📦 Sql Server 2022

by Microsoft

🔍 What is Sql Server 2022?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2026-20803

HIGH CVSS 7.2 Jan 13, 2026

This vulnerability in SQL Server allows attackers with existing network access to bypass authentication checks and execute privileged functions. It affects organizations running vulnerable SQL Server ...

CVE-2025-59499

HIGH CVSS 8.8 Nov 11, 2025

This SQL injection vulnerability in Microsoft SQL Server allows authenticated attackers to execute arbitrary SQL commands, potentially leading to privilege escalation. It affects SQL Server instances ...

CVE-2025-55227

HIGH CVSS 8.8 Sep 9, 2025

This command injection vulnerability in SQL Server allows authenticated attackers to execute arbitrary commands on the database server, potentially gaining full system control. It affects SQL Server i...

CVE-2025-49759

HIGH CVSS 8.8 Aug 12, 2025

This SQL injection vulnerability in Microsoft SQL Server allows authenticated attackers to execute arbitrary SQL commands, potentially leading to privilege escalation. It affects SQL Server instances ...

CVE-2025-24999

HIGH CVSS 8.8 Aug 12, 2025

This vulnerability allows an authenticated attacker with existing SQL Server access to elevate privileges over the network, potentially gaining administrative control. It affects Microsoft SQL Server ...

CVE-2025-49718

HIGH CVSS 7.5 Jul 8, 2025

This vulnerability in SQL Server involves improper initialization of resources, allowing unauthorized attackers to read uninitialized memory contents over the network. This can lead to information dis...

CVE-2024-49021

HIGH CVSS 7.8 Nov 12, 2024

This vulnerability allows remote attackers to execute arbitrary code on Microsoft SQL Server instances by exploiting a use-after-free memory corruption flaw. It affects SQL Server installations with n...

CVE-2024-37965

HIGH CVSS 8.8 Sep 10, 2024

This CVE describes an elevation of privilege vulnerability in Microsoft SQL Server where an authenticated attacker could execute arbitrary code with elevated privileges. It affects SQL Server instance...

CVE-2024-37980

HIGH CVSS 8.8 Sep 10, 2024

This vulnerability in Microsoft SQL Server allows authenticated attackers to elevate their privileges within the database system. Attackers could gain administrative control over SQL Server instances,...

CVE-2024-37339

HIGH CVSS 8.8 Sep 10, 2024

This vulnerability in Microsoft SQL Server's Native Scoring component allows authenticated attackers to execute arbitrary code remotely. It affects SQL Server instances with the Native Scoring feature...

CVE-2024-37341

HIGH CVSS 8.8 Sep 10, 2024

This vulnerability in Microsoft SQL Server allows authenticated attackers to execute arbitrary code with elevated privileges, potentially gaining full control of the database server. It affects SQL Se...

CVE-2024-37337

HIGH CVSS 7.1 Sep 10, 2024

This vulnerability in Microsoft SQL Server Native Scoring allows an authenticated attacker to read sensitive information from memory. It affects SQL Server instances where the Native Scoring feature i...

CVE-2024-26186

HIGH CVSS 8.8 Sep 10, 2024

This vulnerability in Microsoft SQL Server Native Scoring allows remote attackers to execute arbitrary code on affected systems. Attackers can exploit this use-after-free vulnerability to gain SYSTEM ...

CVE-2024-38087

HIGH CVSS 8.8 Jul 9, 2024

This vulnerability in SQL Server Native Client OLE DB Provider allows remote attackers to execute arbitrary code on affected systems by sending specially crafted requests. It affects systems using thi...

CVE-2024-37332

HIGH CVSS 8.8 Jul 9, 2024

This vulnerability in SQL Server Native Client OLE DB Provider allows remote attackers to execute arbitrary code on affected systems by sending specially crafted requests. It affects applications usin...

CVE-2024-37334

HIGH CVSS 8.8 Jul 9, 2024

This vulnerability in Microsoft OLE DB Driver for SQL Server allows remote attackers to execute arbitrary code on affected systems by sending specially crafted requests. It affects applications using ...

CVE-2024-37328

HIGH CVSS 8.8 Jul 9, 2024

This vulnerability in SQL Server Native Client OLE DB Provider allows remote attackers to execute arbitrary code on affected systems by sending specially crafted requests. It affects applications usin...

CVE-2024-37330

HIGH CVSS 8.8 Jul 9, 2024

This vulnerability in SQL Server Native Client OLE DB Provider allows remote attackers to execute arbitrary code on affected systems by sending specially crafted requests. It affects applications usin...

CVE-2024-37321

HIGH CVSS 8.8 Jul 9, 2024

This vulnerability in SQL Server Native Client OLE DB Provider allows remote attackers to execute arbitrary code on affected systems by sending specially crafted requests. It affects systems using the...

CVE-2024-37323

HIGH CVSS 8.8 Jul 9, 2024

This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of SQL Server Native Client OLE DB Provider. Attackers can exploit this integer overflow vul...

