Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 8.8
CVE-2026-70340
Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network.
Azure Cyclecloud
No fix yet
MEDIUM 6.5
CVE-2026-65806
Missing authorization in Azure CycleCloud allows an authorized attacker to disclose information over a network.
Azure Cyclecloud
No fix yet
MEDIUM 6.5
CVE-2026-62915
Missing authorization in Microsoft Exchange Server allows an authorized attacker to bypass a security feature over a network.
Exchange Server
15.02.2562.046+
MEDIUM 5.5
CVE-2026-61936
Missing authorization in Windows Defender Firewall Service allows an authorized attacker to bypass a security feature locally.
Windows 10 1809
10.0.17763.9115 / 10.0.19044.7663+
HIGH 8.8
CVE-2026-59113
Missing authorization in Visual Studio Code allows an unauthorized attacker to execute code over a network.
Visual Studio Code
No fix yet
MEDIUM 6.5
CVE-2026-40375
Missing authorization in Dynamics Business Central allows an authorized attacker to disclose information over a network.
Dynamics 365 Business Central 2024
26.0.50788 / 27.0.50789+
CRITICAL 10.0
CVE-2026-65667
Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network.
Teams
No fix yet
CRITICAL 9.9
CVE-2026-62830
Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network.
Azure Sre Agent
No fix yet
HIGH 8.8
CVE-2026-66326
Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Edge Chromium
151.0.4129.59+
MEDIUM 6.2
CVE-2026-66311
Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally.
Edge Chromium
151.0.4129.59+
CRITICAL 9.8
CVE-2026-58275
Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network.
Azure Dns
No fix yet
HIGH 8.8
CVE-2026-55052
Missing authorization in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
Sharepoint Server
16.0.19725.20434+
MEDIUM 6.5
CVE-2026-58279
Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network.
Azure Cyclecloud
8.9.1+
CRITICAL 9.6
CVE-2026-48582
Missing authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network.
Exchange Online
Mitigation only
CRITICAL 9.6
CVE-2026-47281
Missing authorization in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.
Visual Studio Code
1.123.1+
HIGH 8.3
CVE-2026-35438
Missing authorization in Windows Admin Center allows an authorized attacker to elevate privileges over a network.
Windows Admin Center
2511+
HIGH 8.1
CVE-2025-30398
Missing authorization in Nuance PowerScribe allows an unauthorized attacker to disclose information over a network.
Nuance Powerscribe 360
Mitigation only
CRITICAL 9.1
CVE-2025-50171
Missing authorization in Remote Desktop Server allows an unauthorized attacker to perform spoofing over a network.
Windows Server 2022
10.0.20348.3989 / 10.0.25398.1791+
HIGH 8.8
CVE-2025-49747
Missing authorization in Azure Machine Learning allows an authorized attacker to elevate privileges over a network.
Azure Machine Learning
Mitigation only
HIGH 8.8
CVE-2025-49723
Missing authorization in Windows StateRepository API allows an authorized attacker to perform tampering locally.
Windows 10 1809
10.0.17763.7558 / 10.0.19044.6093+
HIGH 8.8
CVE-2025-21416
Missing authorization in Azure Virtual Desktop allows an authorized attacker to elevate privileges over a network.
Azure Virtual Desktop
Mitigation only
HIGH 8.2
CVE-2025-21396
Missing authorization in Microsoft Account allows an unauthorized attacker to elevate privileges over a network.
Account
No fix yet
HIGH 8.6
CVE-2024-38190
Missing authorization in Power Platform allows an unauthenticated attacker to view sensitive information through a network attack vector.
Power Platform
Patch available
HIGH 8.8
CVE-2024-38179
Azure Stack Hyperconverged Infrastructure (HCI) Elevation of Privilege Vulnerability
Azure Stack Hci
Patch available
HIGH 8.8
CVE-2024-21417
Windows Text Services Framework Elevation of Privilege Vulnerability
Windows 10 1809
10.0.17763.6054 / 10.0.19044.4651+
MEDIUM 5.5
CVE-2020-0989
<p>An information disclosure vulnerability exists when Windows Mobile Device Management (MDM) Diagnostics improperly handles junctions. An attacker w…
Windows 10
Patch available
HIGH 7.9
CVE-2019-1170
An elevation of privilege vulnerability exists when reparse points are created by sandboxed processes allowing sandbox escape. An attacker who succes…
Windows 10
Patch available
HIGH 8.8
CVE-2019-0566EPSS 19%
An elevation of privilege vulnerability exists in Microsoft Edge Browser Broker COM object, aka "Microsoft Edge Elevation of Privilege Vulnerability.…
Edge
Patch available
HIGH 7.8
CVE-2019-0555
An elevation of privilege vulnerability exists in the Microsoft XmlDocument class that could allow an attacker to escape from the AppContainer sandbo…
Windows 10
Patch available
HIGH 7.8
CVE-2019-0573EPSS 20%
An elevation of privilege vulnerability exists when the Windows Data Sharing Service improperly handles file operations, aka "Windows Data Sharing Se…
Windows 10
Patch available