Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 8.4
CVE-2025-26678
Improper access control in Windows Defender Application Control (WDAC) allows an unauthorized attacker to bypass a security feature locally.
Windows 10 1809
10.0.17763.7136 / 10.0.19044.5737+
MEDIUM 6.5
CVE-2025-21197
Improper access control in Windows NTFS allows an authorized attacker to disclose file path information under a folder where the attacker doesn't hav…
Windows 10 1507
10.0.10240.20978 / 10.0.14393.7969+
HIGH 8.8
CVE-2025-26645
Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
Windows 10 1507
10.0.10240.20947 / 10.0.14393.7876+
HIGH 7.3
CVE-2025-24994
Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally.
Windows 11 22h2
10.0.22621.5039 / 10.0.22631.5039+
HIGH 7.3
CVE-2025-24076
Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally.
Windows 11 22h2
10.0.22621.5039 / 10.0.22631.5039+
CRITICAL 9.8
CVE-2025-24989 KEV
An improper access control vulnerability in Power Pages allows an unauthorized attacker to elevate privileges over a network potentially bypassing th…
Power Pages
Patch available
HIGH 7.3
CVE-2025-24042
Visual Studio Code JS Debug Extension Elevation of Privilege Vulnerability
Visual Studio Code
1.97.1+
HIGH 7.8
CVE-2025-21359
Windows Kernel Security Feature Bypass Vulnerability
Windows 10 1507
10.0.10240.20915 / 10.0.14393.7785+
MEDIUM 6.5
CVE-2025-21185
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
Edge Chromium
132.0.2957.115+
HIGH 7.3
CVE-2025-21405
Visual Studio Elevation of Privilege Vulnerability
Visual Studio 2022
17.12.4+
MEDIUM 5.5
CVE-2025-21340
Windows Virtualization-Based Security (VBS) Security Feature Bypass Vulnerability
Windows 10 1809
10.0.17763.6775 / 10.0.19044.5371+
MEDIUM 6.5
CVE-2025-21301
Windows Geolocation Service Information Disclosure Vulnerability
Windows 10 1507
10.0.10240.20890 / 10.0.14393.7699+
HIGH 8.8
CVE-2025-21293EPSS 19%
Active Directory Domain Services Elevation of Privilege Vulnerability
Windows 10 1507
10.0.10240.20890 / 10.0.14393.7699+
MEDIUM 6.1
CVE-2025-21202
Windows Recovery Environment Agent Elevation of Privilege Vulnerability
Windows 10 1507
10.0.10240.20890 / 10.0.14393.7699+
MEDIUM 6.5
CVE-2025-21380
Improper access control in Azure SaaS Resources allows an authorized attacker to disclose information over a network.
Azure Marketplace
No fix yet
HIGH 8.4
CVE-2024-49105
Remote Desktop Client Remote Code Execution Vulnerability
Remote Desktop Client
1.2.5716.0 / 2.0.327.0+
HIGH 7.3
CVE-2024-49107
WmsRepair Service Elevation of Privilege Vulnerability
Windows 10 1507
10.0.10240.20857 / 10.0.14393.7606+
HIGH 8.2
CVE-2024-49068
Microsoft SharePoint Elevation of Privilege Vulnerability
Sharepoint Server
Mitigation only
HIGH 7.8
CVE-2024-43600
Microsoft Office Elevation of Privilege Vulnerability
Office
No fix yet
HIGH 7.3
CVE-2024-43594
Microsoft System Center Elevation of Privilege Vulnerability
System Center 2019
10.19.10050.0 / 10.22.10118.0+
HIGH 7.1
CVE-2024-49049
Visual Studio Code Remote Extension Elevation of Privilege Vulnerability
Remote Ssh
0.115.1+
MEDIUM 6.7
CVE-2024-49044
Visual Studio Elevation of Privilege Vulnerability
Visual Studio 2022
17.6.21 / 17.8.16+
HIGH 7.8
CVE-2024-43530
Windows Update Stack Elevation of Privilege Vulnerability
Windows 10 21h2
10.0.19044.5131 / 10.0.19045.5131+
MEDIUM 6.5
CVE-2024-38204
Improper access control in Imagine Cup allows an authorized attacker to elevate privileges over a network.
Azure Functions
Patch available
HIGH 7.8
CVE-2024-43590
Visual C++ Redistributable Installer Elevation of Privilege Vulnerability
Visual C\+\+ Redistributable
14.40.33816 / 15.9.67+
HIGH 7.8
CVE-2024-43503
Microsoft SharePoint Elevation of Privilege Vulnerability
Sharepoint Server
Patch available
HIGH 7.4
CVE-2024-43456
Windows Remote Desktop Services Tampering Vulnerability
Windows Server 2008
10.0.14393.7428 / 10.0.17763.6414+
HIGH 7.8
CVE-2024-38016
Microsoft Office Visio Remote Code Execution Vulnerability
365 Apps
Patch available
HIGH 7.8
CVE-2024-43492
Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability
Autoupdate
4.72+
HIGH 8.5
CVE-2024-43479
Microsoft Power Automate Desktop Remote Code Execution Vulnerability
Power Automate
2.41.178.24249 / 2.42.331.24249+