Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2535▼ 358 respecto a la semana anterior
Críticas / altas1338▲ 66 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 6 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
128 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.9) | 0.24% | — | Sqlite | 29/7/2025 | 17/6/2026 | An integer overflow in the sqlite3KeyInfoFromExprList function in SQLite versions 3.39.2 through 3.41.1 allows an attacker with the ability to execute arbitrary SQL statements to cause a denial of service or disclose sensitive information from process memory via a crafted SELECT statement with a large number of… | |
| Aplazada | Alta (8.6) | 0.16% | — | Signum-net FaraAISqliteAI | 21/7/2025 | 17/6/2026 | Use of hard-coded, the same among all vulnerable installations SQLite credentials vulnerability in SIGNUM-NET FARA allows to read and manipulate local-stored database.This issue affects FARA: through 5.0.80.34. | |
| Analizada | Alta (7.2) | 73% | — | SqliteApple IpadosApple Iphone OSApple Macos+5 | 15/7/2025 | 26/6/2026 | There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corruption issue. We recommend upgrading to version 3.50.2 or above. | |
| Aplazada | Baja (2.9) | 0.25% | — | Libsql Sqlite3 ParserAI | 9/5/2025 | 17/6/2026 | dialect/mod.rs in the libsql-sqlite3-parser crate through 0.13.0 before 14f422a for Rust can crash if the input is not valid UTF-8. | |
| Analizada | Media (6.9) | 0.83% | — | Sqlite | 14/4/2025 | 17/6/2026 | An integer overflow can be triggered in SQLite’s `concat_ws()` function. The resulting, truncated integer is then used to allocate a buffer. When SQLite then writes the resulting string to the buffer, it uses the original, untruncated size and thus a wild Heap Buffer overflow of size ~4GB can be triggered. This can… | |
| Analizada | Media (5.5) | 0.21% | — | Sqlite | 10/4/2025 | 17/6/2026 | In SQLite 3.49.0 before 3.49.1, certain argument values to sqlite3_db_config (in the C-language API) can cause a denial of service (application crash). An sz*nBig multiplication is not cast to a 64-bit integer, and consequently some memory allocations may be incorrect. | |
| Analizada | Alta (7.5) | 0.51% | — | Sqlite | 7/4/2025 | 17/6/2026 | In SQLite 3.44.0 through 3.49.0 before 3.49.1, the concat_ws() SQL function can cause memory to be written beyond the end of a malloc-allocated buffer. If the separator argument is attacker-controlled and has a large string (e.g., 2MB or more), an integer overflow occurs in calculating the size of the result buffer,… | |
| Analizada | Media (5.5) | 0.44% | — | Asg017 Sqlite-vec | 25/9/2024 | 17/6/2026 | sqlite-vec v0.1.1 was discovered to contain a heap buffer overflow via the npy_token_next function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted file. | |
| Aplazada | Crítica (9.8) | 0.89% | — | SqlitedictAI | 18/9/2024 | 17/6/2026 | Insecure deserialization in sqlitedict up to v2.1.0 allows attackers to execute arbitrary code. | |
| Modificada | Media (5.5) | 0.38% | — | SqliteRedhat Enterprise LinuxFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora | 16/1/2024 | 17/6/2026 | A heap use-after-free issue has been identified in SQLite in the jsonParseAddNodeArray() function in sqlite3.c. This flaw allows a local attacker to leverage a victim to pass specially crafted malicious input to the application, potentially causing a crash and leading to a denial of service. | |
| Modificada | Alta (7.3) | 1.2% | — | SqliteFedoraproject Fedora | 29/12/2023 | 17/6/2026 | A vulnerability was found in SQLite SQLite3 up to 3.43.0 and classified as critical. This issue affects the function sessionReadRecord of the file ext/session/sqlite3session.c of the component make alltest Handler. The manipulation leads to heap-based buffer overflow. It is recommended to apply a patch to fix this… | |
