Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.8
CVE-2025-47175
Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
365 Apps
Mitigation only
HIGH 7.8
CVE-2025-47174
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
365 Apps
Mitigation only
HIGH 7.8
CVE-2025-47173
Improper input validation in Microsoft Office allows an unauthorized attacker to execute code locally.
365 Apps
Mitigation only
MEDIUM 6.7
CVE-2025-47171
Improper input validation in Microsoft Office Outlook allows an authorized attacker to execute code locally.
365 Apps
Mitigation only
HIGH 7.8
CVE-2025-47170
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
365 Apps
Mitigation only
HIGH 7.8
CVE-2025-47169
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
365 Apps
Mitigation only
HIGH 7.8
CVE-2025-47168
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
365 Apps
Mitigation only
HIGH 8.4
CVE-2025-47164
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
365 Apps
No fix yet
HIGH 8.4
CVE-2025-47162
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
365 Apps
No fix yet
CRITICAL 9.8
CVE-2025-47966
Exposure of sensitive information to an unauthorized actor in Power Automate allows an unauthorized attacker to elevate privileges over a network.
Power Automate For Desktop
No fix yet
HIGH 7.8
CVE-2025-32704
Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
365 Apps
Mitigation only
HIGH 7.8
CVE-2025-32705
Out-of-bounds read in Microsoft Office Outlook allows an unauthorized attacker to execute code locally.
365 Apps
Mitigation only
HIGH 7.8
CVE-2025-30393
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
365 Apps
Mitigation only
CRITICAL 9.8
CVE-2025-30387
Improper limitation of a pathname to a restricted directory ('path traversal') in Azure allows an unauthorized attacker to elevate privileges over a …
Azure Ai Document Intelligence Studio
Mitigation only
HIGH 7.8
CVE-2025-29978
Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
365 Apps
Mitigation only
HIGH 7.0
CVE-2025-29973
Improper access control in Azure File Sync allows an authorized attacker to elevate privileges locally.
Azure File Sync
Mitigation only
MEDIUM 6.5
CVE-2025-26685
Improper authentication in Microsoft Defender for Identity allows an unauthorized attacker to perform spoofing over an adjacent network.
Defender For Identity
Mitigation only
HIGH 7.5
CVE-2025-47733
Server-Side Request Forgery (SSRF) in Microsoft Power Apps allows an unauthorized attacker to disclose information over a network
Power Apps
Mitigation only
CRITICAL 9.8
CVE-2025-29813
Authentication bypass by assumed-immutable data in Azure DevOps allows an unauthorized attacker to elevate privileges over a network.
Azure Devops
Mitigation only
CRITICAL 9.8
CVE-2025-29972
Server-side request forgery (ssrf) in Azure Storage Resource Provider allows an authorized attacker to perform spoofing over a network.
Azure Storage Resource Provider
Mitigation only
CRITICAL 9.8
CVE-2025-47732
Deserialization of untrusted data in Microsoft Dataverse allows an authorized attacker to execute code over a network.
Dataverse
Mitigation only
HIGH 8.8
CVE-2025-29827
Improper authorization in Azure Automation allows an authorized attacker to elevate privileges over a network.
Azure Automation
Mitigation only
HIGH 7.5
CVE-2025-33072
Improper access control in Azure allows an unauthorized attacker to disclose information over a network.
Msagsfeedback.azurewebsites.net
Mitigation only
HIGH 8.8
CVE-2025-33074
Improper verification of cryptographic signature in Microsoft Azure Functions allows an authorized attacker to execute code over a network.
Azure Functions
Mitigation only
CRITICAL 9.8
CVE-2025-30389
Improper authorization in Azure Bot Framework SDK allows an unauthorized attacker to elevate privileges over a network.
Azure Ai Bot Service
Mitigation only
CRITICAL 9.8
CVE-2025-30392
Improper authorization in Azure Bot Framework SDK allows an unauthorized attacker to elevate privileges over a network.
Azure Ai Bot Service
Mitigation only
HIGH 8.8
CVE-2025-30390
Improper authorization in Azure allows an authorized attacker to elevate privileges over a network.
Azure Machine Learning
No fix yet
HIGH 7.5
CVE-2025-30391
Improper input validation in Microsoft Dynamics allows an unauthorized attacker to disclose information over a network.
Dynamics 365 Customer Service
Mitigation only
HIGH 8.8
CVE-2025-21416
Missing authorization in Azure Virtual Desktop allows an authorized attacker to elevate privileges over a network.
Azure Virtual Desktop
Mitigation only
HIGH 7.8
CVE-2025-29822
Incomplete list of disallowed inputs in Microsoft Office OneNote allows an unauthorized attacker to bypass a security feature locally.
Office
Mitigation only