Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.8
CVE-2026-21516
Improper neutralization of special elements used in a command ('command injection') in Github Copilot allows an unauthorized attacker to execute code…
Github Copilot
1.5.63-243+
HIGH 8.8
CVE-2026-21256
Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an unauthorized attack…
Visual Studio 2022
17.14.26+
HIGH 8.0
CVE-2026-21257
Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an authorized attacker…
Visual Studio 2022
17.14.26+
HIGH 7.8
CVE-2026-20841EPSS 12%
Improper neutralization of special elements used in a command ('command injection') in Windows Notepad App allows an unauthorized attacker to execute…
Windows Notepad
11.2510+
HIGH 7.5
CVE-2026-21520
Exposure of Sensitive Information to an Unauthorized Actor in Copilot Studio allows a unauthenticated attacker to view sensitive information through …
Copilot Studio
Mitigation only
HIGH 7.8
CVE-2025-64671
Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to execute code locall…
Github Copilot
1.5.60-243+
HIGH 7.8
CVE-2025-54100
Improper neutralization of special elements used in a command ('command injection') in Windows PowerShell allows an unauthorized attacker to execute …
Windows 10 1607
10.0.14393.8688 / 10.0.17763.8146+
HIGH 8.8
CVE-2025-62222
Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code CoPilot Chat Extension allows an unauthoriz…
Github Copilot Chat
0.32.5+
MEDIUM 6.7
CVE-2025-62214
Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an authorized attacker to execute code lo…
Visual Studio 2022
17.14.17+
CRITICAL 9.3
CVE-2025-59286
Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to disclose informatio…
365 Copilot Chat
Mitigation only
CRITICAL 9.3
CVE-2025-59252
Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to disclose informatio…
365 Word Copilot
Mitigation only
CRITICAL 9.3
CVE-2025-59272
Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to perform information…
365 Copilot Chat
Mitigation only
CRITICAL 9.8
CVE-2025-55319
Ai command injection in Agentic AI and Visual Studio Code allows an unauthorized attacker to execute code over a network.
Visual Studio Code
1.104.0+
HIGH 8.8
CVE-2025-55227
Improper neutralization of special elements used in a command ('command injection') in SQL Server allows an authorized attacker to elevate privileges…
Sql Server 2016
13.0.6470.1 / 13.0.7065.1+
HIGH 7.8
CVE-2025-53773
Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an unauthorized attack…
Visual Studio 2022
17.14.12+
HIGH 7.5
CVE-2025-53774
Microsoft 365 Copilot BizChat Information Disclosure Vulnerability
365 Copilot Chat
No fix yet
HIGH 7.5
CVE-2025-53787
Microsoft 365 Copilot BizChat Information Disclosure Vulnerability
365 Copilot Chat
No fix yet
HIGH 7.1
CVE-2025-47959EPSS 7%
Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an authorized attacker to execute code ov…
Visual Studio 2022
17.8.22 / 17.10.16+
HIGH 7.8
CVE-2025-32702
Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an unauthorized attacker to execute code …
Visual Studio 2019
16.11.47 / 17.8.21+
HIGH 7.0
CVE-2025-26627
Improper neutralization of special elements used in a command ('command injection') in Azure Arc allows an authorized attacker to elevate privileges …
Azure Arc
1.0.10+
HIGH 8.4
CVE-2025-24049
Improper neutralization of special elements used in a command ('command injection') in Azure Command Line Integration (CLI) allows an unauthorized at…
Azure Command Line Interface
2.69.0+
HIGH 7.2
CVE-2024-49042
Azure Database for PostgreSQL Flexible Server Extension Elevation of Privilege Vulnerability
Azure Database For Postgresql Flexible Server
12.20 / 13.16+
HIGH 7.2
CVE-2024-43613
Azure Database for PostgreSQL Flexible Server Extension Elevation of Privilege Vulnerability
Azure Database For Postgresql Flexible Server
12.20 / 13.16+
HIGH 7.8
CVE-2024-49026
Microsoft Excel Remote Code Execution Vulnerability
365 Apps
Patch available
CRITICAL 9.1
CVE-2024-43591
Azure Command Line Integration (CLI) Elevation of Privilege Vulnerability
Azure Command Line Interface
2.65.0+
HIGH 7.8
CVE-2024-43601
Visual Studio Code for Linux Remote Code Execution Vulnerability
Visual Studio Code
1.94.1+
HIGH 7.8
CVE-2024-43497
DeepSpeed Remote Code Execution Vulnerability
Deepspeed
0.15.1+
HIGH 7.2
CVE-2024-38227EPSS 8%
Microsoft SharePoint Server Remote Code Execution Vulnerability
Sharepoint Server
Patch available
HIGH 7.2
CVE-2024-38228
Microsoft SharePoint Server Remote Code Execution Vulnerability
Sharepoint Server
Patch available
HIGH 7.2
CVE-2024-21322
Microsoft Defender for IoT Remote Code Execution Vulnerability
Defender For Iot
24.1.3+