList function in SQLite versions 3.39.2 through 3.41.1 allows an attacker with the ability to execute arbitrary SQL statements to cause a denial of service or disclose sensitive information from process memory via a crafted SELECT statement with a large number of…
AplazadaAlta (8.6)0.16%—Signum-net FaraAISqliteAI21/7/202517/6/2026
Use of hard-coded, the same among all vulnerable installations SQLite credentials vulnerability in SIGNUM-NET FARA allows to read and manipulate local-stored database.This issue affects FARA: through 5.0.80.34.
AnalizadaAlta (7.2)73%—SqliteApple IpadosApple Iphone OSApple Macos+515/7/202526/6/2026
There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corruption issue. We recommend upgrading to version 3.50.2 or above.
AplazadaBaja (2.9)0.25%—Libsql Sqlite3 ParserAI9/5/202517/6/2026
dialect/mod.rs in the libsql-sqlite3-parser crate through 0.13.0 before 14f422a for Rust can crash if the input is not valid UTF-8.
AnalizadaMedia (6.9)0.83%—Sqlite14/4/202517/6/2026
An integer overflow can be triggered in SQLite’s `concat_ws()` function. The resulting, truncated integer is then used to allocate a buffer. When SQLite then writes the resulting string to the buffer, it uses the original, untruncated size and thus a wild Heap Buffer overflow of size ~4GB can be triggered. This can…
AnalizadaMedia (5.5)0.21%—Sqlite10/4/202517/6/2026
In SQLite 3.49.0 before 3.49.1, certain argument values to sqlite3_db_config (in the C-language API) can cause a denial of service (application crash). An sz*nBig multiplication is not cast to a 64-bit integer, and consequently some memory allocations may be incorrect.
AnalizadaAlta (7.5)0.51%—Sqlite7/4/202517/6/2026
In SQLite 3.44.0 through 3.49.0 before 3.49.1, the concat_ws() SQL function can cause memory to be written beyond the end of a malloc-allocated buffer. If the separator argument is attacker-controlled and has a large string (e.g., 2MB or more), an integer overflow occurs in calculating the size of the result buffer,…
AnalizadaMedia (5.5)0.44%—Asg017 Sqlite-vec25/9/202417/6/2026
sqlite-vec v0.1.1 was discovered to contain a heap buffer overflow via the npy_token_next function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted file.
AplazadaCrítica (9.8)0.89%—SqlitedictAI18/9/202417/6/2026
Insecure deserialization in sqlitedict up to v2.1.0 allows attackers to execute arbitrary code.
ModificadaMedia (5.5)0.38%—SqliteRedhat Enterprise LinuxFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora16/1/202417/6/2026
A heap use-after-free issue has been identified in SQLite in the jsonParseAddNodeArray() function in sqlite3.c. This flaw allows a local attacker to leverage a victim to pass specially crafted malicious input to the application, potentially causing a crash and leading to a denial of service.
ModificadaAlta (7.3)1.2%—SqliteFedoraproject Fedora29/12/202317/6/2026
A vulnerability was found in SQLite SQLite3 up to 3.43.0 and classified as critical. This issue affects the function sessionReadRecord of the file ext/session/sqlite3session.c of the component make alltest Handler. The manipulation leads to heap-based buffer overflow. It is recommended to apply a patch to fix this…
ModificadaCrítica (9.8)1.6%—Sqlite Jdbc Project Sqlite Jdbc23/5/202317/6/2026
SQLite JDBC is a library for accessing and creating SQLite database files in Java. Sqlite-jdbc addresses a remote code execution vulnerability via JDBC URL. This issue impacting versions 3.6.14.1 through 3.41.2.1 and has been fixed in version 3.41.2.2.
ModificadaAlta (7.5)2.2%—Sqlite9/5/202317/6/2026
An issue found in SQLite SQLite3 v.3.35.4 that allows a remote attacker to cause a denial of service via the appendvfs.c function.
ModificadaMedia (5.5)0.32%—Ghost Sqlite311/4/202317/6/2026
Buffer Overflow vulnerability found in SQLite3 v.3.27.1 and before allows a local attacker to cause a denial of service via a crafted script.
ModificadaCrítica (9.8)2.4%—Ghost Sqlite316/3/202317/6/2026
A code execution vulnerability exists in the Statement Bindings functionality of Ghost Foundation node-sqlite3 5.1.1. A specially-crafted Javascript file can lead to arbitrary code execution. An attacker can provide malicious input to trigger this vulnerability.
ModificadaAlta (7.3)0.44%—Sqlite12/12/202217/6/2026
SQLite through 3.40.0, when relying on --safe for execution of an untrusted CLI script, does not properly implement the azProhibitedFunctions protection mechanism, and instead allows UDF functions such as WRITEFILE.
ModificadaCrítica (9.8)1.2%—SqliteNetapp Ontap Select Deploy Administration Utility1/9/202217/6/2026
In SQLite 3.31.1, there is an out of bounds access problem through ALTER TABLE for views that have a nested FROM clause.
ModificadaAlta (7.5)1.1%—Sqlite1/9/202217/6/2026
In SQlite 3.31.1, a potential null pointer derreference was found in the INTERSEC query processing.
ModificadaAlta (7.5)23%—SqliteNetapp Ontap Select Deploy Administration UtilitySplunk Universal Forwarder3/8/202217/6/2026
SQLite 1.0.12 through 3.39.x before 3.39.2 sometimes allows an array-bounds overflow if billions of bytes are used in a string argument to a C API.
ModificadaAlta (7.5)2.2%—Ghost Sqlite31/5/202217/6/2026
The package sqlite3 before 5.0.3 are vulnerable to Denial of Service (DoS) which will invoke the toString function of the passed parameter. If passed an invalid Function object it will throw and crash the V8 engine.
ModificadaMedia (4.3)1.6%—SqliteNetapp Ontap Select Deploy Administration Utility14/2/202217/6/2026
A Memory Leak vulnerability exists in SQLite Project SQLite3 3.35.1 and 3.37.0 via maliciously crafted SQL Queries (made via editing the Database File), it is possible to query a record, and leak subsequent bytes of memory that extend beyond the record, which could let a malicious user obtain sensitive information.…
ModificadaAlta (7.5)1.2%—Rusqlite Project Rusqlite26/12/202117/6/2026
An issue was discovered in the rusqlite crate 0.25.x before 0.25.4 and 0.26.x before 0.26.2 for Rust. update_hook has a use-after-free.
ModificadaAlta (7.5)1.2%—Rusqlite Project Rusqlite26/12/202117/6/2026
An issue was discovered in the rusqlite crate 0.25.x before 0.25.4 and 0.26.x before 0.26.2 for Rust. rollback_hook has a use-after-free.
ModificadaAlta (7.5)1.2%—Rusqlite Project Rusqlite26/12/202117/6/2026
An issue was discovered in the rusqlite crate 0.25.x before 0.25.4 and 0.26.x before 0.26.2 for Rust. commit_hook has a use-after-free.
ModificadaAlta (7.5)1.2%—Rusqlite Project Rusqlite26/12/202117/6/2026
An issue was discovered in the rusqlite crate 0.25.x before 0.25.4 and 0.26.x before 0.26.2 for Rust. create_collation has a use-after-free.