| Modificada | Crítica (9.8) | 1.6% | — | Sqlite Jdbc Project Sqlite Jdbc | 23/5/2023 | 17/6/2026 | SQLite JDBC is a library for accessing and creating SQLite database files in Java. Sqlite-jdbc addresses a remote code execution vulnerability via JDBC URL. This issue impacting versions 3.6.14.1 through 3.41.2.1 and has been fixed in version 3.41.2.2. | |
| Modificada | Alta (7.5) | 2.2% | — | Sqlite | 9/5/2023 | 17/6/2026 | An issue found in SQLite SQLite3 v.3.35.4 that allows a remote attacker to cause a denial of service via the appendvfs.c function. | |
| Modificada | Media (5.5) | 0.32% | — | Ghost Sqlite3 | 11/4/2023 | 17/6/2026 | Buffer Overflow vulnerability found in SQLite3 v.3.27.1 and before allows a local attacker to cause a denial of service via a crafted script. | |
| Modificada | Crítica (9.8) | 2.4% | — | Ghost Sqlite3 | 16/3/2023 | 17/6/2026 | A code execution vulnerability exists in the Statement Bindings functionality of Ghost Foundation node-sqlite3 5.1.1. A specially-crafted Javascript file can lead to arbitrary code execution. An attacker can provide malicious input to trigger this vulnerability. | |
| Modificada | Alta (7.3) | 0.44% | — | Sqlite | 12/12/2022 | 17/6/2026 | SQLite through 3.40.0, when relying on --safe for execution of an untrusted CLI script, does not properly implement the azProhibitedFunctions protection mechanism, and instead allows UDF functions such as WRITEFILE. | |
| Modificada | Crítica (9.8) | 1.2% | — | SqliteNetapp Ontap Select Deploy Administration Utility | 1/9/2022 | 17/6/2026 | In SQLite 3.31.1, there is an out of bounds access problem through ALTER TABLE for views that have a nested FROM clause. | |
| Modificada | Alta (7.5) | 1.1% | — | Sqlite | 1/9/2022 | 17/6/2026 | In SQlite 3.31.1, a potential null pointer derreference was found in the INTERSEC query processing. | |
| Modificada | Alta (7.5) | 23% | — | SqliteNetapp Ontap Select Deploy Administration UtilitySplunk Universal Forwarder | 3/8/2022 | 17/6/2026 | SQLite 1.0.12 through 3.39.x before 3.39.2 sometimes allows an array-bounds overflow if billions of bytes are used in a string argument to a C API. | |
| Modificada | Alta (7.5) | 2.2% | — | Ghost Sqlite3 | 1/5/2022 | 17/6/2026 | The package sqlite3 before 5.0.3 are vulnerable to Denial of Service (DoS) which will invoke the toString function of the passed parameter. If passed an invalid Function object it will throw and crash the V8 engine. | |
| Modificada | Media (4.3) | 1.6% | — | SqliteNetapp Ontap Select Deploy Administration Utility | 14/2/2022 | 17/6/2026 | A Memory Leak vulnerability exists in SQLite Project SQLite3 3.35.1 and 3.37.0 via maliciously crafted SQL Queries (made via editing the Database File), it is possible to query a record, and leak subsequent bytes of memory that extend beyond the record, which could let a malicious user obtain sensitive information.… | |
| Modificada | Alta (7.5) | 1.2% | — | Rusqlite Project Rusqlite | 26/12/2021 | 17/6/2026 | An issue was discovered in the rusqlite crate 0.25.x before 0.25.4 and 0.26.x before 0.26.2 for Rust. update_hook has a use-after-free. | |
| Modificada | Alta (7.5) | 1.2% | — | Rusqlite Project Rusqlite | 26/12/2021 | 17/6/2026 | An issue was discovered in the rusqlite crate 0.25.x before 0.25.4 and 0.26.x before 0.26.2 for Rust. rollback_hook has a use-after-free. | |
| Modificada | Alta (7.5) | 1.2% | — | Rusqlite Project Rusqlite | 26/12/2021 | 17/6/2026 | An issue was discovered in the rusqlite crate 0.25.x before 0.25.4 and 0.26.x before 0.26.2 for Rust. commit_hook has a use-after-free. | |
| Modificada | Alta (7.5) | 1.2% | — | Rusqlite Project Rusqlite | 26/12/2021 | 17/6/2026 | An issue was discovered in the rusqlite crate 0.25.x before 0.25.4 and 0.26.x before 0.26.2 for Rust. create_collation has a use-after-free. |