<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – SQLite</title>
  <link>https://cvedaily.com/pages/tags/sqlite.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/sqlite.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – SQLite</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:38 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-47179 – Arcane is an interface for managing Docker containers, images, networks, and vol...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-47179</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-47179</guid>
    <pubDate>Fri, 29 May 2026 18:17:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-47179</strong></p>
  <p>Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.4, ProjectService.GetProjectFileContent returns the contents of any Docker Compose include directive declared in a project's compose file before any path-traversal validation runs. Because ProjectService.CreateProject writes attacker-supplied compose content to disk without validating include paths…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-47179">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-45046 – Gryph provides a security layer for AI coding agents. Prior to 0.7.0, Gryph impl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45046</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45046</guid>
    <pubDate>Wed, 27 May 2026 19:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-45046</strong></p>
  <p>Gryph provides a security layer for AI coding agents. Prior to 0.7.0, Gryph implements logging levels that determine what content is logged to a local sqlite database. The README incorrectly mentions that the default log level is minimal while it is standard. Source code review shows sensitive file-write content remains in the stored payload as ContentPreview, OldString, or NewString at the defau…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-212</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45046">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44635 – Kysely is a type-safe TypeScript SQL query builder. From 0.26.0 to 0.28.16, Defa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44635</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44635</guid>
    <pubDate>Wed, 27 May 2026 19:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44635</strong></p>
  <p>Kysely is a type-safe TypeScript SQL query builder. From 0.26.0 to 0.28.16, DefaultQueryCompiler.visitJSONPathLeg does not escape JSON-path metacharacters (., [, ], *, **, ?). When attacker-controlled input flows into eb.ref(col, '->$').key(input) or .at(input) — including type-safe code where the JSON column is shaped like Record<string, T> so K extends string is the inferred type — every dot be…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44635">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41496 – PraisonAI is a multi-agent teams system. Prior to praisonai version 4.6.9 and pr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41496</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41496</guid>
    <pubDate>Fri, 08 May 2026 14:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41496</strong></p>
  <p>PraisonAI is a multi-agent teams system. Prior to praisonai version 4.6.9 and praisonaiagents version 1.6.9, the fix for CVE-2026-40315 added input validation to SQLiteConversationStore only. Nine sibling backends — MySQL, PostgreSQL, async SQLite/MySQL/PostgreSQL, Turso, SingleStore, Supabase, SurrealDB — pass table_prefix straight into f-string SQL. Same root cause, same code pattern, same expl…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41496">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-42238 – Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42238</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42238</guid>
    <pubDate>Mon, 04 May 2026 21:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-42238</strong></p>
  <p>Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.8, nginx-ui exposes a backup restore endpoint (POST /api/restore) that is completely unauthenticated during the first 10 minutes after process startup on any fresh installation. An unauthenticated remote attacker can upload a crafted backup archive that overwrites the application's configuration file (app.ini) and SQL…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42238">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-7206 – A security flaw has been discovered in dubydu sqlite-mcp up to 0.1.0. The affect...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-7206</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-7206</guid>
    <pubDate>Tue, 28 Apr 2026 01:16:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-7206</strong></p>
  <p>A security flaw has been discovered in dubydu sqlite-mcp up to 0.1.0. The affected element is the function extract_to_json of the file src/entry.py. Performing a manipulation of the argument output_filename results in sql injection. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. The patch is named a5580cb992f4f6c308c9ffe6442…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-7206">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41894 – SiYuan is an open-source personal knowledge management system. Prior to 3.6.5, t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41894</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41894</guid>
    <pubDate>Fri, 24 Apr 2026 19:17:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41894</strong></p>
  <p>SiYuan is an open-source personal knowledge management system. Prior to 3.6.5, the fix for CVE-2026-30869 only added a denylist check (IsSensitivePath) but did not address the root cause — a redundant url.PathUnescape() call in serveExport(). An authenticated attacker can use double URL encoding (%252e%252e) to traverse directories and read arbitrary workspace files including the full SQLite data…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41894">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-40887 – Vendure is an open-source headless commerce platform. Starting in version 1.7.4 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40887</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40887</guid>
    <pubDate>Tue, 21 Apr 2026 20:17:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-40887</strong></p>
  <p>Vendure is an open-source headless commerce platform. Starting in version 1.7.4 and prior to versions 2.3.4, 3.5.7, and 3.6.2, an unauthenticated SQL injection vulnerability exists in the Vendure Shop API. A user-controlled query string parameter is interpolated directly into a raw SQL expression without parameterization or validation, allowing an attacker to execute arbitrary SQL against the dat…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40887">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-35465 – SecureDrop Client is a desktop app for journalists to securely communicate with ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-35465</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-35465</guid>
    <pubDate>Sat, 18 Apr 2026 01:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-35465</strong></p>
  <p>SecureDrop Client is a desktop app for journalists to securely communicate with sources and handle submissions on the SecureDrop Workstation. In versions 0.17.4 and below, a compromised SecureDrop Server can achieve code execution on the Client's virtual machine (sd-app) by exploiting improper filename validation in gzip archive extraction, which permits absolute paths and enables overwriting cri…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-36</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-35465">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-40315 – PraisonAI is a multi-agent teams system. Prior to 4.5.133, there is an SQL ident...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40315</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40315</guid>
    <pubDate>Tue, 14 Apr 2026 04:17:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-40315</strong></p>
  <p>PraisonAI is a multi-agent teams system. Prior to 4.5.133, there is an SQL identifier injection vulnerability in SQLiteConversationStore where the table_prefix configuration value is directly concatenated into SQL queries via f-strings without any validation or sanitization. Since SQL identifiers cannot be safely parameterized, an attacker who controls the table_prefix value (e.g., through from_y…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40315">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-14815 – Cleartext Storage of Sensitive Information vulnerability in Mitsubishi Electric ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-14815</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-14815</guid>
    <pubDate>Wed, 08 Apr 2026 14:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-14815</strong></p>
  <p>Cleartext Storage of Sensitive Information vulnerability in Mitsubishi Electric GENESIS64 versions 10.97.3 and prior, Mitsubishi Electric ICONICS Suite versions 10.97.3 and prior, Mitsubishi Electric MobileHMI versions 10.97.3 and prior, Mitsubishi Electric Hyper Historian versions 10.97.3 and prior, Mitsubishi Electric AnalytiX versions 10.97.3 and prior, Mitsubishi Electric GENESIS versions 11.…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-312</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-14815">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-32714 – SciTokens is a reference library for generating and using SciTokens. Prior to ve...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32714</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32714</guid>
    <pubDate>Tue, 31 Mar 2026 03:15:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-32714</strong></p>
