VYPR

SQL Server

by Microsoft

CVEs (260)

  • CVE-2025-49719HigJul 8, 2025
    risk 0.50cvss 7.5epss 0.10

    Improper input validation in SQL Server allows an unauthorized attacker to disclose information over a network.

  • CVE-2024-43474HigSep 10, 2024
    risk 0.50cvss 7.6epss 0.01

    Microsoft SQL Server Information Disclosure Vulnerability

  • CVE-2025-49718HigJul 8, 2025
    risk 0.49cvss 7.5epss 0.03

    Use of uninitialized resource in SQL Server allows an unauthorized attacker to disclose information over a network.

  • CVE-2024-29045HigApr 9, 2024
    risk 0.49cvss 7.5epss 0.02

    Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability

  • CVE-2022-29143HigJun 15, 2022
    risk 0.49cvss 7.5epss 0.02

    Microsoft SQL Server Remote Code Execution Vulnerability

  • CVE-2017-8516HigAug 8, 2017
    risk 0.49cvss 7.5epss 0.08

    Microsoft SQL Server Analysis Services in Microsoft SQL Server 2012, Microsoft SQL Server 2014, and Microsoft SQL Server 2016 allows an information disclosure vulnerability when it improperly enforces permissions, aka "Microsoft SQL Server Analysis Services Information…

  • CVE-2002-1872HigDec 31, 2002
    risk 0.49cvss 7.5epss 0.06

    Microsoft SQL Server 6.0 through 2000, with SQL Authentication enabled, uses weak password encryption (XOR), which allows remote attackers to sniff and decrypt the password.

  • CVE-2023-23384HigApr 11, 2023
    risk 0.48cvss 7.3epss 0.01

    Microsoft SQL Server Remote Code Execution Vulnerability

  • CVE-2026-20803HigJan 13, 2026
    risk 0.47cvss 7.2epss 0.01

    Missing authentication for critical function in SQL Server allows an authorized attacker to elevate privileges over a network.

  • CVE-2024-37966HigSep 10, 2024
    risk 0.46cvss 7.1epss 0.02

    Microsoft SQL Server Native Scoring Information Disclosure Vulnerability

  • CVE-2024-37342HigSep 10, 2024
    risk 0.46cvss 7.1epss 0.02

    Microsoft SQL Server Native Scoring Information Disclosure Vulnerability

  • CVE-2024-37337HigSep 10, 2024
    risk 0.46cvss 7.1epss 0.02

    Microsoft SQL Server Native Scoring Information Disclosure Vulnerability

  • CVE-2026-32176MedApr 14, 2026
    risk 0.44cvss 6.7epss 0.00

    Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges locally.

  • CVE-2026-32167MedApr 14, 2026
    risk 0.44cvss 6.7epss 0.00

    Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges locally.

  • CVE-2016-7252MedNov 10, 2016
    risk 0.44cvss 6.5epss 0.18

    Microsoft SQL Server 2016 mishandles the FILESTREAM path, which allows remote authenticated users to gain privileges via unspecified vectors, aka "SQL Analysis Services Information Disclosure Vulnerability."

  • CVE-2019-0819MedMay 16, 2019
    risk 0.43cvss 6.5epss 0.05

    An information disclosure vulnerability exists in Microsoft SQL Server Analysis Services when it improperly enforces metadata permissions, aka 'Microsoft SQL Server Analysis Services Information Disclosure Vulnerability'.

  • CVE-2025-47997MedSep 9, 2025
    risk 0.42cvss 6.5epss 0.01

    Concurrent execution using shared resource with improper synchronization ('race condition') in SQL Server allows an authorized attacker to disclose information over a network.

  • CVE-2016-7251MedNov 10, 2016
    risk 0.40cvss 6.1epss 0.08

    Cross-site scripting (XSS) vulnerability in the MDS API in Microsoft SQL Server 2016 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka "MDS API XSS Vulnerability."

  • CVE-2023-36728MedOct 10, 2023
    risk 0.36cvss 5.5epss 0.01

    Microsoft SQL Server Denial of Service Vulnerability

  • CVE-2008-5416Dec 10, 2008
    risk 0.10cvss epss 0.87

    Heap-based buffer overflow in Microsoft SQL Server 2000 SP4, 8.00.2050, 8.00.2039, and earlier; SQL Server 2000 Desktop Engine (MSDE 2000) SP4; SQL Server 2005 SP2 and 9.00.1399.06; SQL Server 2000 Desktop Engine (WMSDE) on Windows Server 2003 SP1 and SP2; and Windows Internal…

Page 9 of 13