Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.5
CVE-2026-26120
Server-side request forgery (ssrf) in Microsoft Bing allows an unauthorized attacker to perform tampering over a network.
Bing
No fix yet
HIGH 8.8
CVE-2026-26118
Server-side request forgery (ssrf) in Azure MCP Server allows an authorized attacker to elevate privileges over a network.
Azure Mcp Server
2.0.0+
HIGH 7.5
CVE-2026-26121
Server-side request forgery (ssrf) in Azure IoT Explorer allows an unauthorized attacker to perform spoofing over a network.
Azure Iot Explorer
0.15.14+
MEDIUM 6.5
CVE-2026-21512
Server-side request forgery (ssrf) in Azure DevOps Server allows an authorized attacker to perform spoofing over a network.
Azure Devops Server
2022.2.0+
MEDIUM 5.4
CVE-2026-20958
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.
Sharepoint Server
16.0.19127.20442+
HIGH 8.8
CVE-2025-64663
Custom Question Answering Elevation of Privilege Vulnerability
Azure Language
No fix yet
CRITICAL 9.8
CVE-2025-62207
Azure Monitor Elevation of Privilege Vulnerability
Azure Monitor
No fix yet
CRITICAL 9.8
CVE-2025-59503
Server-side request forgery (ssrf) in Azure Compute Gallery allows an unauthorized attacker to elevate privileges over a network.
Azure Compute Resource Provider
Mitigation only
HIGH 7.1
CVE-2025-53760EPSS 12%
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
Sharepoint Server
16.0.18526.20518+
CRITICAL 10.0
CVE-2025-53767
Azure OpenAI Elevation of Privilege Vulnerability
Azure Openai
No fix yet
HIGH 7.5
CVE-2025-47733
Server-Side Request Forgery (SSRF) in Microsoft Power Apps allows an unauthorized attacker to disclose information over a network
Power Apps
Mitigation only
CRITICAL 9.8
CVE-2025-29972
Server-side request forgery (ssrf) in Azure Storage Resource Provider allows an authorized attacker to perform spoofing over a network.
Azure Storage Resource Provider
Mitigation only
HIGH 8.8
CVE-2025-21384
An authenticated attacker can exploit an Server-Side Request Forgery (SSRF) vulnerability in Microsoft Azure Health Bot to elevate privileges over a …
Azure Health Bot
Mitigation only
HIGH 8.8
CVE-2025-21177
Server-side request forgery (ssrf) in Microsoft Dynamics 365 Sales allows an authorized attacker to elevate privileges over a network.
Dynamics 365 Sales
Mitigation only
MEDIUM 6.5
CVE-2025-21385EPSS 24%
A Server-Side Request Forgery (SSRF) vulnerability in Microsoft Purview allows an authorized attacker to disclose information over a network.
Purview
No fix yet
CRITICAL 9.8
CVE-2024-38183
An improper access control vulnerability in GroupMe allows an a unauthenticated attacker to elevate privileges over a network.
Groupme
Patch available
HIGH 8.8
CVE-2024-38109
An authenticated attacker can exploit an Server-Side Request Forgery (SSRF) vulnerability in Microsoft Azure Health Bot to elevate privileges over a …
Azure Health Bot
Patch available
MEDIUM 6.5
CVE-2024-38206EPSS 12%
An authenticated attacker can bypass Server-Side Request Forgery (SSRF) protection in Microsoft Copilot Studio to leak sensitive information over a n…
Copilot Studio
Patch available
HIGH 7.5
CVE-2024-32987
Microsoft SharePoint Server Information Disclosure Vulnerability
Sharepoint Server
Patch available
MEDIUM 5.3
CVE-2023-41763 KEVEPSS 90%
Skype for Business Elevation of Privilege Vulnerability
Skype For Business Server
Patch available
MEDIUM 5.4
CVE-2023-32052
Microsoft Power Apps (online) Spoofing Vulnerability
Power Apps
9.2.23042+
MEDIUM 6.5
CVE-2023-24954
Microsoft SharePoint Server Information Disclosure Vulnerability
Windows 10 1507
10.0.10240.19926 / 10.0.14393.5921+
HIGH 8.1
CVE-2023-28288EPSS 6%
Microsoft SharePoint Server Spoofing Vulnerability
Sharepoint Foundation
Patch available
HIGH 7.5
CVE-2023-21761
Microsoft Exchange Server Information Disclosure Vulnerability
Exchange Server
No fix yet
HIGH 8.8
CVE-2022-41040 KEVEPSS 100%
Microsoft Exchange Server Elevation of Privilege Vulnerability
Exchange Server
Patch available
CRITICAL 9.1
CVE-2021-34473 KEVEPSS 100%
Microsoft Exchange Server Remote Code Execution Vulnerability
Exchange Server
Patch available
HIGH 7.6
CVE-2021-31950
Microsoft SharePoint Server Spoofing Vulnerability
Sharepoint Foundation
Patch available
CRITICAL 9.1
CVE-2021-26855 KEVEPSS 100%
Microsoft Exchange Server Remote Code Execution Vulnerability
Exchange Server
Patch available
HIGH 8.6
CVE-2018-16793EPSS 11%
Rollup 18 for Microsoft Exchange Server 2010 SP3 and previous versions has an SSRF vulnerability via the username parameter in /owa/auth/logon.aspx i…
Exchange Server
No fix yet
HIGH 8.6
CVE-2018-16794EPSS 8%
Microsoft ADFS 4.0 Windows Server 2016 and previous (Active Directory Federation Services) has an SSRF vulnerability via the txtBoxEmail parameter in…
Active Directory Federation Services
after 4.0