SQL Server
by Microsoft
CVEs (260)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-21705 | Hig | 0.57 | 8.8 | 0.01 | Feb 14, 2023 | Microsoft SQL Server Remote Code Execution Vulnerability | ||
| CVE-2025-49717 | Hig | 0.55 | 8.5 | 0.01 | Jul 8, 2025 | Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network. | ||
| CVE-2025-62575 | Hig | 0.54 | 8.3 | 0.00 | Dec 2, 2025 | NMIS/BioDose V22.02 and previous versions rely on a Microsoft SQL Server database. The SQL user account 'nmdbuser' and other created accounts by default have the sysadmin role. This can lead to remote code execution through the use of certain built-in stored procedures. | ||
| CVE-2009-2502 | Hig | 0.54 | 8.1 | 0.22 | Oct 14, 2009 | Buffer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003… | ||
| CVE-2024-49043 | Hig | 0.51 | 7.8 | 0.01 | Nov 12, 2024 | Microsoft.SqlServer.XEvent.Configuration.dll Remote Code Execution Vulnerability | ||
| CVE-2024-49021 | Hig | 0.51 | 7.8 | 0.01 | Nov 12, 2024 | Microsoft SQL Server Remote Code Execution Vulnerability | ||
| CVE-2023-36785 | Hig | 0.51 | 7.8 | 0.01 | Oct 10, 2023 | Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | ||
| CVE-2023-36730 | Hig | 0.51 | 7.8 | 0.01 | Oct 10, 2023 | Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | ||
| CVE-2023-36420 | Hig | 0.51 | 7.8 | 0.01 | Oct 10, 2023 | Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | ||
| CVE-2023-36417 | Hig | 0.51 | 7.8 | 0.01 | Oct 10, 2023 | Microsoft SQL OLE DB Remote Code Execution Vulnerability | ||
| CVE-2023-32028 | Hig | 0.51 | 7.8 | 0.01 | Jun 16, 2023 | Microsoft SQL OLE DB Remote Code Execution Vulnerability | ||
| CVE-2023-32027 | Hig | 0.51 | 7.8 | 0.01 | Jun 16, 2023 | Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | ||
| CVE-2023-32026 | Hig | 0.51 | 7.8 | 0.01 | Jun 16, 2023 | Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | ||
| CVE-2023-32025 | Hig | 0.51 | 7.8 | 0.01 | Jun 16, 2023 | Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | ||
| CVE-2023-29356 | Hig | 0.51 | 7.8 | 0.01 | Jun 16, 2023 | Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | ||
| CVE-2023-29349 | Hig | 0.51 | 7.8 | 0.01 | Jun 16, 2023 | Microsoft ODBC and OLE DB Remote Code Execution Vulnerability | ||
| CVE-2023-21718 | Hig | 0.51 | 7.8 | 0.01 | Feb 14, 2023 | Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | ||
| CVE-2023-21704 | Hig | 0.51 | 7.8 | 0.00 | Feb 14, 2023 | Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | ||
| CVE-2023-21528 | Hig | 0.51 | 7.8 | 0.00 | Feb 14, 2023 | Microsoft SQL Server Remote Code Execution Vulnerability | ||
| CVE-2022-23276 | Hig | 0.51 | 7.8 | 0.01 | Feb 9, 2022 | SQL Server for Linux Containers Elevation of Privilege Vulnerability |
- risk 0.57cvss 8.8epss 0.01
Microsoft SQL Server Remote Code Execution Vulnerability
- risk 0.55cvss 8.5epss 0.01
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
- risk 0.54cvss 8.3epss 0.00
NMIS/BioDose V22.02 and previous versions rely on a Microsoft SQL Server database. The SQL user account 'nmdbuser' and other created accounts by default have the sysadmin role. This can lead to remote code execution through the use of certain built-in stored procedures.
- risk 0.54cvss 8.1epss 0.22
Buffer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003…
- risk 0.51cvss 7.8epss 0.01
Microsoft.SqlServer.XEvent.Configuration.dll Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Microsoft SQL Server Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Microsoft SQL OLE DB Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Microsoft SQL OLE DB Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Microsoft ODBC and OLE DB Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.00
Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.00
Microsoft SQL Server Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
SQL Server for Linux Containers Elevation of Privilege Vulnerability
Page 8 of 13