Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2026-23658
Insufficiently protected credentials in Azure DevOps allows an unauthorized attacker to elevate privileges over a network.
Azure Devops
No fix yet
CRITICAL 9.3
CVE-2026-26105
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker t…
Sharepoint Server
16.0.19725.20076+
CRITICAL 9.8
CVE-2026-26125
Payment Orchestrator Service Elevation of Privilege Vulnerability
Payment Orchestrator Service
No fix yet
CRITICAL 9.8
CVE-2026-21536
Microsoft Devices Pricing Program Remote Code Execution Vulnerability
Devices Pricing Program
No fix yet
CRITICAL 9.9
CVE-2026-26030
Semantic Kernel, Microsoft's semantic kernel Python SDK, has a remote code execution vulnerability in versions prior to 1.39.4, specifically within t…
Semantic Kernel
1.39.4+
CRITICAL 9.8
CVE-2026-21531
Deserialization of untrusted data in Azure SDK allows an unauthorized attacker to execute code over a network.
Azure Conversation Authoring Client Library
Mitigation only
CRITICAL 9.8
CVE-2026-24300
Azure Front Door Elevation of Privilege Vulnerability
Azure Front Door
No fix yet
CRITICAL 9.8
CVE-2026-24302
Improper access control in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
Azure Arc
Mitigation only
CRITICAL 9.8
CVE-2026-24888
Maker.js is a 2D vector line drawing and shape modeling for CNC and laser cutters. In versions up to and including 0.19.1, the `makerjs.extendObject`…
Maker.js
after 0.19.1
CRITICAL 9.9
CVE-2026-24304
Improper access control in Azure Resource Manager allows an authorized attacker to elevate privileges over a network.
Azure Resource Manager
Mitigation only
CRITICAL 9.8
CVE-2026-24305
Azure Entra ID Elevation of Privilege Vulnerability
Entra Id
No fix yet
CRITICAL 9.8
CVE-2026-24306
Improper access control in Azure Front Door (AFD) allows an unauthorized attacker to elevate privileges over a network.
Azure Front Door
No fix yet
CRITICAL 9.8
CVE-2026-21227
Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privile…
Azure Logic Apps
Mitigation only
CRITICAL 9.8
CVE-2026-20963 KEVEPSS 32%
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
Sharepoint Server
16.0.19127.20442+
CRITICAL 9.6
CVE-2025-64675
Improper neutralization of input during web page generation ('cross-site scripting') in Azure Cosmos DB allows an unauthorized attacker to perform sp…
Azure Cosmos Db
Mitigation only
CRITICAL 10.0
CVE-2025-65037
Improper control of generation of code ('code injection') in Azure Container Apps allows an unauthorized attacker to execute code over a network.
Azure Container Apps
Mitigation only
CRITICAL 9.8
CVE-2025-65041
Improper authorization in Microsoft Partner Center allows an unauthorized attacker to elevate privileges over a network.
Partner Center
Mitigation only
CRITICAL 9.0
CVE-2025-64672
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to …
Sharepoint Server
16.0.19127.20378+
CRITICAL 9.8
CVE-2025-64656
Out-of-bounds read in Application Gateway allows an unauthorized attacker to elevate privileges over a network.
Azure Application Gateway
Mitigation only
CRITICAL 9.8
CVE-2025-64657
Stack-based buffer overflow in Azure Application Gateway allows an unauthorized attacker to elevate privileges over a network.
Azure Application Gateway
Mitigation only
CRITICAL 9.8
CVE-2025-64655
Improper authorization in Dynamics OmniChannel SDK Storage Containers allows an unauthorized attacker to elevate privileges over a network.
Dynamics Omnichannel Sdk Storage Containers
No fix yet
CRITICAL 9.8
CVE-2025-62207
Azure Monitor Elevation of Privilege Vulnerability
Azure Monitor
No fix yet
CRITICAL 9.8
CVE-2025-59245
Microsoft SharePoint Online Elevation of Privilege Vulnerability
Sharepoint Online
No fix yet
CRITICAL 10.0
CVE-2025-49752
Azure Bastion Elevation of Privilege Vulnerability
Azure Bastion Developer
No fix yet
CRITICAL 9.8
CVE-2025-60724EPSS 6%
Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.
365 Copilot
10.0.14393.8594 / 10.0.17763.8027+
CRITICAL 9.8
CVE-2025-59503
Server-side request forgery (ssrf) in Azure Compute Gallery allows an unauthorized attacker to elevate privileges over a network.
Azure Compute Resource Provider
Mitigation only
CRITICAL 9.8
CVE-2025-59273
Improper access control in Azure Event Grid allows an unauthorized attacker to elevate privileges over a network.
Azure Event Grid
No fix yet
CRITICAL 9.8
CVE-2025-59287 KEVEPSS 100%
Deserialization of untrusted data in Windows Server Update Service allows an unauthorized attacker to execute code over a network.
Windows Server 2012
10.0.14393.8524 / 10.0.17763.7922+
CRITICAL 9.9
CVE-2025-55315EPSS 66%
Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized attacker to bypass a security f…
Asp.net Core
2.3.6 / 8.0.21+
CRITICAL 9.9
CVE-2025-49708
Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges over a network.
Windows 10 1809
10.0.17763.7919 / 10.0.19044.6456+