SQL Server
by Microsoft
CVEs (321)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-29045 | Hig | 0.49 | 7.5 | 0.02 | Apr 9, 2024 | Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability | ||
| CVE-2022-29143 | Hig | 0.49 | 7.5 | 0.02 | Jun 15, 2022 | Microsoft SQL Server Remote Code Execution Vulnerability | ||
| CVE-2017-8516 | Hig | 0.49 | 7.5 | 0.08 | Aug 8, 2017 | Microsoft SQL Server Analysis Services in Microsoft SQL Server 2012, Microsoft SQL Server 2014, and Microsoft SQL Server 2016 allows an information disclosure vulnerability when it improperly enforces permissions, aka "Microsoft SQL Server Analysis Services Information… | ||
| CVE-2002-1872 | Hig | 0.49 | 7.5 | 0.07 | Dec 31, 2002 | Microsoft SQL Server 6.0 through 2000, with SQL Authentication enabled, uses weak password encryption (XOR), which allows remote attackers to sniff and decrypt the password. | ||
| CVE-2023-23384 | Hig | 0.48 | 7.3 | 0.01 | Apr 11, 2023 | Microsoft SQL Server Remote Code Execution Vulnerability | ||
| CVE-2026-20803 | Hig | 0.47 | 7.2 | 0.01 | Jan 13, 2026 | Missing authentication for critical function in SQL Server allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-77485 | Hig | 0.46 | 7.0 | 0.00 | Sep 8, 2026 | Use after free in SQL Server allows an authorized attacker to elevate privileges locally. | ||
| CVE-2024-37966 | Hig | 0.46 | 7.1 | 0.02 | Sep 10, 2024 | Microsoft SQL Server Native Scoring Information Disclosure Vulnerability | ||
| CVE-2024-37342 | Hig | 0.46 | 7.1 | 0.02 | Sep 10, 2024 | Microsoft SQL Server Native Scoring Information Disclosure Vulnerability | ||
| CVE-2024-37337 | Hig | 0.46 | 7.1 | 0.02 | Sep 10, 2024 | Microsoft SQL Server Native Scoring Information Disclosure Vulnerability | ||
| CVE-2026-32176 | Med | 0.44 | 6.7 | 0.00 | Apr 14, 2026 | Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-32167 | Med | 0.44 | 6.7 | 0.00 | Apr 14, 2026 | Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges locally. | ||
| CVE-2016-7252 | Med | 0.44 | 6.5 | 0.18 | Nov 10, 2016 | Microsoft SQL Server 2016 mishandles the FILESTREAM path, which allows remote authenticated users to gain privileges via unspecified vectors, aka "SQL Analysis Services Information Disclosure Vulnerability." | ||
| CVE-2019-0819 | Med | 0.43 | 6.5 | 0.05 | May 16, 2019 | An information disclosure vulnerability exists in Microsoft SQL Server Analysis Services when it improperly enforces metadata permissions, aka 'Microsoft SQL Server Analysis Services Information Disclosure Vulnerability'. | ||
| CVE-2026-73029 | Med | 0.42 | 6.5 | 0.01 | Sep 8, 2026 | Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network. | ||
| CVE-2026-69562 | Med | 0.42 | 6.5 | 0.01 | Sep 8, 2026 | Out-of-bounds read in SQL Server allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2026-68784 | Med | 0.42 | 6.5 | 0.01 | Sep 8, 2026 | Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. | ||
| CVE-2026-68781 | Med | 0.42 | 6.5 | 0.01 | Sep 8, 2026 | Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. | ||
| CVE-2026-68780 | Med | 0.42 | 6.5 | 0.01 | Sep 8, 2026 | Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. | ||
| CVE-2026-68779 | Med | 0.42 | 6.5 | 0.01 | Sep 8, 2026 | Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. |
- risk 0.49cvss 7.5epss 0.02
Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
- risk 0.49cvss 7.5epss 0.02
Microsoft SQL Server Remote Code Execution Vulnerability
- risk 0.49cvss 7.5epss 0.08
Microsoft SQL Server Analysis Services in Microsoft SQL Server 2012, Microsoft SQL Server 2014, and Microsoft SQL Server 2016 allows an information disclosure vulnerability when it improperly enforces permissions, aka "Microsoft SQL Server Analysis Services Information…
- risk 0.49cvss 7.5epss 0.07
Microsoft SQL Server 6.0 through 2000, with SQL Authentication enabled, uses weak password encryption (XOR), which allows remote attackers to sniff and decrypt the password.
- risk 0.48cvss 7.3epss 0.01
Microsoft SQL Server Remote Code Execution Vulnerability
- risk 0.47cvss 7.2epss 0.01
Missing authentication for critical function in SQL Server allows an authorized attacker to elevate privileges over a network.
- risk 0.46cvss 7.0epss 0.00
Use after free in SQL Server allows an authorized attacker to elevate privileges locally.
- risk 0.46cvss 7.1epss 0.02
Microsoft SQL Server Native Scoring Information Disclosure Vulnerability
- risk 0.46cvss 7.1epss 0.02
Microsoft SQL Server Native Scoring Information Disclosure Vulnerability
- risk 0.46cvss 7.1epss 0.02
Microsoft SQL Server Native Scoring Information Disclosure Vulnerability
- risk 0.44cvss 6.7epss 0.00
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges locally.
- risk 0.44cvss 6.7epss 0.00
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges locally.
- risk 0.44cvss 6.5epss 0.18
Microsoft SQL Server 2016 mishandles the FILESTREAM path, which allows remote authenticated users to gain privileges via unspecified vectors, aka "SQL Analysis Services Information Disclosure Vulnerability."
- risk 0.43cvss 6.5epss 0.05
An information disclosure vulnerability exists in Microsoft SQL Server Analysis Services when it improperly enforces metadata permissions, aka 'Microsoft SQL Server Analysis Services Information Disclosure Vulnerability'.
- risk 0.42cvss 6.5epss 0.01
Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.
- risk 0.42cvss 6.5epss 0.01
Out-of-bounds read in SQL Server allows an unauthorized attacker to disclose information over a network.
- risk 0.42cvss 6.5epss 0.01
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
- risk 0.42cvss 6.5epss 0.01
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
- risk 0.42cvss 6.5epss 0.01
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
- risk 0.42cvss 6.5epss 0.01
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
Page 11 of 17