Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2537▼ 360 respecto a la semana anterior
Críticas / altas1344▲ 80 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
128 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.2% | — | Rusqlite Project Rusqlite | 26/12/2021 | 17/6/2026 | An issue was discovered in the rusqlite crate 0.25.x before 0.25.4 and 0.26.x before 0.26.2 for Rust. create_window_function has a use-after-free. | |
| Modificada | Alta (7.5) | 1.2% | — | Rusqlite Project Rusqlite | 26/12/2021 | 17/6/2026 | An issue was discovered in the rusqlite crate 0.25.x before 0.25.4 and 0.26.x before 0.26.2 for Rust. create_aggregate_function has a use-after-free. | |
| Modificada | Alta (7.5) | 1.2% | — | Rusqlite Project Rusqlite | 26/12/2021 | 17/6/2026 | An issue was discovered in the rusqlite crate 0.25.x before 0.25.4 and 0.26.x before 0.26.2 for Rust. create_scalar_function has a use-after-free. | |
| Modificada | Alta (8.8) | 0.48% | — | Sqlite-web Project Sqlite-web | 8/9/2021 | 17/6/2026 | This affects all versions of package sqlite-web. The SQL dashboard area allows sensitive actions to be performed without validating that the request originated from the application. This could enable an attacker to trick a user into performing these actions unknowingly through a Cross Site Request Forgery (CSRF)… | |
| Modificada | Alta (7.5) | 3.9% | — | SqliteOracle ZFS Storage Appliance KITApple Iphone OSApple Macos+2 | 24/8/2021 | 17/6/2026 | A segmentation fault can occur in the sqlite3.exe command-line component of SQLite 3.36.0 via the idxGetTableInfo function when there is a crafted SQL query. NOTE: the vendor disputes the relevance of this report because a sqlite3.exe user already has full privileges (e.g., is intentionally allowed to execute… | |
| Modificada | Media (5.5) | 0.50% | — | SqliteOracle Communications Network Charging AND ControlEnterprise Manager FOR Oracle DatabaseOracle JD Edwards Enterpriseone Tools+3 | 23/3/2021 | 17/6/2026 | A flaw was found in SQLite's SELECT query functionality (src/select.c). This flaw allows an attacker who is capable of running SQL queries locally on the SQLite database to cause a denial of service or possible code execution by triggering a use-after-free. The highest threat from this vulnerability is to system… | |
| Modificada | Crítica (9.8) | 1.8% | — | Rusqlite Project Rusqlite | 31/12/2020 | 17/6/2026 | An issue was discovered in the rusqlite crate before 0.23.0 for Rust. Memory safety can be violated because sessions.rs has a use-after-free. | |
| Modificada | Crítica (9.8) | 1.7% | — | Rusqlite Project Rusqlite | 31/12/2020 | 17/6/2026 | An issue was discovered in the rusqlite crate before 0.23.0 for Rust. Memory safety can be violated via the repr(Rust) type. | |
| Modificada | Alta (8.1) | 1.0% | — | Rusqlite Project Rusqlite | 31/12/2020 | 17/6/2026 | An issue was discovered in the rusqlite crate before 0.23.0 for Rust. Memory safety can be violated via an Auxdata API data race. | |
| Modificada | Crítica (9.8) | 1.7% | — | Rusqlite Project Rusqlite | 31/12/2020 | 17/6/2026 | An issue was discovered in the rusqlite crate before 0.23.0 for Rust. Memory safety can be violated via an Auxdata API use-after-free. | |
| Modificada | Crítica (9.8) | 1.7% | — | Rusqlite Project Rusqlite | 31/12/2020 | 17/6/2026 | An issue was discovered in the rusqlite crate before 0.23.0 for Rust. Memory safety can be violated because rusqlite::trace::log mishandles format strings. | |
| Modificada | Crítica (9.8) | 1.7% | — | Rusqlite Project Rusqlite | 31/12/2020 | 17/6/2026 | An issue was discovered in the rusqlite crate before 0.23.0 for Rust. Memory safety can be violated via UnlockNotification. | |
