radar

ONE Sentinel

shield

CVE Tracker

205,665 total CVEs

Live vulnerability feed from the National Vulnerability Database

6.5

Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.

6.5

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

8.8

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

6.5

Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network.

8.8

Use after free in SQL Server allows an authorized attacker to execute code over a network.

8.8

Integer overflow or wraparound in SQL Server allows an authorized attacker to execute code over a network.

6.5

Generation of error message containing sensitive information in SQL Server allows an authorized attacker to disclose information over a network.

8.8

Heap-based buffer overflow in SQL Server allows an authorized attacker to elevate privileges over a network.

8.8

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

8.5

Stack-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

8.5

Untrusted pointer dereference in SQL Server allows an authorized attacker to execute code over a network.

7.5

Integer overflow or wraparound in SQL Server allows an unauthorized attacker to deny service over a network.

8.8

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

8.8

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.

6.5

Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network.

8.8

Improper link resolution before file access ('link following') in SQL Server allows an authorized attacker to elevate privileges over a network.

8.8

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.

8.8

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.

8.8

Improper privilege management in SQL Server allows an authorized attacker to elevate privileges over a network.

6.5

Insufficient logging in SQL Server allows an authorized attacker to bypass a security feature over a network.

8.8

Insufficient granularity of access control in SQL Server allows an authorized attacker to elevate privileges over a network.

6.8

Insertion of sensitive information into sent data in Microsoft Teams for Android allows an authorized attacker to disclose information over a network.

8.8

Deserialization of untrusted data in Microsoft Dynamics 365 allows an authorized attacker to execute code over a network.

9.6

Improper neutralization of special elements in output used by a downstream component ('injection') in SQL Server allows an unauthorized attacker to elevate privileges over a network.

6.5

Insufficiently protected credentials in Microsoft Office allows an unauthorized attacker to perform spoofing over a network.

Showing 3001-3025 of 205,665 CVEs