Microsoft
Microsoft SQL Server: vulnerabilidades y CVE
Microsoft SQL Server tiene 118 vulnerabilidades publicadas, 10 de ellas en los últimos 12 meses. 3 son críticas y 3 figuran en el catálogo de explotación activa de CISA.
CVE118
Últimos 12 meses10
Críticas3
Explotadas activamente3
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2019-1068 | Alta (8.8) | 57% | ⚠ Explotación activa | 15 jul 2019 | A remote code execution vulnerability exists in Microsoft SQL Server when it incorrectly handles processing of internal functions, aka 'Microsoft SQL Server Remote Code Execution Vulnerability'. |
| CVE-2020-0618 | Alta (8.8) | 99% | ⚠ Explotación activa | 11 feb 2020 | A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page requests, aka 'Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability'. |
| CVE-2012-1856 | Alta (8.8) | 72% | ⚠ Explotación activa | 15 ago 2012 | The TabStrip ActiveX control in the Common Controls in MSCOMCTL.OCX in Microsoft Office 2003 SP3, Office 2003 Web Components SP3, Office 2007 SP2 and SP3, Office 2010 SP1, SQL Server 2000 SP4, SQL Server 2005 SP4, SQL… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-58385 | Crítica (9.3) | 0.38% | — | 15 sept 2026 | Yonyou U8 CRM contains an unauthenticated SQL injection vulnerability in the fillbacksettingedit.php configuration endpoint where the DontCheckLogin=1 parameter bypasses authentication and the id parameter is… |
| CVE-2026-69562 | Media (6.5) | 0.94% | — | 8 sept 2026 | Out-of-bounds read in SQL Server allows an unauthorized attacker to disclose information over a network. |
| CVE-2026-67630 | Media (6.5) | 0.99% | — | 8 sept 2026 | Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. |
| CVE-2026-67629 | Media (6.5) | 0.99% | — | 8 sept 2026 | Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. |
| CVE-2026-67624 | Media (6.5) | 0.99% | — | 8 sept 2026 | Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. |
| CVE-2026-65669 | Crítica (9.6) | 0.88% | — | 8 sept 2026 | Improper neutralization of special elements in output used by a downstream component ('injection') in SQL Server allows an unauthorized attacker to elevate privileges over a network. |
| CVE-2026-47297 | Alta (8.1) | 1.1% | — | 8 sept 2026 | Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network. |
| CVE-2026-19475 | Media (6.5) | 0.40% | — | 2 sept 2026 | An authenticated user with permission to query a SQL data source can bypass the fix for CVE-2026-33375 by injecting the timeGroup macro through a WHERE clause, which Grafana's regex-based macro parsing does not reject.… |
| CVE-2024-58374 | Alta (8.7) | 0.74% | — | 13 ago 2026 | Hongjing e-HR contains an unauthenticated SQL injection vulnerability in the getSdutyTree servlet endpoint that allows remote unauthenticated attackers to access protected resources by supplying a path traversal… |
| CVE-2026-6093 | Media (6) | 0.28% | — | 11 may 2026 | Corteza contains a SQL injection vulnerability in its Microsoft SQL Server (MSSQL) backend when filtering Compose records by the meta field.This issue affects corteza: 2024.9.8. |
| CVE-2024-0056 | Alta (8.7) | 1.2% | — | 9 ene 2024 | Microsoft.Data.SqlClient and System.Data.SqlClient SQL Data Provider Security Feature Bypass Vulnerability |
| CVE-2023-36785 | Alta (7.8) | 1.1% | — | 10 oct 2023 | Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability |
| CVE-2023-36730 | Alta (7.8) | 1.0% | — | 10 oct 2023 | Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability |
| CVE-2023-36728 | Media (5.5) | 0.85% | — | 10 oct 2023 | Microsoft SQL Server Denial of Service Vulnerability |
| CVE-2023-36420 | Alta (7.8) | 0.98% | — | 10 oct 2023 | Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability |
| CVE-2023-36417 | Alta (7.8) | 0.98% | — | 10 oct 2023 | Microsoft SQL OLE DB Remote Code Execution Vulnerability |
| CVE-2023-38169 | Alta (8.8) | 1.3% | — | 8 ago 2023 | Microsoft SQL OLE DB Remote Code Execution Vulnerability |
| CVE-2023-32028 | Alta (7.8) | 0.72% | — | 16 jun 2023 | Microsoft SQL OLE DB Remote Code Execution Vulnerability |
| CVE-2023-32027 | Alta (7.8) | 0.60% | — | 16 jun 2023 | Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability |
| CVE-2023-32026 | Alta (7.8) | 0.72% | — | 16 jun 2023 | Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability |
| CVE-2023-32025 | Alta (7.8) | 0.60% | — | 16 jun 2023 | Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability |
| CVE-2023-29356 | Alta (7.8) | 0.60% | — | 16 jun 2023 | Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability |
| CVE-2023-29349 | Alta (7.8) | 0.60% | — | 16 jun 2023 | Microsoft ODBC and OLE DB Remote Code Execution Vulnerability |
| CVE-2023-23384 | Alta (7.3) | 0.87% | — | 11 abr 2023 | Microsoft SQL Server Remote Code Execution Vulnerability |
| CVE-2023-21718 | Alta (7.8) | 0.74% | — | 14 feb 2023 | Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability |
| CVE-2023-21713 | Alta (8.8) | 1.8% | — | 14 feb 2023 | Microsoft SQL Server Remote Code Execution Vulnerability |
| CVE-2023-21705 | Alta (8.8) | 1.1% | — | 14 feb 2023 | Microsoft SQL Server Remote Code Execution Vulnerability |
| CVE-2023-21704 | Alta (7.8) | 0.39% | — | 14 feb 2023 | Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability |
| CVE-2023-21528 | Alta (7.8) | 0.39% | — | 14 feb 2023 | Microsoft SQL Server Remote Code Execution Vulnerability |
| CVE-2022-29143 | Alta (7.5) | 1.9% | — | 15 jun 2022 | Microsoft SQL Server Remote Code Execution Vulnerability |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.