Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3047▲ 440 respecto a la semana anterior
Críticas / altas1452▲ 212 respecto a la semana anterior
Nueva explotación activa (KEV)8▼ 2 respecto a la semana anterior
Sin puntuar (sin CVSS)365▲ 151 respecto a la semana anterior
12 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.61% | — | VendureAIBetter-sqlite3AISql.js SqljsAI | 17/9/2026 | 17/9/2026 | Vendure is an open-source headless commerce platform. Prior to 3.6.5, the public Shop GraphQL API allows an unauthenticated caller to supply a catastrophically backtracking pattern through StringOperators.regex. packages/core/src/service/helpers/list-query-builder/parse-filter-params.ts passes the raw pattern to the… | |
| Analizada | Media (6.1) | 0.58% | — | Dangerblack N8n-node-sqlite3 | 27/8/2026 | 23/9/2026 | n8n-nodes-sqlite3 is a node for operating a local SQLite database from n8n. Prior to 1.0.0, nodes/SqliteNode/v1/SqliteV1.node.ts exposes the db_path database file path as a node parameter that permits data expressions from upstream workflow input. A workflow author who maps untrusted input to db_path can allow a… | |
| Pendiente de análisis | Media (5.8) | 0.10% | — | Linuxfabrik Monitoring-pluginsAIPython Sqlite3AI | 29/7/2026 | 30/7/2026 | Linuxfabrik monitoring-plugins provides Python monitoring plugins for Icinga, Nagios, and related monitoring systems. In version 6.0.0, the logfile check legacy database migration moved a predictable path from /tmp with os.rename() and allowed a local user controlling the plugin account to place a symlink that would… | |
| Pendiente de análisis | Baja (2) | 0.14% | — | Ghost Sqlite3AI | 28/7/2026 | 30/7/2026 | sqlite3 provides Ruby bindings for the SQLite3 embedded database. From 2.1.0 to 2.9.4, the callbacks used for SQLite aggregate functions can be freed while still referenced during aggregation, resulting in a use-after-free. This issue is fixed in version 2.9.5. | |
| Pendiente de análisis | Baja (2) | 0.14% | — | Ghost Sqlite3AI | 28/7/2026 | 30/7/2026 | sqlite3 provides Ruby bindings for the SQLite3 embedded database. In version 2.9.4 and earlier, redefining a SQLite function with a different arity frees the previously registered function handler while SQLite may still reference it, resulting in a use-after-free. This issue is fixed in version 2.9.5. | |
| Aplazada | Baja (2.1) | 0.41% | — | VETAISqlite3AI | 29/9/2025 | 17/6/2026 | vet is an open source software supply chain security tool. Versions 1.12.4 and below are vulnerable to a DNS rebinding attack due to lack of HTTP Host and Origin header validation. Data from the vet scan sqlite3 database may be exposed to remote attackers when vet is used as an MCP server in SSE mode with default… | |
| Aplazada | Baja (2.9) | 0.25% | — | Libsql Sqlite3 ParserAI | 9/5/2025 | 17/6/2026 | dialect/mod.rs in the libsql-sqlite3-parser crate through 0.13.0 before 14f422a for Rust can crash if the input is not valid UTF-8. | |
| Modificada | Media (5.5) | 0.32% | — | Ghost Sqlite3 | 11/4/2023 | 17/6/2026 | Buffer Overflow vulnerability found in SQLite3 v.3.27.1 and before allows a local attacker to cause a denial of service via a crafted script. | |
| Modificada | Crítica (9.8) | 2.4% | — | Ghost Sqlite3 | 16/3/2023 | 17/6/2026 | A code execution vulnerability exists in the Statement Bindings functionality of Ghost Foundation node-sqlite3 5.1.1. A specially-crafted Javascript file can lead to arbitrary code execution. An attacker can provide malicious input to trigger this vulnerability. | |
| Modificada | Alta (7.5) | 2.2% | — | Ghost Sqlite3 | 1/5/2022 | 17/6/2026 | The package sqlite3 before 5.0.3 are vulnerable to Denial of Service (DoS) which will invoke the toString function of the passed parameter. If passed an invalid Function object it will throw and crash the V8 engine. | |
| Modificada | Alta (8.1) | 1.8% | — | Mapbox Npm-test-sqlite3-trunk | 4/6/2018 | 17/6/2026 | The npm-test-sqlite3-trunk module provides asynchronous, non-blocking SQLite3 bindings. npm-test-sqlite3-trunk downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested resources with an attacker controlled… | |
| Modificada | Baja (2.1) | 0.38% | — | Rubyforge Rubygem-sqlite3Novell Suse Linux Enterprise | 13/5/2011 | 16/6/2026 | The sqlite3-ruby gem in the rubygem-sqlite3 package before 1.2.4-0.5.1 in SUSE Linux Enterprise (SLE) 11 SP1 uses weak permissions for unspecified files, which allows local users to gain privileges via unknown vectors. |