CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

Search Vulnerabilities

 Software

Searching vulnerabilities affecting “sqlite”

76 vulnerabilities found for “sqlite”

Page 1 of 4

CVE-2024-46488
MEDIUM5.5

sqlite-vec v0.1.1 was discovered to contain a heap buffer overflow via the npy_token_next function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted file.

asg017 / sqlite-vec
Local
Published Sep 25, 2024
Page 1 of 4
CVE-2024-0232
MEDIUM4.7

A heap use-after-free issue has been identified in SQLite in the jsonParseAddNodeArray() function in sqlite3.c. This flaw allows a local attacker to leverage a victim to pass specially crafted malicious input to the application, potentially causing a crash and leading to a denial of service.

sqlite / sqlite+4
Local
Published Jan 16, 2024
CVE-2023-7104
MEDIUM5.5

A vulnerability was found in SQLite SQLite3 up to 3.43.0 and classified as critical. This issue affects the function sessionReadRecord of the file ext/session/sqlite3session.c of the component make alltest Handler. The manipulation leads to heap-based buffer overflow. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-248999.

sqlite / sqlite+2
Adjacent
Published Dec 29, 2023
CVE-2021-31239
HIGH7.5

An issue found in SQLite SQLite3 v.3.35.4 that allows a remote attacker to cause a denial of service via the appendvfs.c function.

sqlite / sqlite
Network
Published May 9, 2023
CVE-2022-46908
HIGH7.3

SQLite through 3.40.0, when relying on --safe for execution of an untrusted CLI script, does not properly implement the azProhibitedFunctions protection mechanism, and instead allows UDF functions such as WRITEFILE.

sqlite / sqlite
Local
Published Dec 12, 2022
CVE-2020-35525
HIGH7.5

In SQlite 3.31.1, a potential null pointer derreference was found in the INTERSEC query processing.

sqlite / sqlite
Network
Published Sep 1, 2022
CVE-2020-35527
CRITICAL9.8

In SQLite 3.31.1, there is an out of bounds access problem through ALTER TABLE for views that have a nested FROM clause.

sqlite / sqlite+1
Network
Published Sep 1, 2022
CVE-2022-35737
HIGH7.5

SQLite 1.0.12 through 3.39.x before 3.39.2 sometimes allows an array-bounds overflow if billions of bytes are used in a string argument to a C API.

sqlite / sqlite+4
Network
Published Aug 3, 2022
CVE-2021-45346
MEDIUM4.3

A Memory Leak vulnerability exists in SQLite Project SQLite3 3.35.1 and 3.37.0 via maliciously crafted SQL Queries (made via editing the Database File), it is possible to query a record, and leak subsequent bytes of memory that extend beyond the record, which could let a malicious user obtain sensitive information. NOTE: The developer disputes this as a vulnerability stating that If you give SQLite a corrupted database file and submit a query against the database, it might read parts of the database that you did not intend or expect.

sqlite / sqlite+2
Network
Published Feb 14, 2022
CVE-2021-23404
HIGH7.6

This affects all versions of package sqlite-web. The SQL dashboard area allows sensitive actions to be performed without validating that the request originated from the application. This could enable an attacker to trick a user into performing these actions unknowingly through a Cross Site Request Forgery (CSRF) attack.

sqlite-web_project / sqlite-web
Network
Published Sep 8, 2021
CVE-2021-36690
HIGH7.5

A segmentation fault can occur in the sqlite3.exe command-line component of SQLite 3.36.0 via the idxGetTableInfo function when there is a crafted SQL query. NOTE: the vendor disputes the relevance of this report because a sqlite3.exe user already has full privileges (e.g., is intentionally allowed to execute commands). This report does NOT imply any problem in the SQLite library.

sqlite / sqlite+5
Network
Published Aug 24, 2021
CVE-2021-20227
MEDIUM5.5

A flaw was found in SQLite's SELECT query functionality (src/select.c). This flaw allows an attacker who is capable of running SQL queries locally on the SQLite database to cause a denial of service or possible code execution by triggering a use-after-free. The highest threat from this vulnerability is to system availability.

sqlite / sqlite+7
Local
Published Mar 23, 2021
CVE-2020-15358
MEDIUM5.5

In SQLite before 3.32.3, select.c mishandles query-flattener optimization, leading to a multiSelectOrderBy heap overflow because of misuse of transitive properties for constant propagation.

sqlite / sqlite+17
Local
Published Jun 27, 2020
CVE-2020-13871
HIGH7.5

SQLite 3.32.2 has a use-after-free in resetAccumulator in select.c because the parse tree rewrite for window functions is too late.

sqlite / sqlite+12
Network
Published Jun 6, 2020
CVE-2020-13632
MEDIUM5.5

ext/fts3/fts3_snippet.c in SQLite before 3.32.0 has a NULL pointer dereference via a crafted matchinfo() query.

sqlite / sqlite+16
Local
Published May 27, 2020
CVE-2020-13630
HIGH7.0

ext/fts3/fts3.c in SQLite before 3.32.0 has a use-after-free in fts3EvalNextRow, related to the snippet feature.

sqlite / sqlite+23
Local
Published May 27, 2020
CVE-2020-13631
MEDIUM5.5

SQLite before 3.32.0 allows a virtual table to be renamed to the name of one of its shadow tables, related to alter.c and build.c.

sqlite / sqlite+22
Local
Published May 27, 2020
CVE-2020-13434
MEDIUM5.5

SQLite through 3.32.0 has an integer overflow in sqlite3_str_vappendf in printf.c.

sqlite / sqlite+42
Local
Published May 24, 2020
CVE-2020-13435
MEDIUM5.5

SQLite through 3.32.0 has a segmentation fault in sqlite3ExprCodeTarget in expr.c.

sqlite / sqlite+1
Local
Published May 24, 2020
CVE-2017-16048
HIGH7.5

`node-sqlite` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.

node-sqlite_project / node-sqlite
Network
Published Jun 4, 2018