Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 5.4
CVE-2026-21529
Improper neutralization of input during web page generation ('cross-site scripting') in Azure HDInsights allows an authorized attacker to perform spo…
Azure Hdinsight
5.1+
MEDIUM 6.1
CVE-2026-21264
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Account allows an unauthorized attacker to perform …
Account
Mitigation only
MEDIUM 5.4
CVE-2026-20959EPSS 7%
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to …
Sharepoint Server
16.0.19127.20442+
CRITICAL 9.6
CVE-2025-64675
Improper neutralization of input during web page generation ('cross-site scripting') in Azure Cosmos DB allows an unauthorized attacker to perform sp…
Azure Cosmos Db
Mitigation only
HIGH 8.2
CVE-2025-64677
Improper neutralization of input during web page generation ('cross-site scripting') in Office Out-of-Box Experience allows an unauthorized attacker …
Office Out Of Box Experience
Mitigation only
CRITICAL 9.0
CVE-2025-64672
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to …
Sharepoint Server
16.0.19127.20378+
MEDIUM 6.1
CVE-2025-62459
Microsoft Defender Portal Spoofing Vulnerability
365 Defender Portal
No fix yet
HIGH 8.7
CVE-2025-62210
Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Field Service (online) allows an authorized atta…
Dynamics 365
8.8.139.398+
HIGH 8.7
CVE-2025-62211
Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Field Service (online) allows an authorized atta…
Dynamics 365
8.8.139.398+
CRITICAL 9.3
CVE-2025-55321
Improper neutralization of input during web page generation ('cross-site scripting') in Azure Monitor allows an unauthorized attacker to perform spoo…
Azure Monitor
Mitigation only
MEDIUM 5.4
CVE-2025-49745
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Dynamics 365 (on-premises) allows an unauthorized a…
Dynamics 365
9.1.38.10+
HIGH 8.2
CVE-2025-47977
Improper neutralization of input during web page generation ('cross-site scripting') in Nuance Digital Engagement Platform allows an unauthorized att…
Nuance Digital Engagement Platform
5.64.x+
MEDIUM 6.3
CVE-2025-21393
Microsoft SharePoint Server Spoofing Vulnerability
Sharepoint Server
16.0.17928.20356+
MEDIUM 6.1
CVE-2024-54138
NuGet Gallery is a package repository that powers nuget.org. The NuGetGallery has a security vulnerability related to its handling of autolinks in Ma…
Nugetgallery
2024.12.06+
HIGH 7.6
CVE-2024-49053
Microsoft Dynamics 365 Sales Spoofing Vulnerability
Dynamics 365 Sales
3.24104.15+
CRITICAL 9.6
CVE-2024-49038
Improper neutralization of input during web page generation ('Cross-site Scripting') in Copilot Studio by an unauthorized attacker leads to elevation…
Copilot Studio
Mitigation only
HIGH 8.1
CVE-2024-43573 KEVEPSS 44%
Windows MSHTML Platform Spoofing Vulnerability
Windows 10 1507
10.0.10240.20796 / 10.0.14393.7428+
HIGH 8.8
CVE-2024-43481
Power BI Report Server Spoofing Vulnerability
Power Bi Report Server
15.0.1116.121+
MEDIUM 6.1
CVE-2024-47604
NuGet Gallery is a package repository that powers nuget.org. The NuGetGallery has a security vulnerability in its handling of HTML element attributes…
Nugetgallery
2024.09.25+
MEDIUM 5.4
CVE-2024-43476
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
Dynamics 365
9.1.32+
MEDIUM 6.1
CVE-2024-38208
Microsoft Edge for Android Spoofing Vulnerability
Edge
128.0.2739.42+
HIGH 8.2
CVE-2024-38211
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
Dynamics 365
Patch available
CRITICAL 9.3
CVE-2024-38108
Azure Stack Hub Spoofing Vulnerability
Azure Stack Hub
1.2311.1.22+
MEDIUM 6.1
CVE-2024-38166
An unauthenticated attacker can exploit improper neutralization of input during web page generation in Microsoft Dynamics 365 to spoof over a network…
Dynamics Crm Service Portal Web Resource
Patch available
MEDIUM 6.1
CVE-2024-38156
Microsoft Edge (Chromium-based) Spoofing Vulnerability
Edge
126.0.2592.102+
HIGH 7.6
CVE-2024-35266
Azure DevOps Server Spoofing Vulnerability
Azure Devops Server
Patch available
HIGH 7.6
CVE-2024-35267
Azure DevOps Server Spoofing Vulnerability
Azure Devops Server
Patch available
MEDIUM 6.1
CVE-2024-37304
NuGet Gallery is a package repository that powers nuget.org. The NuGetGallery has a security vulnerability related to its handling of autolinks in Ma…
Nugetgallery
2024.05.28+
MEDIUM 5.4
CVE-2024-30053
Azure Migrate Cross-Site Scripting Vulnerability
Azure Migrate
6.1.294.1008+
MEDIUM 5.4
CVE-2024-21419
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
Dynamics 365
9.1.26+