  <p>SciTokens is a reference library for generating and using SciTokens. Prior to version 1.9.6, the KeyCache class in scitokens was vulnerable to SQL Injection because it used Python's str.format() to construct SQL queries with user-supplied data (such as issuer and key_id). This allowed an attacker to execute arbitrary SQL commands against the local SQLite database. This issue has been patched in v…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32714">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-31799 – Tautulli is a Python based monitoring and tracking tool for Plex Media Server. F...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31799</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31799</guid>
    <pubDate>Mon, 30 Mar 2026 20:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-31799</strong></p>
  <p>Tautulli is a Python based monitoring and tracking tool for Plex Media Server. From version 2.14.2 to before version 2.17.0 for parameters "before" and "after" and from version 2.1.0-beta to before version 2.17.0 for parameters "section_id" and "user_id", the /api/v2?cmd=get_home_stats endpoint passes the section_id, user_id, before, and after query parameters directly into SQL via Python %-strin…</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31799">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33906 – Ella Core is a 5G core designed for private networks. Prior to version 1.7.0, th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33906</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33906</guid>
    <pubDate>Fri, 27 Mar 2026 21:17:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33906</strong></p>
  <p>Ella Core is a 5G core designed for private networks. Prior to version 1.7.0, the NetworkManager role was granted backup and restore permission. The restore endpoint accepted any valid SQLite file without verifying its contents. A NetworkManager could replace the production database with a tampered copy to escalate to Admin, gaining access to user management, audit logs, debug endpoints, and oper…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33906">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33735 – MyTube is a self-hosted downloader and player for several video websites Prior t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33735</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33735</guid>
    <pubDate>Fri, 27 Mar 2026 01:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33735</strong></p>
  <p>MyTube is a self-hosted downloader and player for several video websites Prior to version 1.8.69, an authorization bypass in the `/api/settings/import-database` endpoint allows attackers with low-privilege credentials to upload and replace the application's SQLite database entirely, leading to a full compromise of the application. The bypass is relevant for other POST routes as well. Version 1.8.…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33735">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-33545 – MobSF is a mobile application security testing tool used. Prior to version 4.4.6...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33545</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33545</guid>
    <pubDate>Thu, 26 Mar 2026 21:17:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-33545</strong></p>
  <p>MobSF is a mobile application security testing tool used. Prior to version 4.4.6, MobSF's `read_sqlite()` function in `mobsf/MobSF/utils.py` (lines 542-566) uses Python string formatting (`%`) to construct SQL queries with table names read from a SQLite database's `sqlite_master` table. When a security analyst uses MobSF to analyze a malicious mobile application containing a crafted SQLite databa…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33545">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33713 – n8n is an open source workflow automation platform. Prior to versions 2.14.1, 2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33713</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33713</guid>
    <pubDate>Wed, 25 Mar 2026 18:16:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33713</strong></p>
  <p>n8n is an open source workflow automation platform. Prior to versions 2.14.1, 2.13.3, and 1.123.26, an authenticated user with permission to create or modify workflows could exploit a SQL injection vulnerability in the Data Table Get node. On default SQLite DB, single statements can be manipulated and the attack surface is practically limited. On PostgreSQL deployments, multi-statement execution…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33713">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-32767 – SiYuan is a personal knowledge management system. Versions 3.6.0 and below conta...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32767</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32767</guid>
    <pubDate>Fri, 20 Mar 2026 01:15:55 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-32767</strong></p>
  <p>SiYuan is a personal knowledge management system. Versions 3.6.0 and below contain an authorization bypass vulnerability in the /api/search/fullTextSearchBlock endpoint. When the method parameter is set to 2, the endpoint passes user-supplied input directly as a raw SQL statement to the underlying SQLite database without any authorization or read-only checks. This allows any authenticated user —…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32767">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32763 – Kysely is a type-safe TypeScript SQL query builder. Versions up to and including...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32763</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32763</guid>
    <pubDate>Fri, 20 Mar 2026 00:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32763</strong></p>
  <p>Kysely is a type-safe TypeScript SQL query builder. Versions up to and including 0.28.11 has a SQL injection vulnerability in JSON path compilation for MySQL and SQLite dialects. The `visitJSONPathLeg()` function appends user-controlled values from `.key()` and `.at()` directly into single-quoted JSON path string literals (`'$.key'`) without escaping single quotes. An attacker can break out of th…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32763">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-31891 – Cockpit is a headless content management system. Any Cockpit CMS instance runnin...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31891</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31891</guid>
    <pubDate>Wed, 18 Mar 2026 04:17:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-31891</strong></p>
  <p>Cockpit is a headless content management system. Any Cockpit CMS instance running version 2.13.4 or earlier with API access enabled is potentially affected by a a SQL Injection vulnerability in the MongoLite Aggregation Optimizer. Any deployment where the `/api/content/aggregate/{model}` endpoint is publicly accessible or reachable by untrusted users may be vulnerable, and attackers in possession…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31891">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-70873 – An information disclosure issue in the zipfileInflate function in the zipfile ex...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-70873</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-70873</guid>
    <pubDate>Thu, 12 Mar 2026 19:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-70873</strong></p>
  <p>An information disclosure issue in the zipfileInflate function in the zipfile extension in SQLite v3.51.1 and earlier allows attackers to obtain heap memory via supplying a crafted ZIP file.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-244</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-70873">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-2752 – Navtor NavBox allows information disclosure via the /api/ais-data endpoint. A re...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2752</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2752</guid>
    <pubDate>Fri, 06 Mar 2026 15:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-2752</strong></p>
  <p>Navtor NavBox allows information disclosure via the /api/ais-data endpoint. A remote, unauthenticated attacker can send crafted requests to trigger an unhandled exception, causing the server to return verbose .NET stack traces. These error messages expose internal class names, method calls, and third-party library references (e.g., System.Data.SQLite), which may assist attackers in mapping the ap…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-209</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2752">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-25180 – Maitra 1.7.2 contains an sql injection vulnerability that allows authenticated a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25180</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25180</guid>
    <pubDate>Fri, 06 Mar 2026 13:16:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-25180</strong></p>
  <p>Maitra 1.7.2 contains an sql injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the mailid parameter in outmail and inmail modules. Attackers can also download the SQLite database file directly from the application directory to extract sensitive mail tracking data and credentials.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25180">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-28277 – LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28277</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28277</guid>
    <pubDate>Thu, 05 Mar 2026 20:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-28277</strong></p>
