CVE-2026-67370
- EPSS 0.67%
- Veröffentlicht 08.09.2026 17:10:41
- Zuletzt bearbeitet 16.09.2026 12:01:45
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-67368
- EPSS 0.71%
- Veröffentlicht 08.09.2026 17:10:40
- Zuletzt bearbeitet 15.09.2026 18:56:31
Improper link resolution before file access ('link following') in SQL Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-47295
- EPSS 0.92%
- Veröffentlicht 14.07.2026 17:08:01
- Zuletzt bearbeitet 22.07.2026 16:50:46
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-55002
- EPSS 0.62%
- Veröffentlicht 14.07.2026 17:05:06
- Zuletzt bearbeitet 04.08.2026 00:17:16
External control of file name or path in SQL Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-54118
- EPSS 1.29%
- Veröffentlicht 14.07.2026 17:05:05
- Zuletzt bearbeitet 20.08.2026 17:18:16
Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network.
CVE-2026-54117
- EPSS 1.29%
- Veröffentlicht 14.07.2026 17:05:04
- Zuletzt bearbeitet 20.08.2026 17:18:16
Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network.
CVE-2026-47296
- EPSS 0.5%
- Veröffentlicht 14.07.2026 17:04:15
- Zuletzt bearbeitet 04.08.2026 00:16:43
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-32176
- EPSS 0.25%
- Veröffentlicht 14.04.2026 16:58:32
- Zuletzt bearbeitet 07.05.2026 19:52:49
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges locally.
CVE-2026-33120
- EPSS 0.71%
- Veröffentlicht 14.04.2026 16:57:48
- Zuletzt bearbeitet 24.07.2026 22:10:00
Untrusted pointer dereference in SQL Server allows an authorized attacker to execute code over a network.
CVE-2026-32167
- EPSS 0.3%
- Veröffentlicht 14.04.2026 16:57:30
- Zuletzt bearbeitet 07.05.2026 19:54:15
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges locally.