Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
CRITICAL 9.0
CVE-2024-38220
Azure Stack Hub Elevation of Privilege Vulnerability
Azure Stack Hub
1.2311.1.22+
CRITICAL 9.8
CVE-2024-37341
Microsoft SQL Server Elevation of Privilege Vulnerability
Sql 2016 Azure Connect Feature Pack
13.0.6441.1 / 13.0.7040.1+
HIGH 7.5
CVE-2024-43477
Improper access control in Decentralized Identity Services resulted in a vulnerability that allows an unauthenticated attacker to disable Verifiable …
Entra Id
Mitigation only
HIGH 8.8
CVE-2024-38175
An improper access control vulnerability in the Azure Managed Instance for Apache Cassandra allows an authenticated attacker to elevate privileges ov…
Azure Managed Instance For Apache Cassandra
Mitigation only
HIGH 7.8
CVE-2024-38163
Windows Update Stack Elevation of Privilege Vulnerability
Windows 10 21h2
10.0.19041.3920 / 10.0.20348.2201+
MEDIUM 6.8
CVE-2024-38223
Windows Initial Machine Configuration Elevation of Privilege Vulnerability
Windows 10 1507
10.0.10240.20751 / 10.0.14393.7259+
HIGH 7.8
CVE-2024-38195
Azure CycleCloud Remote Code Execution Vulnerability
Azure Cyclecloud
8.6.3+
HIGH 7.8
CVE-2024-38162
Azure Connected Machine Agent Elevation of Privilege Vulnerability
Azure Connected Machine Agent
1.44+
HIGH 7.3
CVE-2024-38202
Summary
Microsoft was notified that an elevation of privilege vulnerability exists in Windows Update, potentially enabling an attacker with basic use…
Windows 10 1607
Patch available
MEDIUM 6.7
CVE-2024-21302
Summary:
As of July 8, 2025 Microsoft has completed mitigations to address this vulnerability. See KB5042562: Guidance for blocking rollback of virtu…
Windows 10 1507
10.0.10240.20710 / 10.0.14393.7259+
HIGH 8.8
CVE-2024-38164
An improper access control vulnerability in GroupMe allows an a unauthenticated attacker to elevate privileges over a network by convincing a user to…
Groupme
Patch available
HIGH 7.8
CVE-2024-38100
Windows File Explorer Elevation of Privilege Vulnerability
Windows Server 2016
10.0.14393.7159 / 10.0.17763.6054+
HIGH 7.5
CVE-2024-38061
DCOM Remote Cross-Session Activation Elevation of Privilege Vulnerability
Windows 10 1507
10.0.10240.20710 / 10.0.14393.7159+
MEDIUM 6.7
CVE-2024-29060
Visual Studio Elevation of Privilege Vulnerability
Visual Studio 2017
15.9.63 / 16.11.37+
MEDIUM 5.5
CVE-2024-30059
Microsoft Intune for Android Mobile Application Management Tampering Vulnerability
Intune Mobile Application Management
5.0.6215.0+
CRITICAL 9.0
CVE-2024-29990EPSS 18%
Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability
Azure Kubernetes Service Confidential Containers
0.3.4+
HIGH 8.8
CVE-2024-29993
Azure CycleCloud Elevation of Privilege Vulnerability
Azure Cyclecloud
No fix yet
HIGH 7.2
CVE-2024-29054
Microsoft Defender for IoT Elevation of Privilege Vulnerability
Defender For Iot
24.1.3+
HIGH 7.2
CVE-2024-29055
Microsoft Defender for IoT Elevation of Privilege Vulnerability
Defender For Iot
24.1.3+
MEDIUM 6.2
CVE-2024-28917
Azure Arc-enabled Kubernetes Extension Cluster-Scope Elevation of Privilege Vulnerability
Azure Arc Extension Microsoft.azstackhci.operator
0.3.0-preview / 1.0.2620-162+
MEDIUM 6.7
CVE-2024-26234
Proxy Driver Spoofing Vulnerability
Windows 10 1507
10.0.10240.20596 / 10.0.14393.6897+
MEDIUM 6.5
CVE-2024-21424
Azure Compute Gallery Elevation of Privilege Vulnerability
Azure Compute Gallery
No fix yet
HIGH 7.3
CVE-2024-26203
Azure Data Studio Elevation of Privilege Vulnerability
Azure Data Studio
1.48.0+
MEDIUM 6.6
CVE-2024-26201
Microsoft Intune Linux Agent Elevation of Privilege Vulnerability
Intune Company Portal
1.2402.12+
HIGH 7.8
CVE-2024-21436
Windows Installer Elevation of Privilege Vulnerability
Windows 10 1507
10.0.10240.20526 / 10.0.14393.6796+
CRITICAL 9.8
CVE-2024-21401
Microsoft Entra Jira Single-Sign-On Plugin Elevation of Privilege Vulnerability
Entra Jira Sso Plugin
1.1.2+
CRITICAL 9.0
CVE-2024-21376
Microsoft Azure Kubernetes Service Confidential Container Remote Code Execution Vulnerability
Azure Kubernetes Service
Patch available
CRITICAL 9.3
CVE-2024-21364
Microsoft Azure Site Recovery Elevation of Privilege Vulnerability
Azure Site Recovery
Patch available
MEDIUM 5.7
CVE-2024-20695
Skype for Business Information Disclosure Vulnerability
Skype For Business Server
Patch available
MEDIUM 6.3
CVE-2024-20675
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
Edge Chromium
120.0.2210.133+