  <p>LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, via aiosqlite). In version 1.0.9 and prior, LangGraph checkpointers can load msgpack-encoded checkpoints that reconstruct Python objects during deserialization. If an attacker can modify checkpoint data in the backing store (for example, after a database compromise or other priv…</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28277">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-27510 – Unitree Go2 firmware versions 1.1.7 through 1.1.11, when used with the Unitree G...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27510</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27510</guid>
    <pubDate>Thu, 26 Feb 2026 20:31:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-27510</strong></p>
  <p>Unitree Go2 firmware versions 1.1.7 through 1.1.11, when used with the Unitree Go2 Android application (com.unitree.doggo2), are vulnerable to remote code execution due to missing integrity protection and validation of user-created programmes. The Android application stores programs in a local SQLite database (unitree_go2.db, table dog_programme) and transmits the programme_text content, includin…</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-345</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27510">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-27794 – LangGraph Checkpoint defines the base interface for LangGraph checkpointers. Pri...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27794</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27794</guid>
    <pubDate>Wed, 25 Feb 2026 18:23:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-27794</strong></p>
  <p>LangGraph Checkpoint defines the base interface for LangGraph checkpointers. Prior to version 4.0.0, a Remote Code Execution vulnerability exists in LangGraph's caching layer when applications enable cache backends that inherit from `BaseCache` and opt nodes into caching via `CachePolicy`. Prior to `langgraph-checkpoint` 4.0.0, `BaseCache` defaults to `JsonPlusSerializer(pickle_fallback=True)`. W…</p>
  <p><strong>CVSS:</strong> 6.6 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27794">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-2250 – The /dbviewer/ web endpoint in METIS WIC devices is exposed without authenticati...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2250</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2250</guid>
    <pubDate>Wed, 11 Feb 2026 15:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-2250</strong></p>
  <p>The /dbviewer/ web endpoint in METIS WIC devices is exposed without authentication. A remote attacker can access and export the internal telemetry SQLite database containing sensitive operational data. Additionally, the application is configured with debug mode enabled, causing malformed requests to return verbose Django tracebacks that disclose backend source code, local file paths, and system c…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-215</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2250">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-25574 – Payload is a free and open source headless content management system. Prior to 3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25574</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25574</guid>
    <pubDate>Fri, 06 Feb 2026 22:16:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-25574</strong></p>
  <p>Payload is a free and open source headless content management system. Prior to 3.74.0, a cross-collection Insecure Direct Object Reference (IDOR) vulnerability exists in the payload-preferences internal collection. In multi-auth collection environments using Postgres or SQLite with default serial/auto-increment IDs, authenticated users from one auth collection can read and delete preferences belo…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-639</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25574">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-69981 – FUXA v1.2.7 contains an Unrestricted File Upload vulnerability in the `/api/uplo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-69981</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-69981</guid>
    <pubDate>Tue, 03 Feb 2026 18:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-69981</strong></p>
  <p>FUXA v1.2.7 contains an Unrestricted File Upload vulnerability in the `/api/upload` API endpoint. The endpoint lacks authentication mechanisms, allowing unauthenticated remote attackers to upload arbitrary files. This can be exploited to overwrite critical system files (such as the SQLite user database) to gain administrative access, or to upload malicious scripts to execute arbitrary code.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-69981">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-59105 – With physical access to the device and enough time an attacker can desolder the ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-59105</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-59105</guid>
    <pubDate>Mon, 26 Jan 2026 10:16:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-59105</strong></p>
  <p>With physical access to the device and enough time an attacker can desolder the flash memory, modify it and then reinstall it because of missing encryption. Thus, essential files, such as "/etc/passwd", as well as stored certificates, cryptographic keys, stored PINs and so on can be modified and read, in order to gain SSH root access on the Linux-based K7 model. On the Windows CE based K5 model,…</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-312</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-59105">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-59100 – The web interface offers a functionality to export the internal SQLite database...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-59100</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-59100</guid>
    <pubDate>Mon, 26 Jan 2026 10:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-59100</strong></p>
  <p>The web interface offers a functionality to export the internal SQLite database. After executing the database export, an automatic download is started and the device reboots. After rebooting, the exported database is deleted and cannot be accessed anymore. However, it was noticed that sometimes the device does not reboot and therefore the exported database is not deleted, or the device reboots an…</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-59100">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-59099 – The Access Manager is using the open source web server CompactWebServer written ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-59099</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-59099</guid>
    <pubDate>Mon, 26 Jan 2026 10:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-59099</strong></p>
  <p>The Access Manager is using the open source web server CompactWebServer written in C#. This web server is affected by a path traversal vulnerability, which allows an attacker to directly access files via simple GET requests without prior authentication.   Hence, it is possible to retrieve all files stored on the file system, including the SQLite database Database.sq3, containing badge information…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-35</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-59099">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-21696 – Wings is the server control plane for Pterodactyl, a free, open-source game serv...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21696</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-21696</guid>
    <pubDate>Mon, 19 Jan 2026 20:15:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-21696</strong></p>
  <p>Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Starting in version 1.7.0 and prior to version 1.12.0, Wings does not consider SQLite max parameter limit when processing activity log entries allowing for low privileged user to trigger a condition that floods the panel with activity records. After Wings sends activity logs to the panel it delete…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21696">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-23838 – Tandoor Recipes is a recipe manager than can be installed with the Nix package m...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-23838</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-23838</guid>
    <pubDate>Mon, 19 Jan 2026 19:16:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-23838</strong></p>
  <p>Tandoor Recipes is a recipe manager than can be installed with the Nix package manager. Starting in version 23.05 and prior to version 26.05, when using the default configuration of Tandoor Recipes, specifically using SQLite and default `MEDIA_ROOT`, the full database file may be externally accessible, potentially on the Internet. The root cause is that the NixOS module configures the working dir…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-538</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-23838">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-25279 – FaceSentry Access Control System 6.4.8 contains a cleartext password storage vul...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25279</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25279</guid>
    <pubDate>Thu, 08 Jan 2026 00:15:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-25279</strong></p>
