Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 82 respecto a la semana anterior
Críticas / altas1416▲ 189 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)100▼ 400 respecto a la semana anterior
128 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.61% | — | VendureAIBetter-sqlite3AISql.js SqljsAI | 17/9/2026 | 17/9/2026 | Vendure is an open-source headless commerce platform. Prior to 3.6.5, the public Shop GraphQL API allows an unauthenticated caller to supply a catastrophically backtracking pattern through StringOperators.regex. packages/core/src/service/helpers/list-query-builder/parse-filter-params.ts passes the raw pattern to the… | |
| Aplazada | Media (4.4) | 0.19% | — | Outerbase StudioAIPostgresqlAIMysqlAISqliteAI | 15/9/2026 | 30/9/2026 | Outerbase Studio is a lightweight browser-based database GUI supporting PostgreSQL, MySQL, and SQLite. In version 0.10.2 and earlier, TextComponent in src/components/chart/index.tsx renders unsanitized Text Widget content through dangerouslySetInnerHTML, allowing injected markup with script-capable event handlers to… | |
| Aplazada | Alta (7.5) | 0.97% | — | AnyqueryAIHashicorp Go-getterAISqliteAI | 14/9/2026 | 30/9/2026 | Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server exposes file-backed SQLite virtual table modules such as csv_reader and log_reader through its MySQL-compatible server port without authentication, authorization, or directory restrictions. A remote attacker can use SQLite CREATE… | |
| Aplazada | Crítica (9.1) | 0.97% | — | AnyqueryAISqliteAI | 14/9/2026 | 30/9/2026 | Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server forwards unauthenticated SQL from its MySQL-compatible server port to SQLite without restricting ATTACH DATABASE filesystem targets. A remote attacker can select any path writable by the Anyquery server process, cause SQLite to… | |
| Aplazada | Baja (2.1) | 0.20% | — | Ash-project ASH SqliteAI | 30/8/2026 | 1/9/2026 | Improper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sqlite allows an attacker who controls a get_path/2 segment to traverse into nested JSON the application never exposed, disclosing private or sensitive? embedded fields. AshSqlite.SqlImplementation builds the SQLite… | |
| Analizada | Media (6.1) | 0.58% | — | Dangerblack N8n-node-sqlite3 | 27/8/2026 | 23/9/2026 | n8n-nodes-sqlite3 is a node for operating a local SQLite database from n8n. Prior to 1.0.0, nodes/SqliteNode/v1/SqliteV1.node.ts exposes the db_path database file path as a node parameter that permits data expressions from upstream workflow input. A workflow author who maps untrusted input to db_path can allow a… | |
| Aplazada | Media (4) | 0.19% | — | SqliteAI | 25/8/2026 | 9/9/2026 | Buffer Overflow vulnerability in SQLite affected version source snapshots/builds containing Fossil check-in 8bdc0d485e3ad0c7a1e818da66f106951d496b05cbe61d12c2c448f2f24b6d5d (Git mirror 169f68ed88b34cb68f720191c64c058f2ccec508, 2026-03-11) and later snapshots/builds allows an attacker to cause a denial of service via… | |
| Pendiente de análisis | Media (5.3) | 0.36% | — | Langchain Langgraph Checkpoint PostgresAILangchain Langgraph Checkpoint SqliteAI | 6/8/2026 | 10/9/2026 | LangGraph Checkpoint Postgres and SQLite Checkpoint are the Postgres and SQLite implementations of LangGraph's checkpoint saver. Prior to 3.1.1, the langgraph-checkpoint-postgres and langgraph-checkpoint-sqlite packages persisted hierarchical namespaces as a dot joined string and scoped reads by matching that string… | |
| Pendiente de análisis | Media (5.8) | 0.10% | — | Linuxfabrik Monitoring-pluginsAIPython Sqlite3AI | 29/7/2026 | 30/7/2026 | Linuxfabrik monitoring-plugins provides Python monitoring plugins for Icinga, Nagios, and related monitoring systems. In version 6.0.0, the logfile check legacy database migration moved a predictable path from /tmp with os.rename() and allowed a local user controlling the plugin account to place a symlink that would… | |
| Pendiente de análisis | Baja (2) | 0.14% | — | Ghost Sqlite3AI | 28/7/2026 | 30/7/2026 | sqlite3 provides Ruby bindings for the SQLite3 embedded database. From 2.1.0 to 2.9.4, the callbacks used for SQLite aggregate functions can be freed while still referenced during aggregation, resulting in a use-after-free. This issue is fixed in version 2.9.5. | |
| Pendiente de análisis | Baja (2) | 0.14% | — | Ghost Sqlite3AI | 28/7/2026 | 30/7/2026 | sqlite3 provides Ruby bindings for the SQLite3 embedded database. In version 2.9.4 and earlier, redefining a SQLite function with a different arity frees the previously registered function handler while SQLite may still reference it, resulting in a use-after-free. This issue is fixed in version 2.9.5. | |
| Aplazada | Crítica (9.3) | 0.52% | — | SAP Cloud Application Programming ModelAICap-js Db-serviceAISqliteAISupabase PostgresAI | 15/7/2026 | 15/7/2026 | The SAP Cloud Application Programming Model is a tool for building enterprise-grade cloud applications, and cap-js/cds-dbs is the monorepo for SQL database services for that tool. On April 29, 2026, compromised versions of `@cap-js/sqlite@2.2.2`, `@cap-js/postgres@2.2.2`, and `@cap-js/db-service@2.10.1` were… | |
