CVE Tools

Sqlite

73 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Sqlite, a product in the databases space. Use it to gauge the current risk picture and drill into individual advisories.

Sqlite CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Sqlite CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-043
2025-050
2025-060
2025-072
2025-080
2025-090
2025-100
2025-110
2025-120
2026-010
2026-020
2026-031
2026-040
2026-050
2026-062
2026-070
2026-080
2026-090

Severity

How the 73 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical1318%
  • High3953%
  • Medium2027%
  • Low11%

Latest CVEs

The 15 most recently published vulnerabilities affecting Sqlite.

  1. CVE-2026-11824SQLite before 3.53.2 Heap Buffer Overflow via FTS5 fts5ChunkIterate7.8
  2. CVE-2026-11822SQLite before 3.53.2 Memory Corruption in FTS5 Extension7.8
  3. CVE-2025-70873An information disclosure issue in the zipfileInflate function in the zipfile extension in SQLite v3.51.1 and earlier allows attackers to obtain heap memory via supplying a crafted ZIP file.7.5
  4. CVE-2025-7458SQLite integer overflow in key info allocation may lead to information disclosure.9.1
  5. CVE-2025-6965Integer Truncation on SQLite7.7
  6. CVE-2025-3277An integer overflow can be triggered in SQLite’s `concat_ws()` function. The resulting, truncated integer is then used to allocate a buffer. When SQLite then writes the resulting string to the bu...9.8
  7. CVE-2025-29088In SQLite 3.49.0 before 3.49.1, certain argument values to sqlite3_db_config (in the C-language API) can cause a denial of service (application crash). An sz*nBig multiplication is not cast to a 64...5.6
  8. CVE-2025-29087In SQLite 3.44.0 through 3.49.0 before 3.49.1, the concat_ws() SQL function can cause memory to be written beyond the end of a malloc-allocated buffer. If the separator argument is attacker-control...3.2
  9. CVE-2024-0232Sqlite: use-after-free bug in jsonparseaddnodearray4.7
  10. CVE-2023-7104SQLite SQLite3 make alltest sqlite3session.c sessionReadRecord heap-based overflow5.5
  11. CVE-2021-31239An issue found in SQLite SQLite3 v.3.35.4 that allows a remote attacker to cause a denial of service via the appendvfs.c function.7.5
  12. CVE-2022-46908SQLite through 3.40.0, when relying on --safe for execution of an untrusted CLI script, does not properly implement the azProhibitedFunctions protection mechanism, and instead allows UDF functions ...7.3
  13. CVE-2020-35525In SQlite 3.31.1, a potential null pointer derreference was found in the INTERSEC query processing.7.5
  14. CVE-2020-35527In SQLite 3.31.1, there is an out of bounds access problem through ALTER TABLE for views that have a nested FROM clause.9.8
  15. CVE-2022-35737SQLite 1.0.12 through 3.39.x before 3.39.2 sometimes allows an array-bounds overflow if billions of bytes are used in a string argument to a C API.7.5

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store