  <p>FaceSentry Access Control System 6.4.8 contains a cleartext password storage vulnerability that allows attackers to access unencrypted credentials in the device's SQLite database. Attackers can directly read sensitive login information stored in /faceGuard/database/FaceSentryWeb.sqlite without additional authentication.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-312</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25279">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-15153 – A weakness has been identified in PbootCMS up to 3.2.12. Impacted is an unknown ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-15153</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-15153</guid>
    <pubDate>Sun, 28 Dec 2025 21:15:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-15153</strong></p>
  <p>A weakness has been identified in PbootCMS up to 3.2.12. Impacted is an unknown function of the file /data/pbootcms.db of the component SQLite Database. Executing a manipulation can lead to files or directories accessible. It is possible to launch the attack remotely. Attacks of this nature are highly complex. The exploitability is considered difficult. The exploit has been made available to the…</p>
  <p><strong>CVSS:</strong> 3.7 · <strong>CWE:</strong> CWE-425</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-15153">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-34179 – NetSupport Manager &lt; 14.12.0001 contains an unauthenticated SQL injection vulner...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-34179</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-34179</guid>
    <pubDate>Mon, 15 Dec 2025 15:15:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-34179</strong></p>
  <p>NetSupport Manager < 14.12.0001 contains an unauthenticated SQL injection vulnerability in its Connectivity Server/Gateway HTTPS request handling. The server evaluates request URIs using an unsanitized SQLite query against the FileLinks table in gateway.db. By injecting SQL through the LinkName/URI value, a remote attacker can control the FileName field used by the server to read and return files…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-34179">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-67644 – LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-67644</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-67644</guid>
    <pubDate>Thu, 11 Dec 2025 00:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-67644</strong></p>
  <p>LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, via aiosqlite). Versions 3.0.0 and below are vulnerable to SQL injection through the checkpoint implementation. Checkpoint allows attackers to manipulate SQL queries through metadata filter keys, affecting applications that accept untrusted metadata filter keys (not just filter…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-67644">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-64439 – LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-64439</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-64439</guid>
    <pubDate>Fri, 07 Nov 2025 21:15:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-64439</strong></p>
  <p>LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, via aiosqlite). In versions 2.1.2 and below, the JsonPlusSerializer (used as the default serialization protocol for all checkpointing) contains a Remote Code Execution (RCE) vulnerability when deserializing payloads saved in the "json" serialization mode. By default, the seriali…</p>
  <p><strong>CVSS:</strong> 7.4 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-64439">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-64104 – LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-64104</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-64104</guid>
    <pubDate>Wed, 29 Oct 2025 19:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-64104</strong></p>
  <p>LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, via aiosqlite). Prior to 2.0.11, LangGraph's SQLite store implementation contains SQL injection vulnerabilities using direct string concatenation without proper parameterization, allowing attackers to inject arbitrary SQL and bypass access controls. This vulnerability is fixed i…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-64104">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-8709 – A SQL injection vulnerability exists in the langchain-ai/langchain repository, s...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-8709</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-8709</guid>
    <pubDate>Sun, 26 Oct 2025 06:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-8709</strong></p>
  <p>A SQL injection vulnerability exists in the langchain-ai/langchain repository, specifically in the LangGraph's SQLite store implementation. The affected version is langgraph-checkpoint-sqlite 2.0.10. The vulnerability arises from improper handling of filter operators ($eq, $ne, $gt, $lt, $gte, $lte) where direct string concatenation is used without proper parameterization. This allows attackers t…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-8709">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-52099 – Integer Overflow vulnerability in SQLite SQLite3 v.3.50.0 allows a remote attack...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-52099</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-52099</guid>
    <pubDate>Fri, 24 Oct 2025 21:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-52099</strong></p>
  <p>Integer Overflow vulnerability in SQLite SQLite3 v.3.50.0 allows a remote attacker to cause a denial of service via the setupLookaside function</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-52099">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-61679 – Anyquery is an SQL query engine built on top of SQLite. Versions 0.4.3 and below...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-61679</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-61679</guid>
    <pubDate>Fri, 03 Oct 2025 22:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-61679</strong></p>
  <p>Anyquery is an SQL query engine built on top of SQLite. Versions 0.4.3 and below allow attackers who have already gained access to localhost, even with low privileges, to use the http server through the port unauthenticated, and access private integration data like emails, without any warning of a foreign login from the provider. This issue is fixed in version 0.4.4.</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61679">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-58761 – Tautulli is a Python based monitoring and tracking tool for Plex Media Server. T...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-58761</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-58761</guid>
    <pubDate>Tue, 09 Sep 2025 20:15:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-58761</strong></p>
  <p>Tautulli is a Python based monitoring and tracking tool for Plex Media Server. The `real_pms_image_proxy` endpoint in Tautulli v2.15.3 and prior is vulnerable to path traversal, allowing unauthenticated attackers to read arbitrary files from the application server's filesystem. The `real_pms_image_proxy` is used to fetch an image directly from the backing Plex Media Server. The image to be fetche…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-27</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58761">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-58760 – Tautulli is a Python based monitoring and tracking tool for Plex Media Server. T...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-58760</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-58760</guid>
    <pubDate>Tue, 09 Sep 2025 20:15:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-58760</strong></p>
  <p>Tautulli is a Python based monitoring and tracking tool for Plex Media Server. The `/image` API endpoint in Tautulli v2.15.3 and earlier is vulnerable to path traversal, allowing unauthenticated attackers to read arbitrary files from the application server's filesystem. In Tautulli, the `/image` API endpoint is used to serve static images from the application's data directory to users. This endpo…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-23</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58760">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-7709 – An integer overflow exists in the  FTS5 https://sqlite.org/fts5.html  extension...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-7709</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-7709</guid>
    <pubDate>Mon, 08 Sep 2025 15:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-7709</strong></p>
  <p>An integer overflow exists in the  FTS5 https://sqlite.org/fts5.html  extension. It occurs when the size of an array of tombstone pointers is calculated and truncated into a 32-bit integer. A pointer to partially controlled data can then be written out of bounds.</p>
  <p><strong>CVSS:</strong> 6.9 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-7709">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-57141 – rsbi-os 4.7 is vulnerable to Remote Code Execution (RCE) in sqlite-jdbc.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-57141</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-57141</guid>
    <pubDate>Mon, 08 Sep 2025 15:15:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-57141</strong></p>
  <p>rsbi-os 4.7 is vulnerable to Remote Code Execution (RCE) in sqlite-jdbc.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-57141">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-57806 – Local Deep Research is an AI-powered research assistant for deep, iterative rese...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-57806</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-57806</guid>
    <pubDate>Wed, 03 Sep 2025 01:15:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-57806</strong></p>
