sql_server_2025 vulnerabilities
CVEs whose affected-version data names the sql_server_2025 package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
55 CVEsRSS
CVE-2026-67393Medium· 6.5Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.
Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.
CVE-2026-67390Medium· 6.5Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.
Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.
CVE-2026-67389Medium· 6.5Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
CVE-2026-67388High· 8.8Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
CVE-2026-67386Medium· 6.5Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network.
Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network.
CVE-2026-67385High· 8.8Use after free in SQL Server allows an authorized attacker to execute code over a network.
Use after free in SQL Server allows an authorized attacker to execute code over a network.
CVE-2026-67384High· 8.8Integer overflow or wraparound in SQL Server allows an authorized attacker to execute code over a network.
Integer overflow or wraparound in SQL Server allows an authorized attacker to execute code over a network.
CVE-2026-67383Medium· 6.5Generation of error message containing sensitive information in SQL Server allows an authorized attacker to disclose information over a network.
Generation of error message containing sensitive information in SQL Server allows an authorized attacker to disclose information over a network.
CVE-2026-67381High· 8.8Heap-based buffer overflow in SQL Server allows an authorized attacker to elevate privileges over a network.
Heap-based buffer overflow in SQL Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-67380High· 8.8Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
CVE-2026-67379High· 8.5Stack-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
Stack-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
CVE-2026-67378Critical· 9.0Untrusted pointer dereference in SQL Server allows an unauthorized attacker to execute code over a network.
Untrusted pointer dereference in SQL Server allows an unauthorized attacker to execute code over a network.
CVE-2026-67376High· 7.5Integer overflow or wraparound in SQL Server allows an unauthorized attacker to deny service over a network.
Integer overflow or wraparound in SQL Server allows an unauthorized attacker to deny service over a network.
CVE-2026-67373High· 8.8Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.
CVE-2026-67370High· 8.8Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-67369Medium· 6.5Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.
CVE-2026-67368High· 8.8Improper link resolution before file access ('link following') in SQL Server allows an authorized attacker to elevate privileges over a network.
Improper link resolution before file access ('link following') in SQL Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-66820High· 8.8Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-66819High· 8.8Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-66818High· 8.8Improper privilege management in SQL Server allows an authorized attacker to elevate privileges over a network.
Improper privilege management in SQL Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-66816Medium· 6.5Insufficient logging in SQL Server allows an authorized attacker to bypass a security feature over a network.
Insufficient logging in SQL Server allows an authorized attacker to bypass a security feature over a network.
CVE-2026-66814High· 8.8Insufficient granularity of access control in SQL Server allows an authorized attacker to elevate privileges over a network.
Insufficient granularity of access control in SQL Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-47296High· 7.8Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges locally.
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges locally.
CVE-2026-21262High· 8.8Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.
Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-20803High· 7.2Missing authentication for critical function in SQL Server allows an authorized attacker to elevate privileges over a network.
Missing authentication for critical function in SQL Server allows an authorized attacker to elevate privileges over a network.