Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.3
CVE-2026-70306
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker t…
Sharepoint Server
16.0.19725.20434+
CRITICAL 9.8
CVE-2026-65791
Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network.
Windows 10 1607
10.0.14393.9418 / 10.0.17763.9115+
CRITICAL 9.8
CVE-2026-65768
Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Teams for Android allows an unauthorized attacker to exec…
Teams
1.0.0.2026133602+
CRITICAL 9.8
CVE-2026-62893
Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network.
Windows 10 1607
10.0.14393.9418 / 10.0.17763.9115+
CRITICAL 9.8
CVE-2026-62878
Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to execute code over a network.
Windows 10 1607
10.0.14393.9418 / 10.0.17763.9121+
CRITICAL 9.8
CVE-2026-62815
Use after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network.
Windows 11 23h2
10.0.20348.5440 / 10.0.22631.7517+
CRITICAL 9.8
CVE-2026-59124
Deserialization of untrusted data in Microsoft High Performance Computing (HPC) Pack allows an unauthorized attacker to execute code over a network.
Windows App
2.0.1314.0+
CRITICAL 9.6
CVE-2026-57104
Improper neutralization of input during web page generation ('cross-site scripting') in Azure Storage Explorer allows an unauthorized attacker to ele…
Azure Storage Explorer
1.45.0+
CRITICAL 9.4
CVE-2026-50516
Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a netwo…
Azure Kubernetes Service
No fix yet
CRITICAL 9.6
CVE-2026-70332
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker t…
Sharepoint Online
No fix yet
CRITICAL 9.1
CVE-2026-68823
Exposed dangerous method or function in Azure Confidential Ledger allows an authorized attacker to execute code over a network.
Azure Confidential Ledger
No fix yet
CRITICAL 10.0
CVE-2026-65667
Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network.
Teams
No fix yet
CRITICAL 10.0
CVE-2026-63508
Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elevate privileges over a network.
Planetary Computer
No fix yet
CRITICAL 9.8
CVE-2026-62873
Improper verification of cryptographic signature in Microsoft 365 Admin Center allows an unauthorized attacker to elevate privileges over a network.
Windows Admin Center
No fix yet
CRITICAL 9.6
CVE-2026-62896
Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a network.
Teams
No fix yet
CRITICAL 10.0
CVE-2026-62836
Improper restriction of communication channel to intended endpoints in Azure SQL Managed Instance allows an unauthorized attacker to elevate privileg…
Azure Sql Managed Instance
No fix yet
CRITICAL 9.9
CVE-2026-62830
Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network.
Azure Sre Agent
No fix yet
CRITICAL 9.9
CVE-2026-59115
'.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network.
Entra Provisioning Service
No fix yet
CRITICAL 9.3
CVE-2026-59118
Improper authorization in Copilot Cowork allows an unauthorized attacker to elevate privileges over a network.
Power Apps
No fix yet
CRITICAL 10.0
CVE-2026-56162
Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.
Azure Sql Database
No fix yet
CRITICAL 9.9
CVE-2026-50515
Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network.
Azure Service Bus
No fix yet
CRITICAL 9.6
CVE-2026-56161
Improper access control in Azure Logic Apps allows an authorized attacker to disclose information over a network.
Azure Logic Apps
No fix yet
CRITICAL 9.9
CVE-2026-50481
Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.
Azure Active Directory
No fix yet
CRITICAL 9.6
CVE-2026-66321
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over…
Edge Chromium
151.0.4129.59+
CRITICAL 10.0
CVE-2026-66803
Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network.
Azure Cosmos Db
No fix yet
CRITICAL 9.8
CVE-2026-58630
Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.
Azure App Service For Linux
No fix yet
CRITICAL 10.0
CVE-2026-57106
Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network.
Purview Data Governance
No fix yet
CRITICAL 10.0
CVE-2026-56163
Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a netwo…
Azure Kubernetes Service
No fix yet
CRITICAL 9.8
CVE-2026-62825
Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network.
Azure Key Vault
No fix yet
CRITICAL 9.8
CVE-2026-58275
Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network.
Azure Dns
No fix yet