Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2025-30392
Improper authorization in Azure Bot Framework SDK allows an unauthorized attacker to elevate privileges over a network.
Azure Ai Bot Service
Mitigation only
CRITICAL 9.8
CVE-2025-26683
Improper authorization in Azure Playwright allows an unauthorized attacker to elevate privileges over a network.
Azure Playwright
Mitigation only
CRITICAL 9.8
CVE-2025-24989 KEV
An improper access control vulnerability in Power Pages allows an unauthorized attacker to elevate privileges over a network potentially bypassing th…
Power Pages
Patch available
CRITICAL 9.8
CVE-2025-21355
Missing Authentication for Critical Function in Microsoft Bing allows an unauthorized attacker to execute code over a network
Bing
Patch available
CRITICAL 9.0
CVE-2025-21198
Microsoft High Performance Compute (HPC) Pack Remote Code Execution Vulnerability
Hpc Pack 2016
6.3.8328.0 / 2016.3+
CRITICAL 9.8
CVE-2025-21311
Windows NTLM V1 Elevation of Privilege Vulnerability
Windows 11 24h2
10.0.25398.1369 / 10.0.26100.2894+
CRITICAL 9.8
CVE-2025-21307
Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability
Windows 10 1507
10.0.10240.20890 / 10.0.14393.7699+
CRITICAL 9.8
CVE-2025-21298EPSS 81%
Windows OLE Remote Code Execution Vulnerability
Windows 10 1507
10.0.10240.20890 / 10.0.14393.7699+
CRITICAL 9.8
CVE-2024-42004
A library injection vulnerability exists in Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A specially crafted library can leverage…
Teams
No fix yet
CRITICAL 9.1
CVE-2024-41165
A library injection vulnerability exists in Microsoft Word 16.83 for macOS. A specially crafted library can leverage Word's access privileges, leadin…
Word
No fix yet
CRITICAL 9.1
CVE-2024-42220
A library injection vulnerability exists in Microsoft Outlook 16.83.3 for macOS. A specially crafted library can leverage Outlook's access privileges…
Outlook
No fix yet
CRITICAL 9.1
CVE-2024-43106
A library injection vulnerability exists in Microsoft Excel 16.83 for macOS. A specially crafted library can leverage Excel's access privileges, lead…
Excel
No fix yet
CRITICAL 9.8
CVE-2024-41138
A library injection vulnerability exists in the com.microsoft.teams2.modulehost.app helper app of Microsoft Teams (work or school) 24046.2813.2770.10…
Teams
No fix yet
CRITICAL 9.8
CVE-2024-41145
A library injection vulnerability exists in the WebView.app helper app of Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A speciall…
Teams
No fix yet
CRITICAL 9.1
CVE-2024-39804
A library injection vulnerability exists in Microsoft PowerPoint 16.83 for macOS. A specially crafted library can leverage PowerPoint's access privil…
Powerpoint
No fix yet
CRITICAL 9.8
CVE-2024-49147
Deserialization of untrusted data in Microsoft Update Catalog allows an unauthorized attacker to elevate privileges on the website’s webserver.
Update Catalog
Mitigation only
CRITICAL 9.8
CVE-2024-49112EPSS 71%
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
Windows 10 1507
10.0.10240.20857 / 10.0.14393.7606+
CRITICAL 9.8
CVE-2024-49052
Missing authentication for critical function in Microsoft Azure PolicyWatch allows an unauthorized attacker to elevate privileges over a network.
Azure Functions
Mitigation only
CRITICAL 9.8
CVE-2024-49035 KEV
An improper access control vulnerability in Partner.Microsoft.com allows an a unauthenticated attacker to elevate privileges over a network.
Partner Center
Mitigation only
CRITICAL 9.6
CVE-2024-49038
Improper neutralization of input during web page generation ('Cross-site Scripting') in Copilot Studio by an unauthorized attacker leads to elevation…
Copilot Studio
Mitigation only
CRITICAL 9.8
CVE-2024-43639EPSS 9%
Windows KDC Proxy Remote Code Execution Vulnerability
Windows Server 2012
10.0.14393.7515 / 10.0.17763.6532+
CRITICAL 9.9
CVE-2024-43602
Azure CycleCloud Remote Code Execution Vulnerability
Azure Cyclecloud
8.6.5+
CRITICAL 9.8
CVE-2024-43498
.NET and Visual Studio Remote Code Execution Vulnerability
.net
17.6.21 / 17.8.16+
CRITICAL 9.8
CVE-2024-43566
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Edge Chromium
130.0.2849.46+
CRITICAL 9.1
CVE-2024-43591
Azure Command Line Integration (CLI) Elevation of Privilege Vulnerability
Azure Command Line Interface
2.65.0+
CRITICAL 9.8
CVE-2024-43488
Missing authentication for critical function in Visual Studio Code extension for Arduino allows an unauthenticated attacker to perform remote code ex…
Visual Studio Code
Patch available
CRITICAL 9.8
CVE-2024-43468 KEVEPSS 62%
Microsoft Configuration Manager Remote Code Execution Vulnerability
Configuration Manager 2403
No fix yet
CRITICAL 9.0
CVE-2024-38124
Windows Netlogon Elevation of Privilege Vulnerability
Windows Server 2008
10.0.14393.7428 / 10.0.17763.6414+
CRITICAL 9.8
CVE-2024-38183
An improper access control vulnerability in GroupMe allows an a unauthenticated attacker to elevate privileges over a network.
Groupme
Patch available
CRITICAL 9.8
CVE-2024-43491EPSS 12%
Microsoft is aware of a vulnerability in Servicing Stack that has rolled back the fixes for some vulnerabilities affecting Optional Components on Win…
Windows 10 1507
10.0.10240.20766+