Sql Server 2019 Microsoft Sql Server 2019

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Microsoft Sql Server 2019.

By the Year

In 2025 there have been 10 vulnerabilities in Microsoft Sql Server 2019 with an average score of 8.3 out of ten. Last year, in 2024 Sql Server 2019 had 120 security vulnerabilities published. Right now, Sql Server 2019 is on track to have less security vulnerabilities in 2025 than it did last year. Last year, the average CVE base score was greater by 0.40

Year Vulnerabilities Average Score
2025 10 8.28
2024 120 8.68

It may take a day or so for new Sql Server 2019 vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Microsoft Sql Server 2019 Security Vulnerabilities

Nov 2025: Microsoft SQL Server Elevation of Privilege Vulnerability
CVE-2025-59499 8.8 - High - November 11, 2025

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.

SQL Injection

Sep 2025: Microsoft SQL Server Elevation of Privilege Vulnerability
CVE-2025-55227 8.8 - High - September 09, 2025

Improper neutralization of special elements used in a command ('command injection') in SQL Server allows an authorized attacker to elevate privileges over a network.

Command Injection

Sep 2025: Microsoft SQL Server Information Disclosure Vulnerability
CVE-2025-47997 6.5 - Medium - September 09, 2025

Concurrent execution using shared resource with improper synchronization ('race condition') in SQL Server allows an authorized attacker to disclose information over a network.

Race Condition

Aug 2025: Microsoft SQL Server Elevation of Privilege Vulnerability
CVE-2025-24999 8.8 - High - August 12, 2025

Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.

Authorization

Aug 2025: Microsoft SQL Server Elevation of Privilege Vulnerability
CVE-2025-49758 8.8 - High - August 12, 2025

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.

Improper Privilege Management

Aug 2025: Microsoft SQL Server Elevation of Privilege Vulnerability
CVE-2025-49759 8.8 - High - August 12, 2025

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.

SQL Injection

Aug 2025: Microsoft SQL Server Elevation of Privilege Vulnerability
CVE-2025-53727 8.8 - High - August 12, 2025

Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.

SQL Injection

Microsoft SQL Server Heap OOB Buffer Overflow Enables Network Code Exec
CVE-2025-49717 8.5 - High - July 08, 2025

Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network.

Heap-based Buffer Overflow

SQL Server Uninitialized Resource Disclosure via Network
CVE-2025-49718 7.5 - High - July 08, 2025

Use of uninitialized resource in SQL Server allows an unauthorized attacker to disclose information over a network.

Use of Uninitialized Resource

SQL Server Improper Input Validation Enables Network Data Disclosure
CVE-2025-49719 7.5 - High - July 08, 2025

Improper input validation in SQL Server allows an unauthorized attacker to disclose information over a network.

Improper Input Validation

Remote Code Execution in Microsoft SQL Server Native Client
CVE-2024-43459 8.8 - High - November 12, 2024

SQL Server Native Client Remote Code Execution Vulnerability

Dangling pointer

SQL Server Native Client RCE Vulnerability in Microsoft's Database Client
CVE-2024-43462 8.8 - High - November 12, 2024

SQL Server Native Client Remote Code Execution Vulnerability

Heap-based Buffer Overflow

Remote Code Execution in Microsoft SQL Server Native Client
CVE-2024-48993 8.8 - High - November 12, 2024

SQL Server Native Client Remote Code Execution Vulnerability

Heap-based Buffer Overflow

Microsoft SQL Server Native Client RCE (CVE-2024-38255)
CVE-2024-38255 8.8 - High - November 12, 2024

SQL Server Native Client Remote Code Execution Vulnerability

Heap-based Buffer Overflow

SQL Server Native Client RCE Vulnerability (CVE-2024-48994)
CVE-2024-48994 8.8 - High - November 12, 2024

SQL Server Native Client Remote Code Execution Vulnerability

Heap-based Buffer Overflow

SQL Server Native Client RCE Vulnerability (Remote Code Exec)
CVE-2024-48995 8.8 - High - November 12, 2024

SQL Server Native Client Remote Code Execution Vulnerability

Heap-based Buffer Overflow

SQL Server Native Client RCE via Remote Vulnerability
CVE-2024-48996 8.8 - High - November 12, 2024

SQL Server Native Client Remote Code Execution Vulnerability

Heap-based Buffer Overflow

SQL Server Native Client Remote RCE Vulnerability
CVE-2024-48997 8.8 - High - November 12, 2024

SQL Server Native Client Remote Code Execution Vulnerability

Microsoft SQL Server Native Client RCE via Remote Exec
CVE-2024-48998 8.8 - High - November 12, 2024

SQL Server Native Client Remote Code Execution Vulnerability

Heap-based Buffer Overflow

MS SQL Server Native Client RCE via Remote Exploit
CVE-2024-48999 8.8 - High - November 12, 2024

SQL Server Native Client Remote Code Execution Vulnerability

Heap-based Buffer Overflow

SQL Server Native Client RCE via Remote Code Execution
CVE-2024-49000 8.8 - High - November 12, 2024

SQL Server Native Client Remote Code Execution Vulnerability

Heap-based Buffer Overflow

Microsoft SQL Server Native Client RCE Remote Code Exec
CVE-2024-49001 8.8 - High - November 12, 2024

SQL Server Native Client Remote Code Execution Vulnerability

Heap-based Buffer Overflow

SQL Server Native Client Remote RCE Vulnerability
CVE-2024-49002 8.8 - High - November 12, 2024

SQL Server Native Client Remote Code Execution Vulnerability

Heap-based Buffer Overflow

SQL Server Native Client RCE via Remote Execution
CVE-2024-49003 8.8 - High - November 12, 2024