  <p>Local Deep Research is an AI-powered research assistant for deep, iterative research. Versions 0.2.0 through 0.6.7 stored confidential information, including API keys, in a local SQLite database without encryption. This behavior was not clearly documented outside of the database architecture page. Users were not given the ability to configure the database location, allowing anyone with access to…</p>
  <p><strong>CVSS:</strong> 6.9 · <strong>CWE:</strong> CWE-312</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-57806">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-4644 – A Session Fixation vulnerability existed in Payload's SQLite adapter due to iden...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-4644</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-4644</guid>
    <pubDate>Fri, 29 Aug 2025 10:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-4644</strong></p>
  <p>A Session Fixation vulnerability existed in Payload's SQLite adapter due to identifier reuse during account creation. A malicious attacker could create a new account, save its JSON Web Token (JWT), and then delete the account, which did not invalidate the JWT. As a result, the next newly created user would receive the same identifier, allowing the attacker to reuse the JWT to authenticate and per…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-384</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-4644">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-50984 – diskover-web v2.3.0 Community Edition is vulnerable to multiple boolean-based bl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-50984</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-50984</guid>
    <pubDate>Wed, 27 Aug 2025 16:15:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-50984</strong></p>
  <p>diskover-web v2.3.0 Community Edition is vulnerable to multiple boolean-based blind SQL injection flaws in its Elasticsearch configuration form. Unsanitized user input in POST parameters such as ES_PASS, ES_MAXSIZE, ES_TRANSLOGSIZE, ES_TIMEOUT, ES_USER, ES_HOST, ES_PORT, ES_SCROLLSIZE, ES_CHUNKSIZE and others can be crafted to inject arbitrary SQLite expressions wrapped in JSON functions. By expl…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-50984">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-50983 – SQL Injection vulnerability exists in the sortKey parameter of the GET /api/v1/w...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-50983</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-50983</guid>
    <pubDate>Wed, 27 Aug 2025 16:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-50983</strong></p>
  <p>SQL Injection vulnerability exists in the sortKey parameter of the GET /api/v1/wanted/cutoff API endpoint in readarr 0.4.15.2787. The endpoint fails to properly sanitize user-supplied input, allowing attackers to inject and execute arbitrary SQL commands against the backend SQLite database. Sqlmap confirmed exploitation via stacked queries, demonstrating that the parameter can be abused to run ar…</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-50983">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-7458 – An integer overflow in the sqlite3KeyInfoFromExprList function in SQLite version...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-7458</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-7458</guid>
    <pubDate>Tue, 29 Jul 2025 13:15:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-7458</strong></p>
  <p>An integer overflow in the sqlite3KeyInfoFromExprList function in SQLite versions 3.39.2 through 3.41.1 allows an attacker with the ability to execute arbitrary SQL statements to cause a denial of service or disclose sensitive information from process memory via a crafted SELECT statement with a large number of expressions in the ORDER BY clause.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-7458">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-54379 – LF Edge eKuiper is a lightweight IoT data analytics and stream processing engine...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54379</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54379</guid>
    <pubDate>Thu, 24 Jul 2025 23:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-54379</strong></p>
  <p>LF Edge eKuiper is a lightweight IoT data analytics and stream processing engine running on resource-constraint edge devices. In versions before 2.2.1, there is a critical SQL Injection vulnerability in the getLast API functionality of the eKuiper project. This flaw allows unauthenticated remote attackers to execute arbitrary SQL statements on the underlying SQLite database by manipulating the ta…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54379">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-4049 – Use of hard-coded, the same among all vulnerable installations SQLite credential...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-4049</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-4049</guid>
    <pubDate>Mon, 21 Jul 2025 08:15:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-4049</strong></p>
  <p>Use of hard-coded, the same among all vulnerable installations SQLite credentials vulnerability in SIGNUM-NET FARA allows to read and manipulate local-stored database.This issue affects FARA: through 5.0.80.34.</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-798</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-4049">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-6230 – A SQL injection vulnerability was reported in Lenovo Vantage that could allow a ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-6230</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-6230</guid>
    <pubDate>Thu, 17 Jul 2025 20:15:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-6230</strong></p>
  <p>A SQL injection vulnerability was reported in Lenovo Vantage that could allow a local attacker to modify the local SQLite database and execute limited SQLite commands.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-6230">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-6965 – There exists a vulnerability in SQLite versions before 3.50.2 where the number o...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-6965</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-6965</guid>
    <pubDate>Tue, 15 Jul 2025 14:15:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-6965</strong></p>
  <p>There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corruption issue. We recommend upgrading to version 3.50.2 or above.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-197</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-6965">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-53549 – The Matrix Rust SDK is a collection of libraries that make it easier to build Ma...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-53549</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-53549</guid>
    <pubDate>Thu, 10 Jul 2025 19:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-53549</strong></p>
  <p>The Matrix Rust SDK is a collection of libraries that make it easier to build Matrix clients in Rust. An SQL injection vulnerability in the EventCache::find_event_with_relations method of matrix-sdk 0.11 and 0.12 allows malicious room members to execute arbitrary SQL commands in Matrix clients that directly pass relation types provided by those room members into this method, when used with the de…</p>
  <p><strong>CVSS:</strong> 5.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53549">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-5154 – A vulnerability, which was classified as problematic, was found in PhonePe App 2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-5154</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-5154</guid>
    <pubDate>Sun, 25 May 2025 19:15:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-5154</strong></p>
  <p>A vulnerability, which was classified as problematic, was found in PhonePe App 25.03.21.0 on Android. Affected is an unknown function of the file /data/data/com.phonepe.app/databases/ of the component SQLite Database. The manipulation leads to cleartext storage in a file or on disk. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used.</p>
  <p><strong>CVSS:</strong> 2.3 · <strong>CWE:</strong> CWE-312</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-5154">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-3277 – An integer overflow can be triggered in SQLite’s `concat_ws()` function. The res...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-3277</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-3277</guid>
    <pubDate>Mon, 14 Apr 2025 17:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-3277</strong></p>
  <p>An integer overflow can be triggered in SQLite’s `concat_ws()` function. The resulting, truncated integer is then used to allocate a buffer. When SQLite then writes the resulting string to the buffer, it uses the original, untruncated size and thus a wild Heap Buffer overflow of size ~4GB can be triggered. This can result in arbitrary code execution.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-3277">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-29088 – In SQLite 3.49.0 before 3.49.1, certain argument values to sqlite3_db_config (in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-29088</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-29088</guid>
    <pubDate>Thu, 10 Apr 2025 14:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-29088</strong></p>
  <p>In SQLite 3.49.0 before 3.49.1, certain argument values to sqlite3_db_config (in the C-language API) can cause a denial of service (application crash). An sz*nBig multiplication is not cast to a 64-bit integer, and consequently some memory allocations may be incorrect.</p>
