Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 5.4
CVE-2026-47634
Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Office SharePoint allows an authorize…
Sharepoint Server
16.0.19725.20384+
HIGH 8.1
CVE-2026-42835
Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Teams for Android allows an authorize…
Teams
1.0.76.2026111302+
HIGH 7.5
CVE-2026-47644
Improper neutralization of special elements in output used by a downstream component ('injection') in Copilot Chat (Microsoft Edge) allows an unautho…
Copilot Chat
Mitigation only
MEDIUM 5.4
CVE-2026-42838
Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Edge (Chromium-based) allows an unaut…
Edge Chromium
148.0.3967.55+
HIGH 8.8
CVE-2026-41109
Improper neutralization of special elements in output used by a downstream component ('injection') in GitHub Copilot and Visual Studio allows an unau…
Visual Studio Code
1.119.1+
HIGH 8.2
CVE-2026-33833
Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Machine Learning allows an unauthorized a…
Azure Machine Learning
Mitigation only
HIGH 7.5
CVE-2026-26164
Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose infor…
365 Copilot Chat
No fix yet
HIGH 7.5
CVE-2025-32711EPSS 8%
Ai command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.
365 Copilot
No fix yet
HIGH 7.8
CVE-2020-35608
A code execution vulnerability exists in the normal world’s signed code execution functionality of Microsoft Azure Sphere 20.07. A specially crafted …
Azure Sphere
No fix yet
HIGH 8.4
CVE-2020-16875EPSS 47%
<p>A remote code execution vulnerability exists in Microsoft Exchange server due to improper validation of cmdlet arguments.</p>
<p>An attacker who s…
Exchange Server
Patch available
MEDIUM 5.4
CVE-2019-1490
A spoofing vulnerability exists when a Skype for Business Server does not properly sanitize a specially crafted request, aka 'Skype for Business Serv…
Skype For Business
Patch available
HIGH 7.1
CVE-2015-1762EPSS 10%
Microsoft SQL Server 2008 SP3 and SP4, 2008 R2 SP2 and SP3, 2012 SP1 and SP2, and 2014, when transactional replication is configured, does not preven…
Sql Server
Mitigation only