Search Results (5 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-67384 1 Microsoft 12 Microsoft Sql Server 2017 (cu 31), Microsoft Sql Server 2017 (gdr), Microsoft Sql Server 2019 (cu 32) and 9 more 2026-09-08 8.8 High
Integer overflow or wraparound in SQL Server allows an authorized attacker to execute code over a network.
CVE-2026-66814 1 Microsoft 12 Microsoft Sql Server 2017 (cu 31), Microsoft Sql Server 2017 (gdr), Microsoft Sql Server 2019 (cu 32) and 9 more 2026-09-08 8.8 High
Insufficient granularity of access control in SQL Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-66816 1 Microsoft 6 Microsoft Sql Server 2022 (cu 26), Microsoft Sql Server 2022 (gdr), Microsoft Sql Server 2025 (cu8) and 3 more 2026-09-08 6.5 Medium
Insufficient logging in SQL Server allows an authorized attacker to bypass a security feature over a network.
CVE-2026-66818 1 Microsoft 12 Microsoft Sql Server 2017 (cu 31), Microsoft Sql Server 2017 (gdr), Microsoft Sql Server 2019 (cu 32) and 9 more 2026-09-08 8.8 High
Improper privilege management in SQL Server allows an authorized attacker to elevate privileges over a network.
CVE-2026-67381 1 Microsoft 12 Microsoft Sql Server 2017 (cu 31), Microsoft Sql Server 2017 (gdr), Microsoft Sql Server 2019 (cu 32) and 9 more 2026-09-08 8.8 High
Heap-based buffer overflow in SQL Server allows an authorized attacker to elevate privileges over a network.