  <p><strong>CVSS:</strong> 5.6 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-29088">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-29087 – In SQLite 3.44.0 through 3.49.0 before 3.49.1, the concat_ws() SQL function can ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-29087</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-29087</guid>
    <pubDate>Mon, 07 Apr 2025 20:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-29087</strong></p>
  <p>In SQLite 3.44.0 through 3.49.0 before 3.49.1, the concat_ws() SQL function can cause memory to be written beyond the end of a malloc-allocated buffer. If the separator argument is attacker-controlled and has a large string (e.g., 2MB or more), an integer overflow occurs in calculating the size of the result buffer, and thus malloc may not allocate enough memory.</p>
  <p><strong>CVSS:</strong> 3.2 · <strong>CWE:</strong> CWE-190</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-29087">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-11042 – In invoke-ai/invokeai version v5.0.2, the web API `POST /api/v1/images/delete` i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-11042</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-11042</guid>
    <pubDate>Thu, 20 Mar 2025 10:15:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-11042</strong></p>
  <p>In invoke-ai/invokeai version v5.0.2, the web API `POST /api/v1/images/delete` is vulnerable to Arbitrary File Deletion. This vulnerability allows unauthorized attackers to delete arbitrary files on the server, potentially including critical or sensitive system files such as SSH keys, SQLite databases, and configuration files. This can impact the integrity and availability of applications relying…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-73</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-11042">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-2265 – The password of a web user in "Sante PACS Server.exe" is zero-padded to 0x2000 b...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-2265</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-2265</guid>
    <pubDate>Thu, 13 Mar 2025 17:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-2265</strong></p>
  <p>The password of a web user in "Sante PACS Server.exe" is zero-padded to 0x2000 bytes, SHA1-hashed, base64-encoded, and stored in the USER table in the SQLite database HTTP.db. However, the number of hash bytes encoded and stored is truncated if the hash contains a zero byte</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-916</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-2265">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-26794 – Exim 4.98 before 4.98.1, when SQLite hints and ETRN serialization are used, allo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-26794</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-26794</guid>
    <pubDate>Fri, 21 Feb 2025 13:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-26794</strong></p>
  <p>Exim 4.98 before 4.98.1, when SQLite hints and ETRN serialization are used, allows remote SQL injection. (Resolving SQL injection requires an update to 4.99.1 in certain non-default rate-limit configurations.)</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-26794">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-25224 – The LuxCal Web Calendar prior to 5.3.3M (MySQL version) and prior to 5.3.3L (SQL...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-25224</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-25224</guid>
    <pubDate>Tue, 18 Feb 2025 01:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-25224</strong></p>
  <p>The LuxCal Web Calendar prior to 5.3.3M (MySQL version) and prior to 5.3.3L (SQLite version) contains a missing authentication vulnerability in dloader.php. If this vulnerability is exploited, arbitrary files on a server may be obtained.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-25224">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-25223 – The LuxCal Web Calendar prior to 5.3.3M (MySQL version) and prior to 5.3.3L (SQL...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-25223</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-25223</guid>
    <pubDate>Tue, 18 Feb 2025 01:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-25223</strong></p>
  <p>The LuxCal Web Calendar prior to 5.3.3M (MySQL version) and prior to 5.3.3L (SQLite version) contains a path traversal vulnerability in dloader.php. If this vulnerability is exploited, arbitrary files on a server may be obtained.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-25223">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-25222 – The LuxCal Web Calendar prior to 5.3.3M (MySQL version) and prior to 5.3.3L (SQL...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-25222</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-25222</guid>
    <pubDate>Tue, 18 Feb 2025 01:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-25222</strong></p>
  <p>The LuxCal Web Calendar prior to 5.3.3M (MySQL version) and prior to 5.3.3L (SQLite version) contains an SQL injection vulnerability in retrieve.php. If this vulnerability is exploited, information in a database may be deleted, altered, or retrieved.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-25222">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-25221 – The LuxCal Web Calendar prior to 5.3.3M (MySQL version) and prior to 5.3.3L (SQL...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-25221</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-25221</guid>
    <pubDate>Tue, 18 Feb 2025 01:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-25221</strong></p>
  <p>The LuxCal Web Calendar prior to 5.3.3M (MySQL version) and prior to 5.3.3L (SQLite version) contains an SQL injection vulnerability in pdf.php. If this vulnerability is exploited, information in a database may be deleted, altered, or retrieved.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-25221">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-31631 – In PHP versions 8.0.* before 8.0.27, 8.1.* before 8.1.15, 8.2.* before 8.2.2 whe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-31631</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-31631</guid>
    <pubDate>Wed, 12 Feb 2025 22:15:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-31631</strong></p>
  <p>In PHP versions 8.0.* before 8.0.27, 8.1.* before 8.1.15, 8.2.* before 8.2.2 when using PDO::quote() function to quote user-supplied data for SQLite, supplying an overly long string may cause the driver to incorrectly quote the data, which may further lead to SQL injection vulnerabilities.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-31631">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-51748 – Kanboard is project management software that focuses on the Kanban methodology. ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-51748</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-51748</guid>
    <pubDate>Mon, 11 Nov 2024 20:15:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-51748</strong></p>
  <p>Kanboard is project management software that focuses on the Kanban methodology. An authenticated Kanboard admin can run arbitrary php code on the server in combination with a file write possibility. The user interface language is determined and loaded by the setting `application_language` in the `settings` table. Thus, an attacker who can upload a modified sqlite.db through the dedicated feature,…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-51748">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-51747 – Kanboard is project management software that focuses on the Kanban methodology. ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-51747</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-51747</guid>
    <pubDate>Mon, 11 Nov 2024 20:15:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-51747</strong></p>
  <p>Kanboard is project management software that focuses on the Kanban methodology. An authenticated Kanboard admin can read and delete arbitrary files from the server. File attachments, that are viewable or downloadable in Kanboard are resolved through its `path` entry in the `project_has_files`  SQLite db. Thus, an attacker who can upload a modified sqlite.db through the dedicated feature, can set…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-51747">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-47881 – OpenRefine is a free, open source tool for working with messy data. Starting in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47881</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47881</guid>
    <pubDate>Thu, 24 Oct 2024 21:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-47881</strong></p>
  <p>OpenRefine is a free, open source tool for working with messy data. Starting in version 3.4-beta and prior to version 3.8.3, in the `database` extension, the "enable_load_extension" property can be set for the SQLite integration, enabling an attacker to load (local or remote) extension DLLs and so run arbitrary code on the server. The attacker needs to have network access to the OpenRefine instan…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47881">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-47692 – In the Linux kernel, the following vulnerability has been resolved:

nfsd: retur...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-47692</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-47692</guid>
