Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.8
CVE-2025-55694
Improper access control in Windows Error Reporting allows an authorized attacker to elevate privileges locally.
Windows 11 24h2
10.0.26100.6899 / 10.0.26200.6899+
HIGH 7.3
CVE-2025-55240
Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally.
Visual Studio 2017
15.9.77 / 16.11.52+
HIGH 7.0
CVE-2025-47989
Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.
Azure Connected Machine Agent
1.57+
HIGH 7.3
CVE-2025-25004
Improper access control in Microsoft PowerShell allows an authorized attacker to elevate privileges locally.
Powershell
7.4.13 / 7.5.4+
CRITICAL 9.6
CVE-2025-59218
Azure Entra ID Elevation of Privilege Vulnerability
Entra Id
No fix yet
HIGH 7.3
CVE-2025-54116
Improper access control in Windows MultiPoint Services allows an authorized attacker to elevate privileges locally.
Windows 10 1507
10.0.10240.21128 / 10.0.14393.8422+
HIGH 7.8
CVE-2025-54098
Improper access control in Windows Hyper-V allows an authorized attacker to elevate privileges locally.
Windows 10 1507
10.0.10240.21128 / 10.0.14393.8422+
HIGH 7.8
CVE-2025-49692
Improper access control in Azure Windows Virtual Machine Agent allows an authorized attacker to elevate privileges locally.
Azure Connected Machine Agent
1.49+
CRITICAL 9.0
CVE-2025-55244
Azure Bot Service Elevation of Privilege Vulnerability
Azure Ai Bot Service
No fix yet
CRITICAL 9.8
CVE-2025-54914
Azure Networking Elevation of Privilege Vulnerability
Azure Networking
No fix yet
HIGH 7.5
CVE-2025-55238
Dynamics 365 FastTrack Implementation Assets Information Disclosure Vulnerability
Dynamics 365
No fix yet
CRITICAL 9.8
CVE-2025-53763
Improper access control in Azure Databricks allows an unauthorized attacker to elevate privileges over a network.
Purview Data Governance
No fix yet
HIGH 7.8
CVE-2025-53729
Improper access control in Azure File Sync allows an authorized attacker to elevate privileges locally.
Azure File Sync
18.3.0.0 / 19.2.0.0+
MEDIUM 5.5
CVE-2025-49707
Improper access control in Azure Virtual Machines allows an authorized attacker to perform spoofing locally.
Ecesv6 Series Azure Vm Firmware
No fix yet
HIGH 8.8
CVE-2025-24999
Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.
Sql Server 2016
13.0.6465.1 / 13.0.7060.1+
HIGH 8.8
CVE-2025-48817
Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
Remote Desktop Client
1.2.6353 / 2.0.559.0+
HIGH 7.8
CVE-2025-47993
Improper access control in Microsoft PC Manager allows an authorized attacker to elevate privileges locally.
Windows 11 24h2
10.0.25398.1732 / 10.0.26100.4652+
HIGH 7.8
CVE-2025-47962
Improper access control in Windows SDK allows an authorized attacker to elevate privileges locally.
Windows Software Development Kit
10.0.26100.4188+
HIGH 8.8
CVE-2025-33073 KEVEPSS 80%
Improper access control in Windows SMB allows an authorized attacker to elevate privileges over a network.
Windows 10 1507
10.0.10240.21034 / 10.0.14393.8148+
HIGH 7.5
CVE-2025-33056
Improper access control in Microsoft Local Security Authority Server (lsasrv) allows an unauthorized attacker to deny service over a network.
Windows 10 1507
10.0.10240.21034 / 10.0.14393.8148+
MEDIUM 5.5
CVE-2025-32722
Improper access control in Windows Storage Port Driver allows an authorized attacker to disclose information locally.
Windows 10 1507
10.0.10240.21034 / 10.0.14393.8148+
HIGH 7.8
CVE-2025-32714
Improper access control in Windows Installer allows an authorized attacker to elevate privileges locally.
Windows 10 1507
10.0.10240.21034 / 10.0.14393.8148+
HIGH 7.8
CVE-2025-47161
Improper access control in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally.
Defender For Endpoint
101.25022.0002+
HIGH 7.0
CVE-2025-29973
Improper access control in Azure File Sync allows an authorized attacker to elevate privileges locally.
Azure File Sync
Mitigation only
HIGH 7.5
CVE-2025-33072
Improper access control in Azure allows an unauthorized attacker to disclose information over a network.
Msagsfeedback.azurewebsites.net
Mitigation only
MEDIUM 6.8
CVE-2025-32726
Improper access control in Visual Studio Code allows an authorized attacker to elevate privileges locally.
Visual Studio Code
1.99.1+
HIGH 7.5
CVE-2025-29810
Improper access control in Active Directory Domain Services allows an authorized attacker to elevate privileges over a network.
Windows 10 1507
10.0.10240.20978 / 10.0.14393.7969+
HIGH 7.3
CVE-2025-29804
Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally.
Visual Studio 2022
17.8.20 / 17.10.13+
HIGH 7.8
CVE-2025-27744
Improper access control in Microsoft Office allows an authorized attacker to elevate privileges locally.
Office
Mitigation only
MEDIUM 6.5
CVE-2025-27738
Improper access control in Windows Resilient File System (ReFS) allows an authorized attacker to disclose information over a network.
Windows 10 1507
10.0.10240.20978 / 10.0.14393.7969+