SQL Server Native Client Remote Code Execution Vulnerability

Dangling pointer

MS SQLServer Native Client RCE via Remote Code Exec
CVE-2024-49004 8.8 - High - November 12, 2024

SQL Server Native Client Remote Code Execution Vulnerability

Heap-based Buffer Overflow

SQL Server Native Client RCE Vulnerability CVE-2024-49005
CVE-2024-49005 8.8 - High - November 12, 2024

SQL Server Native Client Remote Code Execution Vulnerability

Heap-based Buffer Overflow

SQL Server Native Client RCE Remote Code Execution Vulnerability
CVE-2024-49006 8.8 - High - November 12, 2024

SQL Server Native Client Remote Code Execution Vulnerability

Heap-based Buffer Overflow

SQL Server Native Client RCE Vulnerability
CVE-2024-49007 8.8 - High - November 12, 2024

SQL Server Native Client Remote Code Execution Vulnerability

Heap-based Buffer Overflow

Microsoft SQL Server Native Client Remote Code Execution Vulnerability
CVE-2024-49008 8.8 - High - November 12, 2024

SQL Server Native Client Remote Code Execution Vulnerability

Heap-based Buffer Overflow

SQL Server Native Client RCE (CVE-2024-49009)
CVE-2024-49009 8.8 - High - November 12, 2024

SQL Server Native Client Remote Code Execution Vulnerability

Heap-based Buffer Overflow

Microsoft SQL Server XEvent Configuration Remote Code Execution Vulnerability
CVE-2024-49043 7.8 - High - November 12, 2024

Microsoft.SqlServer.XEvent.Configuration.dll Remote Code Execution Vulnerability

Untrusted Path

Microsoft SQL Server Remote Code Execution Vulnerability
CVE-2024-49021 7.8 - High - November 12, 2024

Microsoft SQL Server Remote Code Execution Vulnerability

Dangling pointer

SQL Server Native Client: Remote Code Execution Vulnerability
CVE-2024-49018 8.8 - High - November 12, 2024

SQL Server Native Client Remote Code Execution Vulnerability

Numeric Truncation Error

SQL Server Native Client: Remote Code Execution Vulnerability
CVE-2024-49017 8.8 - High - November 12, 2024

SQL Server Native Client Remote Code Execution Vulnerability

Heap-based Buffer Overflow

RCE in Microsoft SQL Server Native Client
CVE-2024-49016 8.8 - High - November 12, 2024

SQL Server Native Client Remote Code Execution Vulnerability

Dangling pointer

Microsoft SQL Server Native Client RCE Vulnerability
CVE-2024-49015 8.8 - High - November 12, 2024

SQL Server Native Client Remote Code Execution Vulnerability

Heap-based Buffer Overflow

SQL Server Native Client RCE Vulnerability in 2024
CVE-2024-49014 8.8 - High - November 12, 2024

SQL Server Native Client Remote Code Execution Vulnerability

SQL Server Native Client RCE via Native Client Driver
CVE-2024-49013 8.8 - High - November 12, 2024

SQL Server Native Client Remote Code Execution Vulnerability

Heap-based Buffer Overflow

SQL Server Native Client RCE Vulnerability (CVE-2024-49012)
CVE-2024-49012 8.8 - High - November 12, 2024

SQL Server Native Client Remote Code Execution Vulnerability

Heap-based Buffer Overflow

SQL Server Native Client RCE Vulnerability
CVE-2024-49011 8.8 - High - November 12, 2024

SQL Server Native Client Remote Code Execution Vulnerability

Heap-based Buffer Overflow

CVE-2024-49010: MS SQL Server Native Client RCE Vulnerability
CVE-2024-49010 8.8 - High - November 12, 2024

SQL Server Native Client Remote Code Execution Vulnerability

Heap-based Buffer Overflow

MS SQL Server Info Disclosure via CVE-2024-43474
CVE-2024-43474 7.5 - High - September 10, 2024

Microsoft SQL Server Information Disclosure Vulnerability

Improper Null Termination

Microsoft SQL Server EoP Vulnerability
CVE-2024-37965 8.8 - High - September 10, 2024

Microsoft SQL Server Elevation of Privilege Vulnerability

Improper Input Validation

Microsoft SQL Server Info Disclosure via Native Scoring Function
CVE-2024-37966 7.1 - High - September 10, 2024

Microsoft SQL Server Native Scoring Information Disclosure Vulnerability

Out-of-bounds Read

Microsoft SQL Server EOP Vulnerability CVE-2024-37980
CVE-2024-37980 9.8 - Critical - September 10, 2024

Microsoft SQL Server Elevation of Privilege Vulnerability

SQL Server Native Scoring Info Disclosure Vulnerability
CVE-2024-37342 4.3 - Medium - September 10, 2024

Microsoft SQL Server Native Scoring Information Disclosure Vulnerability

Out-of-bounds Read

Remote Code Execution in Microsoft SQL Server Native Scoring
CVE-2024-37340 8.8 - High - September 10, 2024

Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability

Untrusted Pointer Dereference

Microsoft SQL Server Elevation of Privilege Vulnerability CVE-2024-37341
CVE-2024-37341 9.8 - Critical - September 10, 2024

Microsoft SQL Server Elevation of Privilege Vulnerability

Authorization

SQL Server NativeScoring RCE Vulnerability (CVE-2024-26191)
CVE-2024-26191 8.8 - High - September 10, 2024

Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability

Heap-based Buffer Overflow

Microsoft SQL Server Native Scoring RCE Vulnerability (CVE-2024-26186)
CVE-2024-26186 8.8 - High - September 10, 2024

Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability

Dangling pointer

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Microsoft Sql Server 2019 or by Microsoft? Click the Watch button to subscribe.

Microsoft
Vendor

subscribe