cbcvebase.

Microsoft Sql Server 2019 vulnerabilities

140 known vulnerabilities affecting microsoft/sql_server_2019.

Total CVEs
140
CISA KEV
0
Public exploits
0
Exploited in wild
1
Severity breakdown
CRITICAL2HIGH135MEDIUM3

Vulnerabilities

Page 7 of 7
CVE-2024-49013P3HIGHCVSS 8.8≥ 15.0.2000.5, < 15.0.2130.3≥ 15.0.4003.23, < 15.0.4410.12024-11-12
CVE-2024-49013 [HIGH] CWE-122 CVE-2024-49013: SQL Server Native Client Remote Code Execution Vulnerability SQL Server Native Client Remote Code Execution Vulnerability
nvd
CVE-2024-48999P3HIGHCVSS 8.8≥ 15.0.2000.5, < 15.0.2130.3≥ 15.0.4003.23, < 15.0.4410.12024-11-12
CVE-2024-48999 [HIGH] CWE-122 CVE-2024-48999: SQL Server Native Client Remote Code Execution Vulnerability SQL Server Native Client Remote Code Execution Vulnerability
nvd
CVE-2024-49014P3HIGHCVSS 8.8≥ 15.0.2000.5, < 15.0.2130.3≥ 15.0.4003.23, < 15.0.4410.12024-11-12
CVE-2024-49014 [HIGH] CWE-415 CVE-2024-49014: SQL Server Native Client Remote Code Execution Vulnerability SQL Server Native Client Remote Code Execution Vulnerability
nvd
CVE-2024-48997P3HIGHCVSS 8.8≥ 15.0.2000.5, < 15.0.2130.3≥ 15.0.4003.23, < 15.0.4410.12024-11-12
CVE-2024-48997 [HIGH] CWE-122 CVE-2024-48997: SQL Server Native Client Remote Code Execution Vulnerability SQL Server Native Client Remote Code Execution Vulnerability
nvd
CVE-2024-49017P3HIGHCVSS 8.8≥ 15.0.2000.5, < 15.0.2130.3≥ 15.0.4003.23, < 15.0.4410.12024-11-12
CVE-2024-49017 [HIGH] CWE-122 CVE-2024-49017: SQL Server Native Client Remote Code Execution Vulnerability SQL Server Native Client Remote Code Execution Vulnerability
nvd
CVE-2024-49006P3HIGHCVSS 8.8≥ 15.0.2000.5, < 15.0.2130.3≥ 15.0.4003.23, < 15.0.4410.12024-11-12
CVE-2024-49006 [HIGH] CWE-122 CVE-2024-49006: SQL Server Native Client Remote Code Execution Vulnerability SQL Server Native Client Remote Code Execution Vulnerability
nvd
CVE-2024-49009P3HIGHCVSS 8.8≥ 15.0.2000.5, < 15.0.2130.3≥ 15.0.4003.23, < 15.0.4410.12024-11-12
CVE-2024-49009 [HIGH] CWE-122 CVE-2024-49009: SQL Server Native Client Remote Code Execution Vulnerability SQL Server Native Client Remote Code Execution Vulnerability
nvd
CVE-2024-37334P3HIGHCVSS 8.8fixed in 15.0.2116.2≥ 15.0.4375.4, < 15.0.4382.12024-07-09
CVE-2024-37334 [HIGH] CWE-122 CVE-2024-37334: Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
nvd
CVE-2025-49718P3HIGHCVSS 7.5≥ 15.0.2000.5, < 15.0.2135.5≥ 15.0.4003.23, < 15.0.4435.72025-07-08
CVE-2025-49718 [HIGH] CWE-908 CVE-2025-49718: Use of uninitialized resource in SQL Server allows an unauthorized attacker to disclose information Use of uninitialized resource in SQL Server allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2026-32167P3HIGHCVSS 7.8≥ 15.0.2000.5, < 15.0.2165.1≥ 15.0.4003.23, < 15.0.4465.12026-04-14
CVE-2026-32167 [HIGH] CWE-89 CVE-2026-32167: Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server a Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-32176P3HIGHCVSS 7.8≥ 15.0.2000.5, < 15.0.2165.1≥ 15.0.4003.23, < 15.0.4465.12026-04-14
