SQL Server
by Microsoft
CVEs (321)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-67368 | Hig | 0.57 | 8.8 | 0.01 | Sep 8, 2026 | Improper link resolution before file access ('link following') in SQL Server allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-66820 | Hig | 0.57 | 8.8 | 0.01 | Sep 8, 2026 | Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-66819 | Hig | 0.57 | 8.8 | 0.01 | Sep 8, 2026 | Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-66818 | Hig | 0.57 | 8.8 | 0.01 | Sep 8, 2026 | Improper privilege management in SQL Server allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-66814 | Hig | 0.57 | 8.8 | 0.01 | Sep 8, 2026 | Insufficient granularity of access control in SQL Server allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-40370 | Hig | 0.57 | 8.8 | 0.01 | May 12, 2026 | External control of file name or path in SQL Server allows an authorized attacker to execute code over a network. | ||
| CVE-2026-33120 | Hig | 0.57 | 8.8 | 0.01 | Apr 14, 2026 | Untrusted pointer dereference in SQL Server allows an authorized attacker to execute code over a network. | ||
| CVE-2026-26116 | Hig | 0.57 | 8.8 | 0.01 | Mar 10, 2026 | Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-26115 | Hig | 0.57 | 8.8 | 0.01 | Mar 10, 2026 | Improper validation of specified type of input in SQL Server allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-21262 | Hig | 0.57 | 8.8 | 0.02 | Mar 10, 2026 | Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2025-59499 | Hig | 0.57 | 8.8 | 0.01 | Nov 11, 2025 | Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2025-55227 | Hig | 0.57 | 8.8 | 0.01 | Sep 9, 2025 | Improper neutralization of special elements used in a command ('command injection') in SQL Server allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2025-53727 | Hig | 0.57 | 8.8 | 0.01 | Aug 12, 2025 | Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2025-49759 | Hig | 0.57 | 8.8 | 0.01 | Aug 12, 2025 | Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2025-49758 | Hig | 0.57 | 8.8 | 0.01 | Aug 12, 2025 | Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2025-47954 | Hig | 0.57 | 8.8 | 0.02 | Aug 12, 2025 | Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2025-24999 | Hig | 0.57 | 8.8 | 0.02 | Aug 12, 2025 | Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2024-49018 | Hig | 0.57 | 8.8 | 0.02 | Nov 12, 2024 | SQL Server Native Client Remote Code Execution Vulnerability | ||
| CVE-2024-49017 | Hig | 0.57 | 8.8 | 0.01 | Nov 12, 2024 | SQL Server Native Client Remote Code Execution Vulnerability | ||
| CVE-2024-49016 | Hig | 0.57 | 8.8 | 0.01 | Nov 12, 2024 | SQL Server Native Client Remote Code Execution Vulnerability |
- risk 0.57cvss 8.8epss 0.01
Improper link resolution before file access ('link following') in SQL Server allows an authorized attacker to elevate privileges over a network.
- risk 0.57cvss 8.8epss 0.01
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.
- risk 0.57cvss 8.8epss 0.01
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.
- risk 0.57cvss 8.8epss 0.01
Improper privilege management in SQL Server allows an authorized attacker to elevate privileges over a network.
- risk 0.57cvss 8.8epss 0.01
Insufficient granularity of access control in SQL Server allows an authorized attacker to elevate privileges over a network.
- risk 0.57cvss 8.8epss 0.01
External control of file name or path in SQL Server allows an authorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.01
Untrusted pointer dereference in SQL Server allows an authorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.01
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.
- risk 0.57cvss 8.8epss 0.01
Improper validation of specified type of input in SQL Server allows an authorized attacker to elevate privileges over a network.
- risk 0.57cvss 8.8epss 0.02
Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.
- risk 0.57cvss 8.8epss 0.01
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.
- risk 0.57cvss 8.8epss 0.01
Improper neutralization of special elements used in a command ('command injection') in SQL Server allows an authorized attacker to elevate privileges over a network.
- risk 0.57cvss 8.8epss 0.01
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.
- risk 0.57cvss 8.8epss 0.01
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.
- risk 0.57cvss 8.8epss 0.01
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.
- risk 0.57cvss 8.8epss 0.02
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.
- risk 0.57cvss 8.8epss 0.02
Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.
- risk 0.57cvss 8.8epss 0.02
SQL Server Native Client Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.01
SQL Server Native Client Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.01
SQL Server Native Client Remote Code Execution Vulnerability
Page 3 of 17