Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Sqlite

First CVE: Apr 3, 2009Active for: 17 yearsTotal CVEs: 66
62.2
VTI Score
TOP TARGET

SQLite is a ubiquitous embedded database library that, despite a narrow product scope, achieves prominence through its deep integration into countless applications, operating systems, and devices across the landscape. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, creating cascading risk across the full ecosystem of downstream consumers that bundle the library without independent patching cycles. The recurring weakness classes—including NULL-pointer dereferences, integer overflows, use-after-free conditions, and heap-based buffer overflows—reflect the memory-safety demands of a C-based SQL parser and query engine exposed to untrusted database input. Defenders should prioritize SQLite updates as a supply-chain concern, treating patches as broadly applicable across embedded systems, mobile platforms, and server applications that depend on the library; current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
66
Total CVEs
More Total CVEs than 99% of tracked vendors
5.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 98% of tracked vendors
7.3
Avg CVSS Score
Higher Avg CVSS Score than 54% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Sqlite over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 3, 2009
17 years ago
Most Recent CVE
Jun 9, 2026
46 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (66 CVEs).

66 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-6965HIGH
There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corrupti
Jul 15, 20257.780NOYES
CVE-2019-8457CRITICAL
SQLite3 from 3.6.0 to and including 3.27.2 is vulnerable to heap out-of-bound read in the rtreenode() function when handling invalid rtree tables.
May 30, 20199.850NONO
CVE-2015-5895HIGH
Multiple unspecified vulnerabilities in SQLite before 3.8.10.2, as used in Apple iOS before 9, have unknown impact and attack vectors.
Sep 18, 201510.039NOYES
CVE-2026-11824HIGH
SQLite before 3.53.2 contains a heap-based buffer overflow vulnerability in the FTS5 full-text search extension that allows attackers to cause a crash or execute arbitrary code by
Jun 9, 20267.835NONO
CVE-2026-11822HIGH
SQLite before 3.53.2 contains memory corruption vulnerabilities in the FTS5 full-text search extension that allow attackers to cause process crashes, memory exhaustion, or arbitrar
Jun 9, 20267.835NONO
CVE-2022-35737HIGH
SQLite 1.0.12 through 3.39.x before 3.39.2 sometimes allows an array-bounds overflow if billions of bytes are used in a string argument to a C API.
Aug 3, 20227.532NONO
CVE-2019-19646CRITICAL
pragma.c in SQLite through 3.30.1 mishandles NOT NULL in an integrity_check PRAGMA command in certain cases of generated columns.
Dec 9, 20199.832NONO
CVE-2020-35527CRITICAL
In SQLite 3.31.1, there is an out of bounds access problem through ALTER TABLE for views that have a nested FROM clause.
Sep 1, 20229.831NONO
CVE-2019-19317CRITICAL
lookupName in resolve.c in SQLite 3.30.1 omits bits from the colUsed bitmask in the case of a generated column, which allows attackers to cause a denial of service or possibly have
Dec 5, 20199.831NONO
CVE-2008-6593HIGH
SQL injection vulnerability in LightNEasy/lightneasy.php in LightNEasy SQLite 1.2.2 and earlier allows remote attackers to inject arbitrary PHP code into comments.dat via the dlid
Apr 3, 20097.531NOYES
View all 66 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products66 CVEs
29%
58%
14%
Severity distribution among all CVEs352,427 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local15 (22.7%)
Network40 (60.6%)
Unknown11 (16.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low50 (75.8%)
High5 (7.6%)
Unknown11 (16.7%)
User Interaction
None50 (75.8%)
Unknown11 (16.7%)
Required5 (7.6%)
Privileges Required
Low11 (16.7%)
High0 (0.0%)
None44 (66.7%)
Unknown11 (16.7%)

Exploit Exposure

Signals from CVEs in this vendor scope (66 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
5 CVEs
7.6% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Sqlite.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Sqlite — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Sqlite's Products

View all 11 CNAs →

Top CWEs