CVE-2025-49759 — CVSS 8.8 (high): Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate…
CVE-2025-53727 — CVSS 8.8 (high): Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate…
CVE-2025-55227 — CVSS 8.8 (high): Improper neutralization of special elements used in a command ('command injection') in SQL Server allows an authorized attacker to elevate…
CVE-2025-59499 — CVSS 8.8 (high): Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate…
CVE-2026-21262 — CVSS 8.8 (high): Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-26115 — CVSS 8.8 (high): Improper validation of specified type of input in SQL Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-26116 — CVSS 8.8 (high): Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate…
CVE-2026-33120 — CVSS 8.8 (high): Untrusted pointer dereference in SQL Server allows an authorized attacker to execute code over a network.
CVE-2026-40370 — CVSS 8.8 (high): External control of file name or path in SQL Server allows an authorized attacker to execute code over a network.
CVE-2026-47295 — CVSS 8.8 (high): Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate…
CVE-2026-55002 — CVSS 8.8 (high): External control of file name or path in SQL Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-66814 — CVSS 8.8 (high): Insufficient granularity of access control in SQL Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-66818 — CVSS 8.8 (high): Improper privilege management in SQL Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-66819 — CVSS 8.8 (high): Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate…
CVE-2026-66820 — CVSS 8.8 (high): Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate…
CVE-2026-67368 — CVSS 8.8 (high): Improper link resolution before file access ('link following') in SQL Server allows an authorized attacker to elevate privileges over a…
CVE-2026-67370 — CVSS 8.8 (high): Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate…
CVE-2026-67380 — CVSS 8.8 (high): Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
CVE-2026-67388 — CVSS 8.8 (high): Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
CVE-2026-67639 — CVSS 8.8 (high): Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
CVE-2026-68775 — CVSS 8.8 (high): Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
CVE-2026-68786 — CVSS 8.8 (high): Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
CVE-2026-73028 — CVSS 8.8 (high): Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-77480 — CVSS 8.8 (high): Insufficient granularity of access control in SQL Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-77481 — CVSS 8.8 (high): Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
CVE-2026-77482 — CVSS 8.8 (high): Heap-based buffer overflow in SQL Server allows an unauthorized attacker to execute code over a network.
CVE-2026-77483 — CVSS 8.8 (high): Weak authentication in SQL Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-77486 — CVSS 8.8 (high): Integer overflow or wraparound in SQL Server allows an unauthorized attacker to execute code over a network.
CVE-2026-77487 — CVSS 8.8 (high): Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-78442 — CVSS 8.8 (high): Heap-based buffer overflow in Windows OLE DB allows an unauthorized attacker to execute code over a network.
CVE-2025-24999 — CVSS 8.8 (high): Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.
CVE-2025-49758 — CVSS 8.8 (high): Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate…
CVE-2026-68787 — CVSS 7.8 (high): Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code locally.
CVE-2026-47296 — CVSS 7.5 (high): Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate…
CVE-2026-67376 — CVSS 7.5 (high): Integer overflow or wraparound in SQL Server allows an unauthorized attacker to deny service over a network.
CVE-2025-49719 — CVSS 7.5 (high): Improper input validation in SQL Server allows an unauthorized attacker to disclose information over a network.
CVE-2026-32176 — CVSS 6.7 (medium): Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate…
CVE-2026-32167 — CVSS 6.7 (medium): Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate…
CVE-2026-68779 — CVSS 6.5 (medium): Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
CVE-2026-68780 — CVSS 6.5 (medium): Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
CVE-2026-68781 — CVSS 6.5 (medium): Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
CVE-2026-68784 — CVSS 6.5 (medium): Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
CVE-2025-47997 — CVSS 6.5 (medium): Concurrent execution using shared resource with improper synchronization ('race condition') in SQL Server allows an authorized attacker to…
CVE-2026-67386 — CVSS 6.5 (medium): Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network.
CVE-2026-69562 — CVSS 6.5 (medium): Out-of-bounds read in SQL Server allows an unauthorized attacker to disclose information over a network.
CVE-2026-67390 — CVSS 6.5 (medium): Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.
CVE-2026-67393 — CVSS 6.5 (medium): Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.
CVE-2026-67629 — CVSS 6.5 (medium): Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
CVE-2026-67630 — CVSS 6.5 (medium): Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
CVE-2026-67645 — CVSS 6.5 (medium): Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
CVE-2026-67648 — CVSS 6.5 (medium): Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network.
CVE-2026-78441 — CVSS 6.5 (medium): Out-of-bounds read in Windows OLE DB allows an unauthorized attacker to disclose information over a network.
CVE-2026-68776 — CVSS 6.5 (medium): Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network.
CVE-2026-68777 — CVSS 6.5 (medium): Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
CVE-2026-68778 — CVSS 6.5 (medium): Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
CVE-2026-77488 — CVSS 5.5 (medium): Integer underflow (wrap or wraparound) in SQL Server allows an authorized attacker to disclose information locally.
CVE-2026-68785 — CVSS 4.9 (medium): Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.