Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.8
CVE-2025-62455
Improper input validation in Windows Message Queuing allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.8688 / 10.0.17763.8146+
HIGH 8.8
CVE-2025-62222
Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code CoPilot Chat Extension allows an unauthoriz…
Github Copilot Chat
0.32.5+
HIGH 8.1
CVE-2025-59250
Improper input validation in JDBC Driver for SQL Server allows an unauthorized attacker to perform spoofing over a network.
Jdbc Driver For Sql Server
10.2.4 / 11.2.4+
HIGH 7.5
CVE-2025-59248
Improper input validation in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
Exchange Server
15.02.2562.029+
HIGH 8.8
CVE-2025-59228
Improper input validation in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Sharepoint Server
16.0.19127.20262+
HIGH 7.8
CVE-2025-59207
Untrusted pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.
Windows 10 1809
10.0.17763.7919 / 10.0.19044.6456+
MEDIUM 5.0
CVE-2025-59198
Improper input validation in Microsoft Windows Search Component allows an authorized attacker to deny service locally.
Windows 10 1507
10.0.10240.21161 / 10.0.14393.8519+
HIGH 7.8
CVE-2025-59187
Improper input validation in Windows Kernel allows an authorized attacker to elevate privileges locally.
Windows 10 1507
10.0.10240.21161 / 10.0.14393.8519+
MEDIUM 5.5
CVE-2025-59190
Improper input validation in Microsoft Windows Search Component allows an unauthorized attacker to deny service locally.
Windows 10 1507
10.0.10240.21161 / 10.0.14393.8519+
HIGH 8.8
CVE-2025-58716
Improper input validation in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally.
Windows 10 1507
10.0.10240.21161 / 10.0.14393.8519+
HIGH 7.8
CVE-2025-55692
Improper input validation in Windows Error Reporting allows an authorized attacker to elevate privileges locally.
Windows 10 1507
10.0.10240.21161 / 10.0.14393.8519+
MEDIUM 6.5
CVE-2025-53809
Improper input validation in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to deny service over a network.
Windows 11 24h2
10.0.26100.6508+
MEDIUM 6.5
CVE-2025-25005
Improper input validation in Microsoft Exchange Server allows an authorized attacker to perform tampering over a network.
Exchange Server
15.02.2562.020+
MEDIUM 5.6
CVE-2025-47182
Improper input validation in Microsoft Edge (Chromium-based) allows an authorized attacker to bypass a security feature locally.
Edge Chromium
138.0.3351.55+
HIGH 7.5
CVE-2025-49719EPSS 11%
Improper input validation in SQL Server allows an unauthorized attacker to disclose information over a network.
Sql Server 2016
13.0.6460.7 / 13.0.7055.9+
HIGH 7.8
CVE-2025-47982
Improper input validation in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.8246 / 10.0.17763.7558+
HIGH 7.8
CVE-2025-47968
Improper input validation in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges locally.
Autoupdate
4.79+
MEDIUM 6.7
CVE-2025-47171
Improper input validation in Microsoft Office Outlook allows an authorized attacker to execute code locally.
365 Apps
Mitigation only
HIGH 7.8
CVE-2025-32706 KEV
Improper input validation in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
Windows 10 1507
10.0.10240.21014 / 10.0.14393.8066+
MEDIUM 6.5
CVE-2025-29968
Improper input validation in Active Directory Certificate Services (AD CS) allows an authorized attacker to deny service over a network.
Windows Server 2008
10.0.14393.8066 / 10.0.17763.7314+
MEDIUM 5.5
CVE-2025-29955
Improper input validation in Windows Hyper-V allows an unauthorized attacker to deny service locally.
Windows 11 24h2
10.0.25398.1611 / 10.0.26100.4061+
HIGH 7.5
CVE-2025-30391
Improper input validation in Microsoft Dynamics allows an unauthorized attacker to disclose information over a network.
Dynamics 365 Customer Service
Mitigation only
MEDIUM 5.5
CVE-2025-29821
Improper input validation in Dynamics Business Central allows an authorized attacker to disclose information locally.
Dynamics 365 Business Central 2023
23.18.32409 / 24.12.32447+
HIGH 7.8
CVE-2025-29811
Improper input validation in Windows Mobile Broadband allows an authorized attacker to elevate privileges locally.
Windows 11 22h2
10.0.22621.5189 / 10.0.22631.5189+
HIGH 8.6
CVE-2025-27737
Improper input validation in Windows Security Zone Mapping allows an unauthorized attacker to bypass a security feature locally.
Windows 10 1507
10.0.10240.20978 / 10.0.14393.7969+
HIGH 7.8
CVE-2025-27731
Improper input validation in OpenSSH for Windows allows an authorized attacker to elevate privileges locally.
Windows 10 1809
10.0.17763.7136 / 10.0.19044.5737+
HIGH 7.8
CVE-2025-27489
Improper input validation in Azure Local allows an authorized attacker to elevate privileges locally.
Azure Stack Hci 22h2
10.0.20348.3328 / 10.0.25398.1486+
HIGH 8.8
CVE-2025-26647
Improper input validation in Windows Kerberos allows an authorized attacker to elevate privileges over a network.
Windows Server 2008
10.0.14393.7969 / 10.0.17763.7136+
HIGH 7.8
CVE-2025-24058
Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
Windows 10 1809
10.0.17763.7136 / 10.0.19044.5737+
HIGH 7.8
CVE-2025-24060
Improper input validation in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
Windows 10 1809
10.0.17763.7136 / 10.0.19044.5737+