CVE-2026-32176 [HIGH] CWE-89 CVE-2026-32176: Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server a Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-47296P3HIGHCVSS 7.8≥ 15.0.2000.5, < 15.0.2180.2≥ 15.0.4003.23, < 15.0.4480.22026-07-14
CVE-2026-47296 [HIGH] CWE-89 CVE-2026-47296: Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server a Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges locally.
nvd
CVE-2024-29045P3HIGHCVSS 7.5≥ 15.0.2000.5, < 15.0.2110.4≥ 15.0.4003.23, < 15.0.4360.22024-04-09
CVE-2024-29045 [HIGH] CWE-121 CVE-2024-29045: Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
nvd
CVE-2024-49021P3HIGHCVSS 7.8≥ 15.0.2000.5, < 15.0.2130.3≥ 15.0.4003.23, < 15.0.4410.12024-11-12
CVE-2024-49021 [HIGH] CWE-416 CVE-2024-49021: Microsoft SQL Server Remote Code Execution Vulnerability Microsoft SQL Server Remote Code Execution Vulnerability
nvd
CVE-2024-43474P3HIGHCVSS 7.5≥ 15.0.2000.5, < 15.0.2120.12024-09-10
CVE-2024-43474 [HIGH] CWE-170 CVE-2024-43474: Microsoft SQL Server Information Disclosure Vulnerability Microsoft SQL Server Information Disclosure Vulnerability
nvd
CVE-2024-49043P3HIGHCVSS 7.8≥ 15.0.2000.5, < 15.0.2130.3≥ 15.0.4003.23, < 15.0.4410.12024-11-12
CVE-2024-49043 [HIGH] CWE-426 CVE-2024-49043: Microsoft.SqlServer.XEvent.Configuration.dll Remote Code Execution Vulnerability Microsoft.SqlServer.XEvent.Configuration.dll Remote Code Execution Vulnerability
nvd
CVE-2024-37966P3HIGHCVSS 7.1≥ 15.0.2000.5, < 15.0.2120.1≥ 15.0.4003.23, < 15.0.4390.22024-09-10
CVE-2024-37966 [HIGH] CWE-125 CVE-2024-37966: Microsoft SQL Server Native Scoring Information Disclosure Vulnerability Microsoft SQL Server Native Scoring Information Disclosure Vulnerability
nvd
CVE-2025-47997P4MEDIUMCVSS 5.3≥ 15.0.2000.5, < 15.0.2145.1≥ 15.0.4003.23, < 15.0.4445.12025-09-09
CVE-2025-47997 [MEDIUM] CWE-200 CVE-2025-47997: Concurrent execution using shared resource with improper synchronization ('race condition') in SQL S Concurrent execution using shared resource with improper synchronization ('race condition') in SQL Server allows an authorized attacker to disclose information over a network.
nvd
CVE-2024-37337P4MEDIUMCVSS 4.3≥ 15.0.2000.5, < 15.0.2120.1≥ 15.0.4003.23, < 15.0.4390.22024-09-10
CVE-2024-37337 [MEDIUM] CWE-197 CVE-2024-37337: Microsoft SQL Server Native Scoring Information Disclosure Vulnerability Microsoft SQL Server Native Scoring Information Disclosure Vulnerability
nvd
CVE-2024-37342P4MEDIUMCVSS 4.3≥ 15.0.2000.5, < 15.0.2120.1≥ 15.0.4003.23, < 15.0.4390.22024-09-10
CVE-2024-37342 [MEDIUM] CWE-125 CVE-2024-37342: Microsoft SQL Server Native Scoring Information Disclosure Vulnerability Microsoft SQL Server Native Scoring Information Disclosure Vulnerability
nvd
Microsoft Sql Server 2019 vulnerabilities | cvebase