CVE-2025-6965High· 7.7▾ MidnightPoC availableThere exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corruption issue. We recommend upgrading to version 3.50.2 or above.
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 42.4 · likelihood 14.5 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
73%
73% → 76%
Exploit-DB (last check)
There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corruption issue. We recommend upgrading to version 3.50.2 or above.
sqlite < 3.50.2ipados < 26.0.0iphone_os < 26.0.0macos < 26.0.0tvos < 26.0.0visionos < 26.0.0watchos < 26.0.0ruggedcom_crossbow < 5.8sidis_prime < 4.0.800Upgrade past the affected range:
sqlite 3.50.2ipados 26.0.0iphone_os 26.0.0macos 26.0.0tvos 26.0.0visionos 26.0.0watchos 26.0.0ruggedcom_crossbow 5.8sidis_prime 4.0.800Connected by shared product, vendor, weakness, or advisory.
CVE-2026-19667High· 7.5If an attacker-controlled authoritative server can produce a negative answer that is exactly 65536 bytes, then a flaw in `named` results in a negative cache entry of 0 bytes
CVE-2026-80213Medium· 4.0An issue was discovered in the resolv gem before 0.7.2 for Ruby
CVE-2026-87529Critical· 9.6Numeric truncation error in Media in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page
CVE-2026-86315Medium· 6.2An out-of-bounds write caused by numeric truncation Samsung Open Source Escargot on Linux x86-64 allows an attacker who can supply JavaScript for execution to corrupt native memory and crash the host process via a crafted class definiti…
CVE-2026-63449Low· 3.7Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine
CVE-2026-49263NoneCapstone is a disassembly framework