Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.3
CVE-2025-59286
Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to disclose informatio…
365 Copilot Chat
Mitigation only
CRITICAL 9.8
CVE-2025-59246EPSS 7%
Azure Entra ID Elevation of Privilege Vulnerability
Entra Id
No fix yet
CRITICAL 9.8
CVE-2025-59247
Azure PlayFab Elevation of Privilege Vulnerability
Azure Playfab
No fix yet
CRITICAL 9.6
CVE-2025-59218
Azure Entra ID Elevation of Privilege Vulnerability
Entra Id
No fix yet
CRITICAL 9.3
CVE-2025-59252
Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to disclose informatio…
365 Word Copilot
Mitigation only
CRITICAL 9.3
CVE-2025-59272
Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to perform information…
365 Copilot Chat
Mitigation only
CRITICAL 9.3
CVE-2025-55321
Improper neutralization of input during web page generation ('cross-site scripting') in Azure Monitor allows an unauthorized attacker to perform spoo…
Azure Monitor
Mitigation only
CRITICAL 9.8
CVE-2025-55319
Ai command injection in Agentic AI and Visual Studio Code allows an unauthorized attacker to execute code over a network.
Visual Studio Code
1.104.0+
CRITICAL 9.8
CVE-2025-55232
Deserialization of untrusted data in Microsoft High Performance Compute Pack (HPC) allows an unauthorized attacker to execute code over a network.
Hpc Pack
6.3.8352+
CRITICAL 9.8
CVE-2025-55234EPSS 20%
SMB Server might be susceptible to relay attacks depending on the configuration. An attacker who successfully exploited these vulnerabilities could p…
Windows 10 1507
10.0.10240.21128 / 10.0.14393.8422+
CRITICAL 9.0
CVE-2025-55244
Azure Bot Service Elevation of Privilege Vulnerability
Azure Ai Bot Service
No fix yet
CRITICAL 10.0
CVE-2025-55241
Azure Entra ID Elevation of Privilege Vulnerability
Entra Id
No fix yet
CRITICAL 9.8
CVE-2025-54914
Azure Networking Elevation of Privilege Vulnerability
Azure Networking
No fix yet
CRITICAL 9.8
CVE-2025-53795
Improper authorization in Microsoft PC Manager allows an unauthorized attacker to elevate privileges over a network.
Pc Manager
Mitigation only
CRITICAL 9.8
CVE-2025-53763
Improper access control in Azure Databricks allows an unauthorized attacker to elevate privileges over a network.
Purview Data Governance
No fix yet
CRITICAL 9.8
CVE-2025-53766EPSS 7%
Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network.
365 Copilot
10.0.10240.21100 / 10.0.14393.8330+
CRITICAL 9.1
CVE-2025-50171
Missing authorization in Remote Desktop Server allows an unauthorized attacker to perform spoofing over a network.
Windows Server 2022
10.0.20348.3989 / 10.0.25398.1791+
CRITICAL 9.8
CVE-2025-50165EPSS 10%
Untrusted pointer dereference in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.
Windows 11 24h2
10.0.26100.4851+
CRITICAL 10.0
CVE-2025-53767
Azure OpenAI Elevation of Privilege Vulnerability
Azure Openai
No fix yet
CRITICAL 9.1
CVE-2025-53792
Azure Portal Elevation of Privilege Vulnerability
Azure Portal
No fix yet
CRITICAL 9.8
CVE-2025-53770 KEVEPSS 100%
Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network.
Microsof…
Sharepoint Server
16.0.18526.20508+
CRITICAL 9.9
CVE-2025-53762
Permissive list of allowed inputs in Microsoft Purview allows an authorized attacker to elevate privileges over a network.
Purview
No fix yet
CRITICAL 9.0
CVE-2025-47158
Authentication bypass by assumed-immutable data in Azure DevOps allows an unauthorized attacker to elevate privileges over a network.
Azure Devops
Mitigation only
CRITICAL 9.8
CVE-2025-47981EPSS 32%
Heap-based buffer overflow in Windows SPNEGO Extended Negotiation allows an unauthorized attacker to execute code over a network.
Windows 10 1507
10.0.10240.21073 / 10.0.14393.8246+
CRITICAL 9.8
CVE-2025-47966
Exposure of sensitive information to an unauthorized actor in Power Automate allows an unauthorized attacker to elevate privileges over a network.
Power Automate For Desktop
No fix yet
CRITICAL 9.8
CVE-2025-30387
Improper limitation of a pathname to a restricted directory ('path traversal') in Azure allows an unauthorized attacker to elevate privileges over a …
Azure Ai Document Intelligence Studio
Mitigation only
CRITICAL 9.8
CVE-2025-29813
Authentication bypass by assumed-immutable data in Azure DevOps allows an unauthorized attacker to elevate privileges over a network.
Azure Devops
Mitigation only
CRITICAL 9.8
CVE-2025-29972
Server-side request forgery (ssrf) in Azure Storage Resource Provider allows an authorized attacker to perform spoofing over a network.
Azure Storage Resource Provider
Mitigation only
CRITICAL 9.8
CVE-2025-47732
Deserialization of untrusted data in Microsoft Dataverse allows an authorized attacker to execute code over a network.
Dataverse
Mitigation only
CRITICAL 9.8
CVE-2025-30389
Improper authorization in Azure Bot Framework SDK allows an unauthorized attacker to elevate privileges over a network.
Azure Ai Bot Service
Mitigation only