CVE-2024-37326

HIGH CVSS 8.8 Jul 9, 2024

This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of SQL Server Native Client OLE DB Provider. Attackers can exploit this heap-based buffer ov...

CVE-2024-35271

HIGH CVSS 8.8 Jul 9, 2024

This vulnerability in SQL Server Native Client OLE DB Provider allows remote attackers to execute arbitrary code by sending specially crafted requests to an affected system. It affects applications us...

CVE-2024-37319

HIGH CVSS 8.8 Jul 9, 2024

This vulnerability in SQL Server Native Client OLE DB Provider allows remote attackers to execute arbitrary code by sending specially crafted requests to an affected system. It affects systems running...

CVE-2024-21449

HIGH CVSS 8.8 Jul 9, 2024

This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of SQL Server Native Client OLE DB Provider. Attackers can exploit this heap-based buffer ov...

CVE-2024-21414

HIGH CVSS 8.8 Jul 9, 2024

This vulnerability in SQL Server Native Client OLE DB Provider allows remote attackers to execute arbitrary code on affected systems by sending specially crafted requests. It affects systems using thi...

CVE-2024-21425

HIGH CVSS 8.8 Jul 9, 2024

This vulnerability in SQL Server Native Client OLE DB Provider allows remote attackers to execute arbitrary code on affected systems by sending specially crafted queries. It affects systems running vu...

CVE-2024-21333

HIGH CVSS 8.8 Jul 9, 2024

This vulnerability in SQL Server Native Client OLE DB Provider allows remote attackers to execute arbitrary code on affected systems by sending specially crafted requests. It affects systems using the...

CVE-2024-21373

HIGH CVSS 8.8 Jul 9, 2024

This vulnerability in SQL Server Native Client OLE DB Provider allows remote attackers to execute arbitrary code on affected systems by sending specially crafted requests. It affects systems using the...

CVE-2024-21308

HIGH CVSS 8.8 Jul 9, 2024

This vulnerability in SQL Server Native Client OLE DB Provider allows remote attackers to execute arbitrary code on affected systems by sending specially crafted requests. It affects systems using thi...

CVE-2024-21331

HIGH CVSS 8.8 Jul 9, 2024

This vulnerability in SQL Server Native Client OLE DB Provider allows remote attackers to execute arbitrary code on affected systems by sending specially crafted requests. It affects systems running v...

CVE-2024-20701

HIGH CVSS 8.8 Jul 9, 2024

This vulnerability in SQL Server Native Client OLE DB Provider allows remote attackers to execute arbitrary code on affected systems by sending specially crafted requests. It affects applications usin...

CVE-2024-29982

HIGH CVSS 8.8 Apr 9, 2024

This vulnerability in Microsoft OLE DB Driver for SQL Server allows remote attackers to execute arbitrary code on affected systems by sending specially crafted requests. It affects applications using ...

CVE-2024-29984

HIGH CVSS 8.8 Apr 9, 2024

This vulnerability in Microsoft OLE DB Driver for SQL Server allows remote attackers to execute arbitrary code on affected systems by sending specially crafted requests. It affects applications using ...

CVE-2024-29048

HIGH CVSS 8.8 Apr 9, 2024

This vulnerability in Microsoft OLE DB Driver for SQL Server allows remote attackers to execute arbitrary code on affected systems by sending specially crafted requests. It affects applications using ...

CVE-2024-29043

HIGH CVSS 8.8 Apr 9, 2024

This vulnerability in Microsoft ODBC Driver for SQL Server allows an attacker to execute arbitrary code on affected systems by sending specially crafted queries. It affects applications using vulnerab...

CVE-2024-29044

HIGH CVSS 8.8 Apr 9, 2024

This vulnerability in Microsoft OLE DB Driver for SQL Server allows remote attackers to execute arbitrary code on affected systems by sending specially crafted requests. It affects applications using ...

CVE-2024-29046

HIGH CVSS 8.8 Apr 9, 2024

This vulnerability in Microsoft OLE DB Driver for SQL Server allows remote attackers to execute arbitrary code on affected systems by sending specially crafted requests. It affects applications using ...

CVE-2024-28940

HIGH CVSS 8.8 Apr 9, 2024

This vulnerability in Microsoft OLE DB Driver for SQL Server allows remote attackers to execute arbitrary code on affected systems by sending specially crafted requests. It affects applications using ...

CVE-2024-28942

HIGH CVSS 8.8 Apr 9, 2024

This vulnerability in Microsoft OLE DB Driver for SQL Server allows remote attackers to execute arbitrary code on affected systems by sending specially crafted requests. It affects applications using ...

CVE-2024-28944

HIGH CVSS 8.8 Apr 9, 2024

This vulnerability in Microsoft OLE DB Driver for SQL Server allows remote attackers to execute arbitrary code on affected systems by sending specially crafted requests. It affects applications using ...