SQL Server
by Microsoft
CVEs (321)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-28926 | Hig | 0.57 | 8.8 | 0.02 | Apr 9, 2024 | Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability | ||
| CVE-2024-28915 | Hig | 0.57 | 8.8 | 0.02 | Apr 9, 2024 | Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability | ||
| CVE-2024-28914 | Hig | 0.57 | 8.8 | 0.02 | Apr 9, 2024 | Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability | ||
| CVE-2024-28913 | Hig | 0.57 | 8.8 | 0.02 | Apr 9, 2024 | Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability | ||
| CVE-2024-28912 | Hig | 0.57 | 8.8 | 0.02 | Apr 9, 2024 | Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability | ||
| CVE-2024-28911 | Hig | 0.57 | 8.8 | 0.02 | Apr 9, 2024 | Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability | ||
| CVE-2024-28910 | Hig | 0.57 | 8.8 | 0.03 | Apr 9, 2024 | Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability | ||
| CVE-2024-28909 | Hig | 0.57 | 8.8 | 0.02 | Apr 9, 2024 | Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability | ||
| CVE-2024-28908 | Hig | 0.57 | 8.8 | 0.02 | Apr 9, 2024 | Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability | ||
| CVE-2024-28906 | Hig | 0.57 | 8.8 | 0.02 | Apr 9, 2024 | Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability | ||
| CVE-2024-0056 | Hig | 0.57 | 8.7 | 0.01 | Jan 9, 2024 | Microsoft.Data.SqlClient and System.Data.SqlClient SQL Data Provider Security Feature Bypass Vulnerability | ||
| CVE-2023-38169 | Hig | 0.57 | 8.8 | 0.01 | Aug 8, 2023 | Microsoft SQL OLE DB Remote Code Execution Vulnerability | ||
| CVE-2023-21713 | Hig | 0.57 | 8.8 | 0.02 | Feb 14, 2023 | Microsoft SQL Server Remote Code Execution Vulnerability | ||
| CVE-2023-21705 | Hig | 0.57 | 8.8 | 0.01 | Feb 14, 2023 | Microsoft SQL Server Remote Code Execution Vulnerability | ||
| CVE-2026-67379 | Hig | 0.55 | 8.5 | 0.01 | Sep 8, 2026 | Stack-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network. | ||
| CVE-2025-49717 | Hig | 0.55 | 8.5 | 0.01 | Jul 8, 2025 | Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network. | ||
| CVE-2025-62575 | Hig | 0.54 | 8.3 | 0.00 | Dec 2, 2025 | NMIS/BioDose V22.02 and previous versions rely on a Microsoft SQL Server database. The SQL user account 'nmdbuser' and other created accounts by default have the sysadmin role. This can lead to remote code execution through the use of certain built-in stored procedures. | ||
| CVE-2009-2502 | Hig | 0.54 | 8.1 | 0.22 | Oct 14, 2009 | Buffer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003… | ||
| CVE-2026-47297 | Hig | 0.53 | 8.1 | 0.01 | Sep 8, 2026 | Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-68787 | Hig | 0.51 | 7.8 | 0.00 | Sep 8, 2026 | Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code locally. |
- risk 0.57cvss 8.8epss 0.02
Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.02
Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.02
Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.02
Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.02
Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.02
Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.03
Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.02
Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.02
Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.02
Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
- risk 0.57cvss 8.7epss 0.01
Microsoft.Data.SqlClient and System.Data.SqlClient SQL Data Provider Security Feature Bypass Vulnerability
- risk 0.57cvss 8.8epss 0.01
Microsoft SQL OLE DB Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.02
Microsoft SQL Server Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.01
Microsoft SQL Server Remote Code Execution Vulnerability
- risk 0.55cvss 8.5epss 0.01
Stack-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
- risk 0.55cvss 8.5epss 0.01
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
- risk 0.54cvss 8.3epss 0.00
NMIS/BioDose V22.02 and previous versions rely on a Microsoft SQL Server database. The SQL user account 'nmdbuser' and other created accounts by default have the sysadmin role. This can lead to remote code execution through the use of certain built-in stored procedures.
- risk 0.54cvss 8.1epss 0.22
Buffer overflow in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1 and SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold and SP3, Office Excel Viewer 2003…
- risk 0.53cvss 8.1epss 0.01
Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network.
- risk 0.51cvss 7.8epss 0.00
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code locally.
Page 9 of 17