cbcvebase.

Microsoft Sql Server 2025 vulnerabilities

13 known vulnerabilities affecting microsoft/microsoft_sql_server_2025.

Total CVEs
13
CISA KEV
0
Public exploits
0
Exploited in wild
1
Severity breakdown
HIGH11MEDIUM2

Vulnerabilities

Page 1 of 1
CVE-2026-21262P1HIGHCVSS 8.8Exploited≥ 17.0.0.0, < 17.0.4020.22026-03-10
CVE-2026-21262 [HIGH] CWE-284 CVE-2026-21262: Improper access control in SQL Server allows an authorized attacker to elevate privileges over a net Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2026-54118P2HIGHCVSS 8.8≥ 17.0.4060.2, < 17.0.4060.22026-07-14
CVE-2026-54118 [HIGH] CWE-502 CVE-2026-54118: Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a network.
nvd
CVE-2026-54117P2HIGHCVSS 8.8≥ 17.0.4060.2, < 17.0.4060.22026-07-14
CVE-2026-54117 [HIGH] CWE-502 CVE-2026-54117: Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a network.
nvd
CVE-2026-26116P2HIGHCVSS 8.8≥ 17.0.0.0, < 17.0.4020.22026-03-10
CVE-2026-26116 [HIGH] CWE-89 CVE-2026-26116: Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server a Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2026-26115P2HIGHCVSS 8.8≥ 17.0.0.0, < 17.0.4020.22026-03-10
CVE-2026-26115 [HIGH] CWE-1287 CVE-2026-26115: Improper validation of specified type of input in SQL Server allows an authorized attacker to elevat Improper validation of specified type of input in SQL Server allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2026-47295P2HIGHCVSS 8.8≥ 17.0.4060.2, < 17.0.4060.22026-07-14
CVE-2026-47295 [HIGH] CWE-89 CVE-2026-47295: Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server a Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2026-40370P2HIGHCVSS 8.8≥ 17.0.4040.1, < 17.0.4040.12026-05-12
CVE-2026-40370 [HIGH] CWE-73 CVE-2026-40370: External control of file name or path in SQL Server allows an authorized attacker to execute code ov External control of file name or path in SQL Server allows an authorized attacker to execute code over a network.
nvd
CVE-2026-32167P3HIGHCVSS 7.8≥ 17.0.4030.1, < 17.0.4030.12026-04-14
CVE-2026-32167 [HIGH] CWE-89 CVE-2026-32167: Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server a Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-32176P3HIGHCVSS 7.8≥ 17.0.4030.1, < 17.0.4030.12026-04-14
CVE-2026-32176 [HIGH] CWE-89 CVE-2026-32176: Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server a Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-47296P3HIGHCVSS 7.8≥ 17.0.4060.2, < 17.0.4060.22026-07-14
CVE-2026-47296 [HIGH] CWE-89 CVE-2026-47296: Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server a Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-55002P3HIGHCVSS 7.8≥ 17.0.4060.2, < 17.0.4060.22026-07-14
CVE-2026-55002 [HIGH] CWE-73 CVE-2026-55002: External control of file name or path in SQL Server allows an authorized attacker to elevate privile External control of file name or path in SQL Server allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-54116P3MEDIUMCVSS 6.5≥ 17.0.4060.2, < 17.0.4060.22026-07-14
CVE-2026-54116 [MEDIUM] CWE-843 CVE-2026-54116: Access of resource using incompatible type ('type confusion') in SQL Server allows an authorized att Access of resource using incompatible type ('type confusion') in SQL Server allows an authorized attacker to disclose information over a network.
nvd
CVE-2026-50468P3MEDIUMCVSS 6.5≥ 17.0.4060.2, < 17.0.4060.22026-07-14
CVE-2026-50468 [MEDIUM] CWE-126 CVE-2026-50468: Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network. Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.
nvd
Microsoft Sql Server 2025 vulnerabilities | cvebase