    <pubDate>Mon, 21 Oct 2024 12:15:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-47692</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  nfsd: return -EINVAL when namelen is 0  When we have a corrupted main.sqlite in /var/lib/nfs/nfsdcld/, it may result in namelen being 0, which will cause memdup_user() to return ZERO_SIZE_PTR. When we access the name.data that has been assigned the value of ZERO_SIZE_PTR in nfs4_client_to_reclaim(), null pointer dereference is t…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-47692">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-6971 – A path traversal vulnerability exists in the parisneo/lollms-webui repository, s...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-6971</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-6971</guid>
    <pubDate>Fri, 11 Oct 2024 13:15:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-6971</strong></p>
  <p>A path traversal vulnerability exists in the parisneo/lollms-webui repository, specifically in the `lollms_file_system.py` file. The functions `add_rag_database`, `toggle_mount_rag_database`, and `vectorize_folder` do not implement security measures such as `sanitize_path_from_endpoint` or `sanitize_path`. This allows an attacker to perform vectorize operations on `.sqlite` files in any directory…</p>
  <p><strong>CVSS:</strong> 4.4 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-6971">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-46488 – sqlite-vec v0.1.1 was discovered to contain a heap buffer overflow via the npy_t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-46488</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-46488</guid>
    <pubDate>Wed, 25 Sep 2024 18:15:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-46488</strong></p>
  <p>sqlite-vec v0.1.1 was discovered to contain a heap buffer overflow via the npy_token_next function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted file.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-46488">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-8877 – Improper neutralization of special elements results in a SQL Injection vulnerabi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-8877</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-8877</guid>
    <pubDate>Wed, 25 Sep 2024 01:15:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-8877</strong></p>
  <p>Improper neutralization of special elements results in a SQL Injection vulnerability in Riello Netman 204. It is only limited to the SQLite database of measurement data.This issue affects Netman 204: through 4.05.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-8877">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-44739 – Sourcecodester Simple Forum Website v1.0 has a SQL injection vulnerability in /p...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-44739</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-44739</guid>
    <pubDate>Fri, 06 Sep 2024 13:15:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-44739</strong></p>
  <p>Sourcecodester Simple Forum Website v1.0 has a SQL injection vulnerability in /php-sqlite-forum/?page=manage_user&id=.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-44739">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-45256 – An arbitrary file write issue in the exfiltration endpoint in BYOB (Build Your O...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-45256</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-45256</guid>
    <pubDate>Mon, 26 Aug 2024 07:15:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-45256</strong></p>
  <p>An arbitrary file write issue in the exfiltration endpoint in BYOB (Build Your Own Botnet) 2.0 allows attackers to overwrite SQLite databases and bypass authentication via an unauthenticated HTTP request with a crafted parameter. This occurs in file_add in api/files/routes.py.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-45256">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-7009 – Unsanitized user-input in Calibre &lt;= 7.15.0 allow users with permissions to perf...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-7009</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-7009</guid>
    <pubDate>Tue, 06 Aug 2024 04:16:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-7009</strong></p>
  <p>Unsanitized user-input in Calibre <= 7.15.0 allow users with permissions to perform full-text searches to achieve SQL injection on the SQLite database.</p>
  <p><strong>CVSS:</strong> 4.2 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-7009">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-4888 – BerriAI's litellm, in its latest version, is vulnerable to arbitrary file deleti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-4888</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-4888</guid>
    <pubDate>Thu, 06 Jun 2024 19:16:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-4888</strong></p>
  <p>BerriAI's litellm, in its latest version, is vulnerable to arbitrary file deletion due to improper input validation on the `/audio/transcriptions` endpoint. An attacker can exploit this vulnerability by sending a specially crafted request that includes a file path to the server, which then deletes the specified file without proper authorization or validation. This vulnerability is present in the…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-4888">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-34226 – SQL injection vulnerability in /php-sqlite-vms/?page=manage_visitor&amp;id=1 in Sour...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-34226</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-34226</guid>
    <pubDate>Tue, 14 May 2024 15:38:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-34226</strong></p>
  <p>SQL injection vulnerability in /php-sqlite-vms/?page=manage_visitor&id=1 in SourceCodester Visitor Management System 1.0 allow attackers to execute arbitrary SQL commands via the id parameters.</p>
  <p><strong>CVSS:</strong> 9.4 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-34226">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-32003 – wn-dusk-plugin (Dusk plugin) is a plugin which integrates Laravel Dusk browser t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-32003</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-32003</guid>
    <pubDate>Fri, 12 Apr 2024 21:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-32003</strong></p>
  <p>wn-dusk-plugin (Dusk plugin) is a plugin which integrates Laravel Dusk browser testing into Winter CMS. The Dusk plugin provides some special routes as part of its testing framework to allow a browser environment (such as headless Chrome) to act as a user in the Backend or User plugin without having to go through authentication. This route is `[[URL]]/_dusk/login/[[USER ID]]/[[MANAGER]]` - where…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-32003">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-22077 – An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-22077</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-22077</guid>
    <pubDate>Wed, 20 Mar 2024 05:15:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-22077</strong></p>
  <p>An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. The SQLite database file has weak permissions.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-280</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-22077">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-0232 – A heap use-after-free issue has been identified in SQLite in the jsonParseAddNod...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-0232</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-0232</guid>
    <pubDate>Tue, 16 Jan 2024 14:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-0232</strong></p>
  <p>A heap use-after-free issue has been identified in SQLite in the jsonParseAddNodeArray() function in sqlite3.c. This flaw allows a local attacker to leverage a victim to pass specially crafted malicious input to the application, potentially causing a crash and leading to a denial of service.</p>
  <p><strong>CVSS:</strong> 4.7 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-0232">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-0342 – A vulnerability classified as critical has been found in Inis up to 2.0.1. Affec...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-0342</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-0342</guid>
    <pubDate>Tue, 09 Jan 2024 20:15:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-0342</strong></p>
  <p>A vulnerability classified as critical has been found in Inis up to 2.0.1. Affected is an unknown function of the file /app/api/controller/default/Sqlite.php. The manipulation of the argument sql leads to sql injection. The exploit has been disclosed to the public and may be used. VDB-250110 is the identifier assigned to this vulnerability.</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-0342">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-7104 – A vulnerability was found in SQLite SQLite3 up to 3.43.0 and classified as criti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-7104</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-7104</guid>
    <pubDate>Fri, 29 Dec 2023 10:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-7104</strong></p>
  <p>A vulnerability was found in SQLite SQLite3 up to 3.43.0 and classified as critical. This issue affects the function sessionReadRecord of the file ext/session/sqlite3session.c of the component make alltest Handler. The manipulation leads to heap-based buffer overflow. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-248999.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-7104">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-47175 – Cross-site scripting vulnerability in LuxCal Web Calendar prior to 5.2.4M (MySQL...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-47175</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-47175</guid>
    <pubDate>Mon, 20 Nov 2023 05:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-47175</strong></p>
