Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 8.8
CVE-2026-70336
Improper control of generation of code ('code injection') in Visual Studio Code allows an unauthorized attacker to execute code over a network.
Visual Studio Code
1.132.1+
HIGH 7.8
CVE-2026-70338
Improper control of generation of code ('code injection') in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locall…
Powershell
7.4.19.0 / 7.5.10.0+
MEDIUM 6.5
CVE-2026-65660
Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a net…
Sharepoint Server
16.0.19725.20522+
MEDIUM 6.1
CVE-2026-65804
Improper control of generation of code ('code injection') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over…
Edge Chromium
151.0.4129.59+
HIGH 7.8
CVE-2026-50650
Improper control of generation of code ('code injection') in .NET Framework allows an unauthorized attacker to elevate privileges locally.
.net Framework
8.0.29 / 9.0.18+
MEDIUM 6.5
CVE-2026-56185
Improper authentication in Windows Admin Center allows an authorized attacker to disclose information over a network.
Windows Admin Center
2511+
HIGH 7.8
CVE-2026-47292
Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to elevate privileges locally.
Visual Studio Code
1.123.1+
HIGH 8.1
CVE-2026-45583
Improper control of generation of code ('code injection') in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network.
Exchange Server
15.02.2562.043+
CRITICAL 9.8
CVE-2026-45495
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Edge Chromium
148.0.3967.70+
CRITICAL 9.9
CVE-2026-42898
Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over …
Dynamics 365
9.1.45.11+
HIGH 8.8
CVE-2026-41094
Improper control of generation of code ('code injection') in Microsoft Data Formulator allows an unauthorized attacker to execute code over a network.
Data Formulator
0.7+
HIGH 7.8
CVE-2026-41134
Kiota is an OpenAPI based HTTP Client code generator. Versions prior to 1.29.1 and 1.31.1 are affected by a code-generation literal injection vulnera…
Kiota
1.31.1+
CRITICAL 9.9
CVE-2026-26030
Semantic Kernel, Microsoft's semantic kernel Python SDK, has a remote code execution vulnerability in versions prior to 1.39.4, specifically within t…
Semantic Kernel
1.39.4+
HIGH 8.8
CVE-2026-21537
Improper control of generation of code ('code injection') in Microsoft Defender for Linux allows an unauthorized attacker to execute code over an adj…
Defender For Endpoint
Mitigation only
HIGH 8.8
CVE-2026-21256
Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an unauthorized attack…
Visual Studio 2022
17.14.26+
CRITICAL 10.0
CVE-2025-65037
Improper control of generation of code ('code injection') in Azure Container Apps allows an unauthorized attacker to execute code over a network.
Azure Container Apps
Mitigation only
HIGH 7.2
CVE-2025-64676
'.../...//' in Microsoft Purview allows an authorized attacker to execute code over a network.
Purview
No fix yet
HIGH 7.6
CVE-2025-59251
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Edge Chromium
140.0.3485.81+
HIGH 8.8
CVE-2025-49704 KEVEPSS 100%
Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Sharepoint Server
Mitigation only
HIGH 7.5
CVE-2025-47988
Improper control of generation of code ('code injection') in Azure Monitor Agent allows an unauthorized attacker to execute code over an adjacent net…
Azure Monitor Agent
1.35.1+
MEDIUM 6.5
CVE-2025-29806
No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Edge Chromium
129.0.2792.52+
HIGH 8.8
CVE-2025-29807
Deserialization of untrusted data in Microsoft Dataverse allows an authorized attacker to execute code over a network.
Dataverse
Mitigation only
HIGH 8.8
CVE-2025-21292
Windows Search Service Elevation of Privilege Vulnerability
Windows 10 1809
10.0.17763.6775 / 10.0.19044.5371+
HIGH 7.8
CVE-2025-21187
Microsoft Power Automate Remote Code Execution Vulnerability
Power Automate For Desktop
2.46.184.25013 / 2.47.126.25010+
HIGH 8.1
CVE-2024-49048
TorchGeo Remote Code Execution Vulnerability
Torchgeo
0.6.1+
HIGH 8.8
CVE-2024-43469
Azure CycleCloud Remote Code Execution Vulnerability
Azure Cyclecloud
8.6.4+
MEDIUM 5.0
CVE-2024-29991
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
Edge Chromium
124.0.2478.51+
HIGH 8.8
CVE-2024-21378EPSS 11%
Microsoft Outlook Remote Code Execution Vulnerability
365 Apps
Patch available
HIGH 7.6
CVE-2024-21351 KEVEPSS 30%
Windows SmartScreen Security Feature Bypass Vulnerability
Windows 10 1507
10.0.10240.20469 / 10.0.14393.6709+
HIGH 8.1
CVE-2024-25110EPSS 7%
The UAMQP is a general purpose C library for AMQP 1.0. During a call to open_get_offered_capabilities, a memory allocation may fail causing a use-aft…
Azure Uamqp
2024-02-01+