Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.5
CVE-2025-47733
Server-Side Request Forgery (SSRF) in Microsoft Power Apps allows an unauthorized attacker to disclose information over a network
Power Apps
Mitigation only
CRITICAL 9.8
CVE-2025-29813
Authentication bypass by assumed-immutable data in Azure DevOps allows an unauthorized attacker to elevate privileges over a network.
Azure Devops
Mitigation only
CRITICAL 9.8
CVE-2025-29972
Server-side request forgery (ssrf) in Azure Storage Resource Provider allows an authorized attacker to perform spoofing over a network.
Azure Storage Resource Provider
Mitigation only
CRITICAL 9.8
CVE-2025-47732
Deserialization of untrusted data in Microsoft Dataverse allows an authorized attacker to execute code over a network.
Dataverse
Mitigation only
HIGH 8.8
CVE-2025-29827
Improper authorization in Azure Automation allows an authorized attacker to elevate privileges over a network.
Azure Automation
Mitigation only
HIGH 7.5
CVE-2025-33072
Improper access control in Azure allows an unauthorized attacker to disclose information over a network.
Msagsfeedback.azurewebsites.net
Mitigation only
HIGH 8.8
CVE-2025-33074
Improper verification of cryptographic signature in Microsoft Azure Functions allows an authorized attacker to execute code over a network.
Azure Functions
Mitigation only
CRITICAL 9.8
CVE-2025-30389
Improper authorization in Azure Bot Framework SDK allows an unauthorized attacker to elevate privileges over a network.
Azure Ai Bot Service
Mitigation only
CRITICAL 9.8
CVE-2025-30392
Improper authorization in Azure Bot Framework SDK allows an unauthorized attacker to elevate privileges over a network.
Azure Ai Bot Service
Mitigation only
HIGH 8.8
CVE-2025-30390
Improper authorization in Azure allows an authorized attacker to elevate privileges over a network.
Azure Machine Learning
No fix yet
HIGH 7.5
CVE-2025-30391
Improper input validation in Microsoft Dynamics allows an unauthorized attacker to disclose information over a network.
Dynamics 365 Customer Service
Mitigation only
HIGH 8.8
CVE-2025-21416
Missing authorization in Azure Virtual Desktop allows an authorized attacker to elevate privileges over a network.
Azure Virtual Desktop
Mitigation only
HIGH 7.8
CVE-2025-29822
Incomplete list of disallowed inputs in Microsoft Office OneNote allows an unauthorized attacker to bypass a security feature locally.
Office
Mitigation only
HIGH 7.8
CVE-2025-29823
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
365 Apps
Mitigation only
HIGH 7.8
CVE-2025-29820
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
365 Apps
Mitigation only
HIGH 7.5
CVE-2025-29816
Improper input validation in Microsoft Office Word allows an unauthorized attacker to bypass a security feature over a network.
365 Apps
No fix yet
HIGH 7.8
CVE-2025-29791
Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.
365 Apps
Mitigation only
HIGH 7.3
CVE-2025-29792
Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.
365 Apps
Mitigation only
HIGH 7.8
CVE-2025-27747
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
365 Apps
Mitigation only
HIGH 7.8
CVE-2025-27748
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
365 Apps
Mitigation only
HIGH 7.8
CVE-2025-27749
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
365 Apps
Mitigation only
HIGH 7.8
CVE-2025-27750
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
365 Apps
Mitigation only
HIGH 7.8
CVE-2025-27751
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
365 Apps
Mitigation only
HIGH 7.8
CVE-2025-27752
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
365 Apps
Mitigation only
HIGH 7.8
CVE-2025-27743
Untrusted search path in System Center allows an authorized attacker to elevate privileges locally.
System Center Data Protection Manager
Mitigation only
HIGH 7.8
CVE-2025-27744
Improper access control in Microsoft Office allows an authorized attacker to elevate privileges locally.
Office
Mitigation only
HIGH 7.8
CVE-2025-27745
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
365 Apps
Mitigation only
HIGH 7.8
CVE-2025-26642
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.
365 Apps
Mitigation only
HIGH 8.8
CVE-2025-21384
An authenticated attacker can exploit an Server-Side Request Forgery (SSRF) vulnerability in Microsoft Azure Health Bot to elevate privileges over a …
Azure Health Bot
Mitigation only
CRITICAL 9.8
CVE-2025-26683
Improper authorization in Azure Playwright allows an unauthorized attacker to elevate privileges over a network.
Azure Playwright
Mitigation only