Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 9.8
CVE-2026-23652
Improper neutralization of special elements used in a command ('command injection') in Microsoft Power Pages allows an unauthorized attacker to execu…
Power Pages
Mitigation only
HIGH 7.7
CVE-2026-26147
Improper input validation in Azure Compute Gallery allows an authorized attacker to disclose information over a network.
Azure Stack Hci
Mitigation only
HIGH 7.5
CVE-2026-23663
Improper privilege management in Azure Entra ID allows an unauthorized attacker to elevate privileges over a network.
Global Secure Access
No fix yet
MEDIUM 6.8
CVE-2026-45585
Microsoft is aware of a security feature bypass vulnerability in Windows publicly referred to as "YellowKey". The proof of concept for this…
Windows 11 24h2
No fix yet
CRITICAL 9.9
CVE-2026-42823
Improper access control in Azure Logic Apps allows an authorized attacker to elevate privileges over a network.
Azure Logic Apps
Mitigation only
HIGH 8.8
CVE-2026-40420
Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.
365 Apps
Mitigation only
HIGH 7.8
CVE-2026-40419
Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.
365 Apps
Mitigation only
HIGH 7.8
CVE-2026-40417
Weak authentication in Dynamics Business Central allows an authorized attacker to elevate privileges locally.
Dynamics 365 Business Central
Mitigation only
HIGH 7.8
CVE-2026-40418
Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.
365 Apps
Mitigation only
HIGH 7.5
CVE-2026-40379
Exposure of sensitive information to an unauthorized actor in Azure Entra ID allows an unauthorized attacker to perform spoofing over a network.
Entra Id
No fix yet
HIGH 8.4
CVE-2026-40364
Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally.
365 Apps
Mitigation only
HIGH 8.4
CVE-2026-40366
Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally.
365 Apps
Mitigation only
HIGH 8.4
CVE-2026-40358
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
365 Apps
No fix yet
HIGH 8.4
CVE-2026-40361
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
365 Apps
No fix yet
MEDIUM 5.5
CVE-2026-35440
Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
365 Apps
No fix yet
HIGH 8.8
CVE-2026-35436
Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.
365 Apps
Mitigation only
HIGH 8.2
CVE-2026-33833
Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Machine Learning allows an unauthorized a…
Azure Machine Learning
Mitigation only
CRITICAL 9.9
CVE-2026-33821
Improper privilege management in Microsoft Dynamics 365 Customer Insights allows an authorized attacker to elevate privileges over a network.
Dynamics 365 Customer Insights
Mitigation only
HIGH 8.1
CVE-2026-41105
Server-side request forgery (ssrf) in Azure Notification Service allows an authorized attacker to elevate privileges over a network.
Azure Monitor Action Group Notification System
Mitigation only
HIGH 7.5
CVE-2026-42826
Exposure of sensitive information to an unauthorized actor in Azure DevOps allows an unauthorized attacker to disclose information over a network.
Azure Devops
No fix yet
CRITICAL 10.0
CVE-2026-35435
Improper access control in Azure AI Foundry M365 published agents allows an unauthorized attacker to elevate privileges over a network.
Azure Ai Foundry
Mitigation only
CRITICAL 9.9
CVE-2026-33109
Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network.
Azure Managed Instance For Apache Cassandra
Mitigation only
CRITICAL 9.6
CVE-2026-35428
Improper neutralization of special elements used in a command ('command injection') in Azure Cloud Shell allows an unauthorized attacker to perform s…
Azure Cloud Shell
Mitigation only
CRITICAL 9.0
CVE-2026-33844
Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network.
Azure Managed Instance For Apache Cassandra
Mitigation only
HIGH 8.2
CVE-2026-34327
Externally controlled reference to a resource in another sphere in Microsoft Partner Center allows an unauthorized attacker to perform spoofing over …
Partner Center
Mitigation only
HIGH 7.5
CVE-2026-33111
Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker …
Copilot Chat
Mitigation only
MEDIUM 6.5
CVE-2026-33823
Improper authorization in Microsoft Teams allows an authorized attacker to disclose information over a network.
Teams
No fix yet
HIGH 7.5
CVE-2026-26129
Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose infor…
365 Copilot Chat
No fix yet
HIGH 7.5
CVE-2026-26164
Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose infor…
365 Copilot Chat
No fix yet
MEDIUM 6.1
CVE-2026-32207
Improper neutralization of input during web page generation ('cross-site scripting') in Azure Machine Learning allows an unauthorized attacker to per…
Azure Machine Learning
Mitigation only