| Modificada | Crítica (9.8) | 1.7% | — | Rusqlite Project Rusqlite | 31/12/2020 | 17/6/2026 | An issue was discovered in the rusqlite crate before 0.23.0 for Rust. Memory safety can be violated via create_module. | |
| Modificada | Crítica (9.8) | 1.7% | — | Rusqlite Project Rusqlite | 31/12/2020 | 17/6/2026 | An issue was discovered in the rusqlite crate before 0.23.0 for Rust. Memory safety can be violated via VTab / VTabCursor. | |
| Modificada | Media (5.5) | 1.0% | — | SqliteCanonical Ubuntu LinuxApple IcloudApple Ipados+12 | 27/6/2020 | 17/6/2026 | In SQLite before 3.32.3, select.c mishandles query-flattener optimization, leading to a multiSelectOrderBy heap overflow because of misuse of transitive properties for constant propagation. | |
| Modificada | Alta (7.5) | 4.4% | — | SqliteFedoraproject FedoraDebian LinuxOracle Communications Messaging Server+8 | 6/6/2020 | 17/6/2026 | SQLite 3.32.2 has a use-after-free in resetAccumulator in select.c because the parse tree rewrite for window functions is too late. | |
| Modificada | Media (5.5) | 0.57% | — | SqliteFedoraproject FedoraCanonical Ubuntu LinuxNetapp Cloud Backup+8 | 27/5/2020 | 17/6/2026 | ext/fts3/fts3_snippet.c in SQLite before 3.32.0 has a NULL pointer dereference via a crafted matchinfo() query. | |
| Modificada | Media (5.5) | 0.62% | — | SqliteFedoraproject FedoraCanonical Ubuntu LinuxNetapp Cloud Backup+14 | 27/5/2020 | 17/6/2026 | SQLite before 3.32.0 allows a virtual table to be renamed to the name of one of its shadow tables, related to alter.c and build.c. | |
| Modificada | Alta (7) | 1.0% | — | SqliteFedoraproject FedoraCanonical Ubuntu LinuxNetapp Cloud Backup+15 | 27/5/2020 | 17/6/2026 | ext/fts3/fts3.c in SQLite before 3.32.0 has a use-after-free in fts3EvalNextRow, related to the snippet feature. | |
| Modificada | Media (5.5) | 0.64% | — | SqliteFedoraproject Fedora | 24/5/2020 | 17/6/2026 | SQLite through 3.32.0 has a segmentation fault in sqlite3ExprCodeTarget in expr.c. | |
| Modificada | Media (5.5) | 1.0% | — | SqliteDebian LinuxFedoraproject FedoraCanonical Ubuntu Linux+11 | 24/5/2020 | 17/6/2026 | SQLite through 3.32.0 has an integer overflow in sqlite3_str_vappendf in printf.c. | |
| Modificada | Alta (7) | 0.31% | — | Opensuse Backports SLEFedoraproject FedoraSqliteodbc Project Sqliteodbc | 30/4/2020 | 17/6/2026 | SQLiteODBC 0.9996, as packaged for certain Linux distributions as 0.9996-4, has a race condition leading to root privilege escalation because any user can replace a /tmp/sqliteodbc$$ file with new contents that cause loading of an arbitrary library. | |
| Modificada | Crítica (9.8) | 7.6% | — | SqliteNetapp Ontap Select Deploy Administration UtilityOracle Communications Network Charging AND ControlOracle Enterprise Manager OPS Center+8 | 9/4/2020 | 17/6/2026 | In SQLite through 3.31.1, the ALTER TABLE implementation has a use-after-free, as demonstrated by an ORDER BY clause that belongs to a compound SELECT statement. | |
| Modificada | Alta (7.5) | 4.3% | — | SqliteNetapp Ontap Select Deploy Administration UtilityDebian LinuxCanonical Ubuntu Linux+14 | 9/4/2020 | 17/6/2026 | SQLite through 3.31.1 allows attackers to cause a denial of service (segmentation fault) via a malformed window-function query because the AggInfo object's initialization is mishandled. | |
| Modificada | Alta (7.5) | 3.7% | — | SqliteNetapp Cloud BackupCanonical Ubuntu LinuxSiemens Sinec Infrastructure Network Services+7 | 21/2/2020 | 17/6/2026 | In SQLite 3.31.1, isAuxiliaryVtabOperator allows attackers to trigger a NULL pointer dereference and segmentation fault because of generated column optimizations. |