Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 8.8
CVE-2026-56167
Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privileges over a network.
Azure Ai Search
No fix yet
HIGH 8.8
CVE-2026-54120
Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network.
Surface Management Services
No fix yet
CRITICAL 9.9
CVE-2026-50517
Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.
365 Copilot
No fix yet
MEDIUM 6.5
CVE-2026-49159
Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network.
Graph
No fix yet
HIGH 7.2
CVE-2026-35425
Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code over a network.
Azure Api Management
No fix yet
HIGH 7.5
CVE-2026-59117
Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code over a network.
Terminal
No fix yet
HIGH 8.8
CVE-2026-47301
Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges over a network.
Configuration Manager 2503
Mitigation only
HIGH 8.8
CVE-2026-58277
Improper authorization in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
Sharepoint Server
Mitigation only
HIGH 8.8
CVE-2026-56642
Stack-based buffer overflow in Microsoft Fabric Data Warehouse allows an authorized attacker to execute code over a network.
Fabric Data Warehouse
Mitigation only
MEDIUM 5.5
CVE-2026-56195
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
365 Apps
Mitigation only
HIGH 7.8
CVE-2026-56156
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
365 Apps
Mitigation only
CRITICAL 9.8
CVE-2026-55944
Deserialization of untrusted data in Microsoft Dynamics NAV allows an unauthorized attacker to execute code over a network.
Dynamics Nav
Mitigation only
HIGH 7.1
CVE-2026-55145
Improper neutralization of special elements used in a command ('command injection') in Outlook Copilot allows an authorized attacker to perform tampe…
Copilot
Mitigation only
HIGH 7.8
CVE-2026-55133
Heap-based buffer overflow in Microsoft Office OneNote allows an unauthorized attacker to execute code locally.
365 Apps
Mitigation only
HIGH 7.8
CVE-2026-55140
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
365 Apps
No fix yet
HIGH 7.8
CVE-2026-55129
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
365 Apps
No fix yet
HIGH 7.8
CVE-2026-55120
Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
365 Apps
Mitigation only
HIGH 7.8
CVE-2026-55123
Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
365 Apps
Mitigation only
HIGH 7.8
CVE-2026-55056
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
365 Apps
No fix yet
MEDIUM 5.5
CVE-2026-55057
Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to disclose information locally.
365 Apps
No fix yet
HIGH 7.8
CVE-2026-55049
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
365 Apps
Mitigation only
HIGH 7.8
CVE-2026-55043
Heap-based buffer overflow in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
365 Apps
No fix yet
MEDIUM 5.5
CVE-2026-55042
Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information locally.
365 Apps
Mitigation only
HIGH 7.8
CVE-2026-55017
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
365 Apps
No fix yet
HIGH 7.8
CVE-2026-55018
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
365 Apps
No fix yet
HIGH 7.8
CVE-2026-55022
Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.
365 Apps
Mitigation only
CRITICAL 9.8
CVE-2026-55010
Heap-based buffer overflow in Minecraft Bedrock Dedicated Server allows an unauthorized attacker to execute code over a network.
Minecraft Bedrock Dedicated Server
No fix yet
HIGH 7.8
CVE-2026-50467
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
365 Apps
No fix yet
HIGH 7.8
CVE-2026-50314
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
365 Apps
No fix yet
HIGH 7.8
CVE-2026-50301
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
365 Apps
No fix yet