cbcvebase.

Microsoft Sql Server 2016 vulnerabilities

99 known vulnerabilities affecting microsoft/sql_server_2016.

Total CVEs
99
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
2
Severity breakdown
CRITICAL4HIGH92MEDIUM3

Vulnerabilities

Page 2 of 5
CVE-2025-49758P3HIGHCVSS 8.8≥ 13.0.6300.2, < 13.0.6465.1≥ 13.0.7000.253, < 13.0.7060.12025-08-12
CVE-2025-49758 [HIGH] CWE-269 CVE-2025-49758: Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server a Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2024-37341P3CRITICALCVSS 9.8≥ 13.0.6300.2, < 13.0.6441.12024-09-10
CVE-2024-37341 [CRITICAL] CWE-284 CVE-2024-37341: Microsoft SQL Server Elevation of Privilege Vulnerability Microsoft SQL Server Elevation of Privilege Vulnerability
nvd
CVE-2024-37965P2HIGHCVSS 8.8≥ 13.0.6300.2, < 13.0.6445.1≥ 13.0.7000.253, < 13.0.7040.12024-09-10
CVE-2024-37965 [HIGH] CWE-20 CVE-2024-37965: Microsoft SQL Server Elevation of Privilege Vulnerability Microsoft SQL Server Elevation of Privilege Vulnerability
nvd
CVE-2024-37980P3CRITICALCVSS 9.8≥ 13.0.6300.2, < 13.0.6445.1≥ 13.0.7000.253, < 13.0.7040.12024-09-10
CVE-2024-37980 [CRITICAL] CWE-269 CVE-2024-37980: Microsoft SQL Server Elevation of Privilege Vulnerability Microsoft SQL Server Elevation of Privilege Vulnerability
nvd
CVE-2025-49719P3HIGHCVSS 7.5≥ 13.0.6300.2, < 13.0.6460.7≥ 13.0.7000.253, < 13.0.7055.92025-07-08
CVE-2025-49719 [HIGH] CWE-20 CVE-2025-49719: Improper input validation in SQL Server allows an unauthorized attacker to disclose information over Improper input validation in SQL Server allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2024-37332P3HIGHCVSS 8.8fixed in 13.0.6441.1≥ 13.0.7000.253, < 13.0.7037.12024-07-09
CVE-2024-37332 [HIGH] CWE-122 CVE-2024-37332: SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability
nvd
CVE-2024-21414P3HIGHCVSS 8.8≥ 13.0.6300.2, < 13.0.6441.1≥ 13.0.7000.253, < 13.0.7037.12024-07-09
CVE-2024-21414 [HIGH] CWE-122 CVE-2024-21414: SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability
nvd
CVE-2024-37318P3HIGHCVSS 8.8fixed in 13.0.6441.1≥ 13.0.7000.253, < 13.0.7037.12024-07-09
CVE-2024-37318 [HIGH] CWE-122 CVE-2024-37318: SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability
nvd
CVE-2024-35272P3HIGHCVSS 8.8fixed in 13.0.6441.1≥ 13.0.7000.253, < 13.0.7037.12024-07-09
CVE-2024-35272 [HIGH] CWE-122 CVE-2024-35272: SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability
nvd
CVE-2024-21398P3HIGHCVSS 8.8≥ 13.0.6300.2, < 13.0.6441.1≥ 13.0.7000.253, < 13.0.7037.12024-07-09
CVE-2024-21398 [HIGH] CWE-122 CVE-2024-21398: SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability
nvd
CVE-2024-37331P3HIGHCVSS 8.8fixed in 13.0.6441.1≥ 13.0.7000.253, < 13.0.7037.12024-07-09
CVE-2024-37331 [HIGH] CWE-122 CVE-2024-37331: SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability
nvd
CVE-2024-35271P3HIGHCVSS 8.8fixed in 13.0.6441.1≥ 13.0.7000.253, < 13.0.7037.12024-07-09
CVE-2024-35271 [HIGH] CWE-122 CVE-2024-35271: SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability
nvd
CVE-2024-48995P3HIGHCVSS 8.8≥ 13.0.6300.2, < 13.0.6455.2≥ 13.0.7000.253, < 13.0.7050.22024-11-12
CVE-2024-48995 [HIGH] CWE-122 CVE-2024-48995: SQL Server Native Client Remote Code Execution Vulnerability SQL Server Native Client Remote Code Execution Vulnerability
nvd
CVE-2024-38255P3HIGHCVSS 8.8≥ 13.0.6300.2, < 13.0.6455.2≥ 13.0.7000.253, < 13.0.7050.22024-11-12
CVE-2024-38255 [HIGH] CWE-122 CVE-2024-38255: SQL Server Native Client Remote Code Execution Vulnerability SQL Server Native Client Remote Code Execution Vulnerability
nvd
CVE-2024-48996P3HIGHCVSS 8.8≥ 13.0.6300.2, < 13.0.6455.2≥ 13.0.7000.253, < 13.0.7050.22024-11-12
CVE-2024-48996 [HIGH] CWE-122 CVE-2024-48996: SQL Server Native Client Remote Code Execution Vulnerability SQL Server Native Client Remote Code Execution Vulnerability
nvd
CVE-2024-48994P3HIGHCVSS 8.8≥ 13.0.6300.2, < 13.0.6455.2≥ 13.0.7000.253, < 13.0.7050.22024-11-12
CVE-2024-48994 [HIGH] CWE-122 CVE-2024-48994: SQL Server Native Client Remote Code Execution Vulnerability SQL Server Native Client Remote Code Execution Vulnerability
nvd
CVE-2024-43459P3HIGHCVSS 8.8≥ 13.0.6300.2, < 13.0.6455.2≥ 13.0.7000.253, < 13.0.7050.22024-11-12
CVE-2024-43459 [HIGH] CWE-416 CVE-2024-43459: SQL Server Native Client Remote Code Execution Vulnerability SQL Server Native Client Remote Code Execution Vulnerability
nvd
CVE-2024-48993P3HIGHCVSS 8.8≥ 13.0.6300.2, < 13.0.6455.2≥ 13.0.7000.253, < 13.0.7050.22024-11-12
CVE-2024-48993 [HIGH] CWE-122 CVE-2024-48993: SQL Server Native Client Remote Code Execution Vulnerability SQL Server Native Client Remote Code Execution Vulnerability
nvd
CVE-2024-43462P3HIGHCVSS 8.8≥ 13.0.6300.2, < 13.0.6455.2≥ 13.0.7000.253, < 13.0.7050.22024-11-12
CVE-2024-43462 [HIGH] CWE-122 CVE-2024-43462: SQL Server Native Client Remote Code Execution Vulnerability SQL Server Native Client Remote Code Execution Vulnerability
nvd
CVE-2026-47296P3HIGHCVSS 7.5≥ 13.0.6300.2, < 13.0.6500.1≥ 13.0.7000.253, < 13.0.7095.12026-07-14
CVE-2026-47296 [HIGH] CWE-89 CVE-2026-47296: Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server a Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.
nvd
Microsoft Sql Server 2016 vulnerabilities | cvebase