Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 6.5
CVE-2025-53771EPSS 100%
Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
Sharepoint Server
16.0.18526.20508+
MEDIUM 6.5
CVE-2025-49706 KEVEPSS 100%
Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
Sharepoint Enterprise Server
16.0.18526.20424+
MEDIUM 6.5
CVE-2025-26685
Improper authentication in Microsoft Defender for Identity allows an unauthorized attacker to perform spoofing over an adjacent network.
Defender For Identity
Mitigation only
CRITICAL 9.8
CVE-2025-29813
Authentication bypass by assumed-immutable data in Azure DevOps allows an unauthorized attacker to elevate privileges over a network.
Azure Devops
Mitigation only
MEDIUM 6.8
CVE-2025-21349
Windows Remote Desktop Configuration Service Tampering Vulnerability
Windows 10 1507
10.0.10240.20915 / 10.0.14393.7785+
HIGH 7.8
CVE-2024-49076
Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability
Windows 10 1809
10.0.17763.6659 / 10.0.19044.5247+
HIGH 8.8
CVE-2024-49039 KEVEPSS 14%
Windows Task Scheduler Elevation of Privilege Vulnerability
Windows 10 1507
10.0.10240.20826 / 10.0.14393.7515+
HIGH 8.8
CVE-2024-38139
Improper authentication in Microsoft Dataverse allows an authorized attacker to elevate privileges over a network.
Dataverse
Patch available
CRITICAL 9.0
CVE-2024-38124
Windows Netlogon Elevation of Privilege Vulnerability
Windows Server 2008
10.0.14393.7428 / 10.0.17763.6414+
CRITICAL 9.8
CVE-2024-38225
Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability
Dynamics 365 Business Central
Patch available
MEDIUM 5.9
CVE-2024-38099
Windows Remote Desktop Licensing Service Denial of Service Vulnerability
Windows Server 2008
10.0.14393.7159 / 10.0.17763.6054+
HIGH 7.3
CVE-2024-35248
Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability
Dynamics 365 Business Central
Patch available
HIGH 7.5
CVE-2024-21427
Windows Kerberos Security Feature Bypass Vulnerability
Windows Server 2012
10.0.14393.6897 / 10.0.17763.5696+
HIGH 7.1
CVE-2024-21390
Microsoft Authenticator Elevation of Privilege Vulnerability
Authenticator
6.2401.0617+
CRITICAL 9.8
CVE-2024-21410 KEVEPSS 13%
Microsoft Exchange Server Elevation of Privilege Vulnerability
Exchange Server
Patch available
CRITICAL 9.8
CVE-2024-21638
Azure IPAM (IP Address Management) is a lightweight solution developed on top of the Azure platform designed to help Azure customers manage their IP …
Azure Ipam
3.0.0+
HIGH 7.5
CVE-2023-36004
Windows DPAPI (Data Protection Application Programming Interface) Spoofing Vulnerability
Windows 10 1507
10.0.10240.20345 / 10.0.14393.6529+
MEDIUM 5.5
CVE-2023-36724
Windows Power Management Service Information Disclosure Vulnerability
Windows 10 1507
10.0.10240.20232 / 10.0.14393.6351+
HIGH 7.8
CVE-2023-21817
Windows Kerberos Elevation of Privilege Vulnerability
Windows 10
10.0.10240.19747 / 10.0.14393.5717+
MEDIUM 6.5
CVE-2023-21721
Microsoft OneNote Elevation of Privilege Vulnerability
Onenote
16.0.16026.20158+
HIGH 7.5
CVE-2022-30150
Windows Defender Remote Credential Guard Elevation of Privilege Vulnerability
Windows 10
Patch available
HIGH 7.1
CVE-2021-36949
Microsoft Azure Active Directory Connect Authentication Bypass Vulnerability
Azure Active Directory Connect
1.1.582.0+
MEDIUM 5.5
CVE-2021-1725
Bot Framework SDK Information Disclosure Vulnerability
Bot Framework Software Development Kit
No fix yet
HIGH 8.8
CVE-2020-0688 KEVEPSS 100%
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka 'Micros…
Exchange Server
Patch available
HIGH 7.8
CVE-2019-0543 KEV
An elevation of privilege vulnerability exists when Windows improperly handles authentication requests, aka "Microsoft Windows Elevation of Privilege…
Windows 10 1507
Patch available
HIGH 7.5
CVE-2018-8171EPSS 10%
A Security Feature Bypass vulnerability exists in ASP.NET when the number of incorrect login attempts is not validated, aka "ASP.NET Security Feature…
Asp.net Core
Patch available
HIGH 7.0
CVE-2018-0886EPSS 82%
The Credential Security Support Provider protocol (CredSSP) in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, W…
Windows 10
Patch available
HIGH 7.5
CVE-2017-8495
Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607,…
Windows 10
Patch available
HIGH 7.8
CVE-2017-0100
A DCOM object in Helppane.exe in Microsoft Windows 7 SP1; Windows Server 2008 R2; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windo…
Windows 10
Patch available
HIGH 8.1
CVE-2016-7191EPSS 29%
The Microsoft Azure Active Directory Passport (aka Passport-Azure-AD) library 1.x before 1.4.6 and 2.x before 2.0.1 for Node.js does not recognize th…
Azure Active Directory Passport
Patch available