  <p>Cross-site scripting vulnerability in LuxCal Web Calendar prior to 5.2.4M (MySQL version) and LuxCal Web Calendar prior to 5.2.4L (SQLite version) allows a remote unauthenticated attacker to execute an arbitrary script on the web browser of the user who is accessing the product.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-47175">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-46700 – SQL injection vulnerability in LuxCal Web Calendar prior to 5.2.4M (MySQL versio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-46700</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-46700</guid>
    <pubDate>Mon, 20 Nov 2023 05:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-46700</strong></p>
  <p>SQL injection vulnerability in LuxCal Web Calendar prior to 5.2.4M (MySQL version) and LuxCal Web Calendar prior to 5.2.4L (SQLite version) allows a remote unauthenticated attacker to execute an arbitrary SQL command by sending a crafted request, and obtain or alter information stored in the database.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-46700">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2023-39265 – Apache Superset would allow for SQLite database connections to be incorrectly re...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-39265</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-39265</guid>
    <pubDate>Wed, 06 Sep 2023 14:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2023-39265</strong></p>
  <p>Apache Superset would allow for SQLite database connections to be incorrectly registered when an attacker uses alternative driver names like sqlite+pysqlite or by using database imports. This could allow for unexpected file creation on Superset webservers. Additionally, if Apache Superset is using a SQLite database for its metadata (not advised for production use) it could result in more severe v…</p>
  <p><strong>CVSS:</strong> 3.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-39265">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-39983 – A vulnerability that poses a potential risk of polluting the MXsecurity sqlite d...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-39983</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-39983</guid>
    <pubDate>Sat, 02 Sep 2023 13:15:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-39983</strong></p>
  <p>A vulnerability that poses a potential risk of polluting the MXsecurity sqlite database and the nsm-web UI has been identified in MXsecurity versions prior to v1.0.1. This vulnerability might allow an unauthenticated remote attacker to register or add devices via the nsm-web application.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-915</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-39983">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-39939 – SQL injection vulnerability in LuxCal Web Calendar prior to 5.2.3M (MySQL versio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-39939</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-39939</guid>
    <pubDate>Mon, 21 Aug 2023 09:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-39939</strong></p>
  <p>SQL injection vulnerability in LuxCal Web Calendar prior to 5.2.3M (MySQL version) and LuxCal Web Calendar prior to 5.2.3L (SQLite version) allows a remote unauthenticated attacker to execute arbitrary queries against the database and obtain or alter the information in it.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-39939">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-39543 – Cross-site scripting vulnerability in LuxCal Web Calendar prior to 5.2.3M (MySQL...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-39543</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-39543</guid>
    <pubDate>Mon, 21 Aug 2023 09:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-39543</strong></p>
  <p>Cross-site scripting vulnerability in LuxCal Web Calendar prior to 5.2.3M (MySQL version) and LuxCal Web Calendar prior to 5.2.3L (SQLite version) allows a remote unauthenticated attacker to execute an arbitrary script on the web browser of the user who is using the product.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-39543">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-37470 – Metabase is an open-source business intelligence and analytics platform. Prior t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-37470</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-37470</guid>
    <pubDate>Fri, 04 Aug 2023 16:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-37470</strong></p>
  <p>Metabase is an open-source business intelligence and analytics platform. Prior to versions 0.43.7.3, 0.44.7.3, 0.45.4.3, 0.46.6.4, 1.43.7.3, 1.44.7.3, 1.45.4.3, and 1.46.6.4, a vulnerability could potentially allow remote code execution on one's Metabase server. The core issue is that one of the supported data warehouses (an embedded in-memory database H2), exposes a number of ways for a connecti…</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-37470">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-32422 – This issue was addressed by adding additional SQLite logging restrictions. This ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-32422</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-32422</guid>
    <pubDate>Fri, 23 Jun 2023 18:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-32422</strong></p>
  <p>This issue was addressed by adding additional SQLite logging restrictions. This issue is fixed in iOS 16.5 and iPadOS 16.5, tvOS 16.5, macOS Ventura 13.4. An app may be able to bypass Privacy preferences.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-32422">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2023-2863 – A vulnerability has been found in Simple Design Daily Journal 1.012.GP.B on Andr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-2863</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-2863</guid>
    <pubDate>Wed, 24 May 2023 10:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2023-2863</strong></p>
  <p>A vulnerability has been found in Simple Design Daily Journal 1.012.GP.B on Android and classified as problematic. Affected by this vulnerability is an unknown functionality of the component SQLite Database. The manipulation leads to cleartext storage in a file or on disk. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The asso…</p>
  <p><strong>CVSS:</strong> 2.3 · <strong>CWE:</strong> CWE-313</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-2863">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-32697 – SQLite JDBC is a library for accessing and creating SQLite database files in Jav...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-32697</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-32697</guid>
    <pubDate>Tue, 23 May 2023 23:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-32697</strong></p>
  <p>SQLite JDBC is a library for accessing and creating SQLite database files in Java. Sqlite-jdbc addresses a remote code execution vulnerability via JDBC URL. This issue impacting versions 3.6.14.1 through 3.41.2.1 and has been fixed in version 3.41.2.2.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-32697">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-31239 – An issue found in SQLite SQLite3 v.3.35.4 that allows a remote attacker to cause...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-31239</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-31239</guid>
    <pubDate>Tue, 09 May 2023 02:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-31239</strong></p>
  <p>An issue found in SQLite SQLite3 v.3.35.4 that allows a remote attacker to cause a denial of service via the appendvfs.c function.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-31239">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-2137 – Heap buffer overflow in sqlite in Google Chrome prior to 112.0.5615.137 allowed ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-2137</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-2137</guid>
    <pubDate>Wed, 19 Apr 2023 04:15:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-2137</strong></p>
  <p>Heap buffer overflow in sqlite in Google Chrome prior to 112.0.5615.137 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-2137">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-47927 – An issue was discovered in MediaWiki before 1.35.9, 1.36.x through 1.38.x before...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-47927</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-47927</guid>
    <pubDate>Thu, 12 Jan 2023 06:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-47927</strong></p>
  <p>An issue was discovered in MediaWiki before 1.35.9, 1.36.x through 1.38.x before 1.38.5, and 1.39.x before 1.39.1. When installing with a pre-existing data directory that has weak permissions, the SQLite files are created with file mode 0644, i.e., world readable to local users. These files include credentials data.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-47927">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-46908 – SQLite through 3.40.0, when relying on --safe for execution of an untrusted CLI ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-46908</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-46908</guid>
    <pubDate>Mon, 12 Dec 2022 06:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-46908</strong></p>
  <p>SQLite through 3.40.0, when relying on --safe for execution of an untrusted CLI script, does not properly implement the azProhibitedFunctions protection mechanism, and instead allows UDF functions such as WRITEFILE.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-46908">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
