本ページは microsoft sql_server_2022 に影響する公開済み CVE(NVD の CPE 経由で関連付け)を列挙します。各行に深刻度指標・概要・公開日が含まれます。
| CVE | 概要 | ソース | CVSS 最大値 | EPSS(%) | 公開 | 更新 |
|---|---|---|---|---|---|---|
| CVE-2026-33120 | Untrusted pointer dereference in SQL Server allows an authorized attacker to execute code over a network. | [email protected] | 8.8 | 0.06% | 2026-04-14 | 2026-05-06 |
| CVE-2026-32176 | Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges locally. | [email protected] | 6.7 | 0.07% | 2026-04-14 | 2026-05-07 |
| CVE-2026-32167 | Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges locally. | [email protected] | 6.7 | 0.05% | 2026-04-14 | 2026-05-07 |
| CVE-2026-26116 | Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. | [email protected] | 8.8 | 0.07% | 2026-03-10 | 2026-03-13 |
| CVE-2026-26115 | Improper validation of specified type of input in SQL Server allows an authorized attacker to elevate privileges over a network. | [email protected] | 8.8 | 0.09% | 2026-03-10 | 2026-03-13 |
| CVE-2026-21262 | Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network. | [email protected] | 8.8 | 0.10% | 2026-03-10 | 2026-03-13 |
| CVE-2026-20803 | Missing authentication for critical function in SQL Server allows an authorized attacker to elevate privileges over a network. | [email protected] | 7.2 | 0.07% | 2026-01-13 | 2026-01-16 |
| CVE-2025-59499 | Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. | [email protected] | 8.8 | 0.11% | 2025-11-11 | 2025-11-17 |
| CVE-2025-55227 | Improper neutralization of special elements used in a command ('command injection') in SQL Server allows an authorized attacker to elevate privileges over a network. | [email protected] | 8.8 | 0.19% | 2025-09-09 | 2025-09-12 |
| CVE-2025-47997 | Concurrent execution using shared resource with improper synchronization ('race condition') in SQL Server allows an authorized attacker to disclose information over a network. | [email protected] | 6.5 | 0.22% | 2025-09-09 | 2025-09-12 |
| CVE-2025-53727 | Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. | [email protected] | 8.8 | 0.87% | 2025-08-12 | 2025-08-14 |
| CVE-2025-49759 | Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. | [email protected] | 8.8 | 1.24% | 2025-08-12 | 2025-08-14 |
| CVE-2025-49758 | Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. | [email protected] | 8.8 | 0.76% | 2025-08-12 | 2025-08-14 |
| CVE-2025-47954 | Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. | [email protected] | 8.8 | 1.67% | 2025-08-12 | 2025-08-14 |
| CVE-2025-24999 | Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network. | [email protected] | 8.8 | 0.76% | 2025-08-12 | 2025-08-14 |
| CVE-2025-49719 | Improper input validation in SQL Server allows an unauthorized attacker to disclose information over a network. | [email protected] | 7.5 | 8.39% | 2025-07-08 | 2025-07-17 |
| CVE-2025-49718 | Use of uninitialized resource in SQL Server allows an unauthorized attacker to disclose information over a network. | [email protected] | 7.5 | 21.98% | 2025-07-08 | 2025-07-17 |
| CVE-2025-49717 | Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network. | [email protected] | 8.5 | 0.39% | 2025-07-08 | 2025-07-17 |
| CVE-2024-49043 | Microsoft.SqlServer.XEvent.Configuration.dll Remote Code Execution Vulnerability | [email protected] | 7.8 | 0.40% | 2024-11-12 | 2024-11-15 |
| CVE-2024-49021 | Microsoft SQL Server Remote Code Execution Vulnerability | [email protected] | 7.8 | 0.81% | 2024-11-12 | 2024-11-15 |