Microsoft Sql Server 2022 vulnerabilities
112 known vulnerabilities affecting microsoft/sql_server_2022.
Total CVEs
112
CISA KEV
0
Public exploits
0
Exploited in wild
1
Severity breakdown
CRITICAL2HIGH107MEDIUM3
Vulnerabilities
Page 6 of 6
CVE-2024-37334P3HIGHCVSS 8.8fixed in 16.0.1121.4≥ 16.0.4125.3, < 16.0.4131.22024-07-09
CVE-2024-37334 [HIGH] CWE-122 CVE-2024-37334: Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
nvd
CVE-2025-49718P3HIGHCVSS 7.5≥ 16.0.1000.6, < 16.0.1140.6≥ 16.0.4003.1, < 16.0.4200.12025-07-08
CVE-2025-49718 [HIGH] CWE-908 CVE-2025-49718: Use of uninitialized resource in SQL Server allows an unauthorized attacker to disclose information
Use of uninitialized resource in SQL Server allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2026-32167P3HIGHCVSS 7.8≥ 16.0.1000.6, < 16.0.1175.1≥ 16.0.4003.1, < 16.0.4250.12026-04-14
CVE-2026-32167 [HIGH] CWE-89 CVE-2026-32167: Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server a
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-32176P3HIGHCVSS 7.8≥ 16.0.1000.6, < 16.0.1175.1≥ 16.0.4003.1, < 16.0.4250.12026-04-14
CVE-2026-32176 [HIGH] CWE-89 CVE-2026-32176: Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server a
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-47296P3HIGHCVSS 7.8≥ 16.0.1000.6, < 16.0.1190.2≥ 16.0.4003.1, < 16.0.4262.22026-07-14
CVE-2026-47296 [HIGH] CWE-89 CVE-2026-47296: Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server a
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges locally.
nvd
CVE-2024-29045P3HIGHCVSS 7.5≥ 16.0.1000.6, < 16.0.1115.1≥ 16.0.4003.1, < 16.0.4120.12024-04-09
CVE-2024-29045 [HIGH] CWE-121 CVE-2024-29045: Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
Microsoft OLE DB Driver for SQL Server Remote Code Execution Vulnerability
nvd
CVE-2024-49021P3HIGHCVSS 7.8≥ 16.0.1000.6, < 16.0.1135.2≥ 16.0.4003.1, < 16.0.4155.42024-11-12
CVE-2024-49021 [HIGH] CWE-416 CVE-2024-49021: Microsoft SQL Server Remote Code Execution Vulnerability
Microsoft SQL Server Remote Code Execution Vulnerability
nvd
CVE-2024-49043P3HIGHCVSS 7.8≥ 16.0.1000.6, < 16.0.1135.2≥ 16.0.4003.1, < 16.0.4155.42024-11-12
CVE-2024-49043 [HIGH] CWE-426 CVE-2024-49043: Microsoft.SqlServer.XEvent.Configuration.dll Remote Code Execution Vulnerability
Microsoft.SqlServer.XEvent.Configuration.dll Remote Code Execution Vulnerability
nvd
CVE-2024-37966P3HIGHCVSS 7.1≥ 16.0.1000.6, < 16.0.1125.1≥ 16.0.4003.1, < 16.0.4140.32024-09-10
CVE-2024-37966 [HIGH] CWE-125 CVE-2024-37966: Microsoft SQL Server Native Scoring Information Disclosure Vulnerability
Microsoft SQL Server Native Scoring Information Disclosure Vulnerability
nvd
CVE-2025-47997P4MEDIUMCVSS 5.3≥ 16.0.1000.6, < 16.0.1150.1≥ 16.0.4003.1, < 16.0.4212.12025-09-09
CVE-2025-47997 [MEDIUM] CWE-200 CVE-2025-47997: Concurrent execution using shared resource with improper synchronization ('race condition') in SQL S
Concurrent execution using shared resource with improper synchronization ('race condition') in SQL Server allows an authorized attacker to disclose information over a network.
nvd
CVE-2024-37337P4MEDIUMCVSS 4.3≥ 16.0.1000.6, < 16.0.1125.1≥ 16.0.4003.1, < 16.0.4140.32024-09-10
CVE-2024-37337 [MEDIUM] CWE-197 CVE-2024-37337: Microsoft SQL Server Native Scoring Information Disclosure Vulnerability
Microsoft SQL Server Native Scoring Information Disclosure Vulnerability
nvd
CVE-2024-37342P4MEDIUMCVSS 4.3≥ 16.0.1000.6, < 16.0.1125.1≥ 16.0.4003.1, < 16.0.4140.32024-09-10
CVE-2024-37342 [MEDIUM] CWE-125 CVE-2024-37342: Microsoft SQL Server Native Scoring Information Disclosure Vulnerability
Microsoft SQL Server Native Scoring Information Disclosure Vulnerability
nvd
← Previous6 / 6