CVE-2026-54116
Published Jul 14, 2026Access of resource using incompatible type ('type confusion') in SQL Server allows an authorized attacker to disclose information over a network.
- evidence mentions
- 4
- Buzz score
- 29.1
Vendor/product archive
14 CVEs tagged to microsoft / sql_server_2025 — 0 Critical, 10 High, 4 Medium, 0 Low, 0 Unrated.
Access of resource using incompatible type ('type confusion') in SQL Server allows an authorized attacker to disclose information over a network.
Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network.
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.
Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a network.
Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a network.
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges locally.
External control of file name or path in SQL Server allows an authorized attacker to execute code over a network.
Untrusted pointer dereference in SQL Server allows an authorized attacker to execute code over a network.
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges locally.
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges locally.
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.
Improper validation of specified type of input in SQL Server allows an authorized attacker to elevate privileges over a network.
Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.
Missing authentication for critical function in SQL Server allows an authorized attacker to elevate privileges over a network.