Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2537▼ 360 respecto a la semana anterior
Críticas / altas1344▲ 80 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

128 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.2%—Rusqlite Project Rusqlite26/12/202117/6/2026
An issue was discovered in the rusqlite crate 0.25.x before 0.25.4 and 0.26.x before 0.26.2 for Rust. create_window_function has a use-after-free.
ModificadaAlta (7.5)1.2%—Rusqlite Project Rusqlite26/12/202117/6/2026
An issue was discovered in the rusqlite crate 0.25.x before 0.25.4 and 0.26.x before 0.26.2 for Rust. create_aggregate_function has a use-after-free.
ModificadaAlta (7.5)1.2%—Rusqlite Project Rusqlite26/12/202117/6/2026
An issue was discovered in the rusqlite crate 0.25.x before 0.25.4 and 0.26.x before 0.26.2 for Rust. create_scalar_function has a use-after-free.
ModificadaAlta (8.8)0.48%—Sqlite-web Project Sqlite-web8/9/202117/6/2026
This affects all versions of package sqlite-web. The SQL dashboard area allows sensitive actions to be performed without validating that the request originated from the application. This could enable an attacker to trick a user into performing these actions unknowingly through a Cross Site Request Forgery (CSRF)…
ModificadaAlta (7.5)3.9%—SqliteOracle ZFS Storage Appliance KITApple Iphone OSApple Macos+224/8/202117/6/2026
A segmentation fault can occur in the sqlite3.exe command-line component of SQLite 3.36.0 via the idxGetTableInfo function when there is a crafted SQL query. NOTE: the vendor disputes the relevance of this report because a sqlite3.exe user already has full privileges (e.g., is intentionally allowed to execute…
ModificadaMedia (5.5)0.50%—SqliteOracle Communications Network Charging AND ControlEnterprise Manager FOR Oracle DatabaseOracle JD Edwards Enterpriseone Tools+323/3/202117/6/2026
A flaw was found in SQLite's SELECT query functionality (src/select.c). This flaw allows an attacker who is capable of running SQL queries locally on the SQLite database to cause a denial of service or possible code execution by triggering a use-after-free. The highest threat from this vulnerability is to system…
ModificadaCrítica (9.8)1.8%—Rusqlite Project Rusqlite31/12/202017/6/2026
An issue was discovered in the rusqlite crate before 0.23.0 for Rust. Memory safety can be violated because sessions.rs has a use-after-free.
ModificadaCrítica (9.8)1.7%—Rusqlite Project Rusqlite31/12/202017/6/2026
An issue was discovered in the rusqlite crate before 0.23.0 for Rust. Memory safety can be violated via the repr(Rust) type.
ModificadaAlta (8.1)1.0%—Rusqlite Project Rusqlite31/12/202017/6/2026
An issue was discovered in the rusqlite crate before 0.23.0 for Rust. Memory safety can be violated via an Auxdata API data race.
ModificadaCrítica (9.8)1.7%—Rusqlite Project Rusqlite31/12/202017/6/2026
An issue was discovered in the rusqlite crate before 0.23.0 for Rust. Memory safety can be violated via an Auxdata API use-after-free.
ModificadaCrítica (9.8)1.7%—Rusqlite Project Rusqlite31/12/202017/6/2026
An issue was discovered in the rusqlite crate before 0.23.0 for Rust. Memory safety can be violated because rusqlite::trace::log mishandles format strings.
ModificadaCrítica (9.8)1.7%—Rusqlite Project Rusqlite31/12/202017/6/2026
An issue was discovered in the rusqlite crate before 0.23.0 for Rust. Memory safety can be violated via UnlockNotification.
ModificadaCrítica (9.8)1.7%—Rusqlite Project Rusqlite31/12/202017/6/2026
An issue was discovered in the rusqlite crate before 0.23.0 for Rust. Memory safety can be violated via create_module.
ModificadaCrítica (9.8)1.7%—Rusqlite Project Rusqlite31/12/202017/6/2026
An issue was discovered in the rusqlite crate before 0.23.0 for Rust. Memory safety can be violated via VTab / VTabCursor.
ModificadaMedia (5.5)1.0%—SqliteCanonical Ubuntu LinuxApple IcloudApple Ipados+1227/6/202017/6/2026
In SQLite before 3.32.3, select.c mishandles query-flattener optimization, leading to a multiSelectOrderBy heap overflow because of misuse of transitive properties for constant propagation.
ModificadaAlta (7.5)4.4%—SqliteFedoraproject FedoraDebian LinuxOracle Communications Messaging Server+86/6/202017/6/2026
SQLite 3.32.2 has a use-after-free in resetAccumulator in select.c because the parse tree rewrite for window functions is too late.
ModificadaMedia (5.5)0.57%—SqliteFedoraproject FedoraCanonical Ubuntu LinuxNetapp Cloud Backup+827/5/202017/6/2026
ext/fts3/fts3_snippet.c in SQLite before 3.32.0 has a NULL pointer dereference via a crafted matchinfo() query.
ModificadaMedia (5.5)0.62%—SqliteFedoraproject FedoraCanonical Ubuntu LinuxNetapp Cloud Backup+1427/5/202017/6/2026
SQLite before 3.32.0 allows a virtual table to be renamed to the name of one of its shadow tables, related to alter.c and build.c.
ModificadaAlta (7)1.0%—SqliteFedoraproject FedoraCanonical Ubuntu LinuxNetapp Cloud Backup+1527/5/202017/6/2026
ext/fts3/fts3.c in SQLite before 3.32.0 has a use-after-free in fts3EvalNextRow, related to the snippet feature.
ModificadaMedia (5.5)0.64%—SqliteFedoraproject Fedora24/5/202017/6/2026
SQLite through 3.32.0 has a segmentation fault in sqlite3ExprCodeTarget in expr.c.
ModificadaMedia (5.5)1.0%—SqliteDebian LinuxFedoraproject FedoraCanonical Ubuntu Linux+1124/5/202017/6/2026
SQLite through 3.32.0 has an integer overflow in sqlite3_str_vappendf in printf.c.
ModificadaAlta (7)0.31%—Opensuse Backports SLEFedoraproject FedoraSqliteodbc Project Sqliteodbc30/4/202017/6/2026
SQLiteODBC 0.9996, as packaged for certain Linux distributions as 0.9996-4, has a race condition leading to root privilege escalation because any user can replace a /tmp/sqliteodbc$$ file with new contents that cause loading of an arbitrary library.
ModificadaCrítica (9.8)7.6%—SqliteNetapp Ontap Select Deploy Administration UtilityOracle Communications Network Charging AND ControlOracle Enterprise Manager OPS Center+89/4/202017/6/2026
In SQLite through 3.31.1, the ALTER TABLE implementation has a use-after-free, as demonstrated by an ORDER BY clause that belongs to a compound SELECT statement.
ModificadaAlta (7.5)4.3%—SqliteNetapp Ontap Select Deploy Administration UtilityDebian LinuxCanonical Ubuntu Linux+149/4/202017/6/2026
SQLite through 3.31.1 allows attackers to cause a denial of service (segmentation fault) via a malformed window-function query because the AggInfo object's initialization is mishandled.
ModificadaAlta (7.5)3.7%—SqliteNetapp Cloud BackupCanonical Ubuntu LinuxSiemens Sinec Infrastructure Network Services+721/2/202017/6/2026
In SQLite 3.31.1, isAuxiliaryVtabOperator allows attackers to trigger a NULL pointer dereference and segmentation fault because of generated column optimizations.