本页列出影响 microsoft sql_server_2025 的已公开 CVE 漏洞(通过 NVD CPE 关联)。每行包含严重程度评分、摘要与发布日期,便于识别与分析安全问题。
| CVE | 摘要 | 来源 | 最高 CVSS | EPSS % | 公开时间 | 更新时间 |
|---|---|---|---|---|---|---|
| CVE-2026-33120 | Untrusted pointer dereference in SQL Server allows an authorized attacker to execute code over a network. | [email protected] | 8.8 | 0.06% | 2026-04-14 | 2026-05-06 |
| CVE-2026-32176 | Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges locally. | [email protected] | 6.7 | 0.07% | 2026-04-14 | 2026-05-07 |
| CVE-2026-32167 | Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges locally. | [email protected] | 6.7 | 0.05% | 2026-04-14 | 2026-05-07 |
| CVE-2026-26116 | Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. | [email protected] | 8.8 | 0.07% | 2026-03-10 | 2026-03-13 |
| CVE-2026-26115 | Improper validation of specified type of input in SQL Server allows an authorized attacker to elevate privileges over a network. | [email protected] | 8.8 | 0.09% | 2026-03-10 | 2026-03-13 |
| CVE-2026-21262 | Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network. | [email protected] | 8.8 | 0.10% | 2026-03-10 | 2026-03-13 |
| CVE-2026-20803 | Missing authentication for critical function in SQL Server allows an authorized attacker to elevate privileges over a network. | [email protected] | 7.2 | 0.07% | 2026-01-13 | 2026-01-16 |