Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 8.8
CVE-2025-29827
Improper authorization in Azure Automation allows an authorized attacker to elevate privileges over a network.
Azure Automation
Mitigation only
CRITICAL 9.8
CVE-2025-30389
Improper authorization in Azure Bot Framework SDK allows an unauthorized attacker to elevate privileges over a network.
Azure Ai Bot Service
Mitigation only
CRITICAL 9.8
CVE-2025-30392
Improper authorization in Azure Bot Framework SDK allows an unauthorized attacker to elevate privileges over a network.
Azure Ai Bot Service
Mitigation only
HIGH 8.8
CVE-2025-30390
Improper authorization in Azure allows an authorized attacker to elevate privileges over a network.
Azure Machine Learning
No fix yet
HIGH 8.8
CVE-2025-29794
Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Sharepoint Enterprise Server
16.0.18526.20172+
CRITICAL 9.8
CVE-2025-26683
Improper authorization in Azure Playwright allows an unauthorized attacker to elevate privileges over a network.
Azure Playwright
Mitigation only
HIGH 7.2
CVE-2025-24053
Improper authentication in Microsoft Dataverse allows an authorized attacker to elevate privileges over a network.
Dataverse
Mitigation only
HIGH 8.0
CVE-2025-21400EPSS 34%
Microsoft SharePoint Server Remote Code Execution Vulnerability
Sharepoint Server
16.0.17928.20396+
HIGH 7.2
CVE-2025-21348
Microsoft SharePoint Server Remote Code Execution Vulnerability
Sharepoint Server
16.0.17928.20356+
HIGH 7.8
CVE-2025-21275
Windows App Package Installer Elevation of Privilege Vulnerability
Windows 10 21h2
10.0.19044.5371 / 10.0.19045.5371+
CRITICAL 9.9
CVE-2024-43602
Azure CycleCloud Remote Code Execution Vulnerability
Azure Cyclecloud
8.6.5+
MEDIUM 6.6
CVE-2024-38129
Windows Kerberos Elevation of Privilege Vulnerability
Windows Server 2022 23h2
10.0.25398.1189+
HIGH 8.8
CVE-2024-43460
Improper authorization in Dynamics 365 Business Central resulted in a vulnerability that allows an authenticated attacker to elevate privileges over …
Dynamics 365 Business Central
Patch available
MEDIUM 6.5
CVE-2024-43482
Microsoft Outlook for iOS Information Disclosure Vulnerability
Outlook
4.2435.0+
HIGH 7.5
CVE-2024-38231
Windows Remote Desktop Licensing Service Denial of Service Vulnerability
Windows Server 2008
10.0.14393.7336 / 10.0.17763.6293+
HIGH 7.3
CVE-2024-30061
Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability
Dynamics 365
Patch available
MEDIUM 6.4
CVE-2024-26193
Azure Migrate Remote Code Execution Vulnerability
Azure Migrate
6.1.294.1003+
HIGH 7.1
CVE-2024-21402
Microsoft Outlook Elevation of Privilege Vulnerability
365 Apps
after 2401.17231.20236
MEDIUM 6.5
CVE-2023-33142
Microsoft SharePoint Server Elevation of Privilege Vulnerability
Sharepoint Server
Patch available
HIGH 7.6
CVE-2023-32022
Windows Server Service Security Feature Bypass Vulnerability
Windows Server 2012
Patch available
MEDIUM 6.6
CVE-2023-29338
Visual Studio Code Spoofing Vulnerability
Visual Studio Code
1.78.1+
HIGH 8.8
CVE-2023-21549
Windows SMB Witness Service Elevation of Privilege Vulnerability
Windows 10 1607
Mitigation only
CRITICAL 10.0
CVE-2021-37705
OneFuzz is an open source self-hosted Fuzzing-As-A-Service platform. Starting with OneFuzz 2.12.0 or greater, an incomplete authorization check allow…
Onefuzz
2.31.0+
HIGH 8.8
CVE-2016-3352EPSS 21%
Microsoft Windows 8.1, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 do not properly check NTLM SSO requests for MSA logins, which makes it eas…
Windows 10
Mitigation only