| Pendiente de análisis | Media (6.1) | 0.16% | — | SqliteAIFossilAI | 8/7/2026 | 9/7/2026 | An issue in SQLite before Fossil check-in 869a51ae84df allows a local attacker to obtain sensitive information via the Session Extension changeset concat/changegroup merge path | |
| Pendiente de análisis | Media (5.5) | 0.16% | — | SqliteAI | 8/7/2026 | 9/7/2026 | A NULL pointer dereference in the SQLite Session Extension in SQLite 3.53.1 and SQLite trunk builds before check-in e807d4e3798efd53 allows an attacker who can supply a malformed changeset blob to cause a denial of service. The issue occurs when sqlite3changeset_apply_v3() applies a corrupt changeset and reaches… | |
| Aplazada | Media (5.3) | 0.36% | — | GhostAINodejsAISqliteAIMysqlAI | 24/6/2026 | 25/6/2026 | Ghost is a Node.js content management system. From 5.46.1 until 6.21.2, the validation applied to filters on the public API endpoints could be partially bypassed, making it possible to reveal private fields via a brute force attack. If SQLite was used as the database password hashes were fully accessible. If MySQL was… | |
| Analizada | Alta (8.5) | 0.18% | — | Sqlite | 9/6/2026 | 23/7/2026 | SQLite before 3.53.2 contains a heap-based buffer overflow vulnerability in the FTS5 full-text search extension that allows attackers to cause a crash or execute arbitrary code by supplying a crafted database with malicious continuation page metadata specifying a szLeaf value smaller than 4. Attackers can trigger an… | |
| Analizada | Alta (8.5) | 0.29% | — | Sqlite | 9/6/2026 | 23/7/2026 | SQLite before 3.53.2 contains memory corruption vulnerabilities in the FTS5 full-text search extension that allow attackers to cause process crashes, memory exhaustion, or arbitrary code execution by supplying a crafted database with malformed FTS5 page data. Attackers can trigger an out-of-bounds read in… | |
| Pendiente de análisis | Crítica (9.2) | 0.38% | — | SqliteAIMicrosoft Windows C RuntimeAI | 4/6/2026 | 22/7/2026 | SQLite 'sqldiff.exe' does not securely handle the way the Microsoft Windows C runtime converts Unicode characters to ANSI codepages. An attacker could use the '-L' option to load an arbitrary DLL with a crafted command line argument string that results in command line file arguments being misinterpreted as command… | |
| Analizada | Crítica (9.6) | 1.1% | ⚠ Explotación activa | Tanstack/arktype-adapterTanstack/eslint-plugin-routerTanstack/eslint-plugin-startTanstack/history+167 | 12/5/2026 | 17/6/2026 | On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, but the publish workflow itself was not modified. The… | |
| Aplazada | Media (5.5) | 0.43% | — | Dubydu Sqlite-mcpAI | 28/4/2026 | 24/7/2026 | A security flaw has been discovered in dubydu sqlite-mcp up to 0.1.0. The affected element is the function extract_to_json of the file src/entry.py. Performing a manipulation of the argument output_filename results in sql injection. Remote exploitation of the attack is possible. The exploit has been released to the… | |
| Analizada | Alta (7.5) | 0.30% | — | Sqlite | 12/3/2026 | 17/6/2026 | An information disclosure issue in the zipfileInflate function in the zipfile extension in SQLite v3.51.1 and earlier allows attackers to obtain heap memory via supplying a crafted ZIP file. | |
| Analizada | Alta (7.8) | 2.3% | — | Langchain Langgraph-checkpoint-sqlite | 11/12/2025 | 17/6/2026 | LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, via aiosqlite). Versions 3.0.0 and below are vulnerable to SQL injection through the checkpoint implementation. Checkpoint allows attackers to manipulate SQL queries through metadata filter keys,… | |
| Aplazada | Alta (7.3) | 0.18% | — | Langchain Langgraph-checkpoint-sqliteAILangchainAI | 26/10/2025 | 17/6/2026 | A SQL injection vulnerability exists in the langchain-ai/langchain repository, specifically in the LangGraph's SQLite store implementation. The affected version is langgraph-checkpoint-sqlite 2.0.10. The vulnerability arises from improper handling of filter operators ($eq, $ne, $gt, $lt, $gte, $lte) where direct… | |
| Aplazada | Baja (2.1) | 0.41% | — | VETAISqlite3AI | 29/9/2025 | 17/6/2026 | vet is an open source software supply chain security tool. Versions 1.12.4 and below are vulnerable to a DNS rebinding attack due to lack of HTTP Host and Origin header validation. Data from the vet scan sqlite3 database may be exposed to remote attackers when vet is used as an MCP server in SSE mode with default… | |
| Aplazada | Media (6.9) | 0.35% | — | Sqlite Fts5AI | 8/9/2025 | 17/6/2026 | An integer overflow exists in the FTS5 https://sqlite.org/fts5.html extension. It occurs when the size of an array of tombstone pointers is calculated and truncated into a 32-bit integer. A pointer to partially controlled data can then be written out of bounds. |