Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.0
CVE-2026-68820 KEV
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.9418 / 10.0.17763.9115+
CRITICAL 9.1
CVE-2026-55040 KEV
Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.
Sharepoint Server
16.0.19725.20434+
CRITICAL 9.8
CVE-2026-58644 KEVEPSS 45%
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
Sharepoint Server
16.0.19725.20434+
CRITICAL 9.8
CVE-2026-56164 KEVEPSS 22%
Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.
Sharepoint Server
16.0.19725.20434+
HIGH 7.8
CVE-2026-56155 KEV
Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locall…
Windows 10 1607
10.0.14393.9339 / 10.0.17763.9020+
CRITICAL 9.8
CVE-2026-50522 KEVEPSS 77%
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
Sharepoint Server
16.0.19725.20434+
HIGH 8.8
CVE-2026-45659 KEVEPSS 10%
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Sharepoint Server
16.0.19725.20280+
HIGH 7.5
CVE-2026-45498 KEVEPSS 63%
Microsoft Defender Denial of Service Vulnerability
Defender Antimalware Platform
4.18.26040.7+
HIGH 7.8
CVE-2026-41091 KEVEPSS 10%
Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally.
Malware Protection Engine
1.1.26040.8+
MEDIUM 6.1
CVE-2026-42897 KEVEPSS 70%
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to …
Exchange Server
15.02.2562.043+
HIGH 7.8
CVE-2026-33825 KEVEPSS 7%
Insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges locally.
Defender Antimalware Platform
4.18.26030.3011+
CRITICAL 9.8
CVE-2026-33824 KEVEPSS 56%
Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.
Windows 10 1607
10.0.14393.9060 / 10.0.17763.8644+
MEDIUM 6.5
CVE-2026-32201 KEVEPSS 23%
Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
Sharepoint Server
16.0.19725.20210+
HIGH 7.8
CVE-2026-21533 KEV
Improper privilege management in Windows Remote Desktop allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.8868 / 10.0.17763.8389+
HIGH 7.8
CVE-2026-21519 KEV
Access of resource using incompatible type ('type confusion') in Desktop Window Manager allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.8868 / 10.0.17763.8389+
MEDIUM 6.2
CVE-2026-21525 KEV
Null pointer dereference in Windows Remote Access Connection Manager allows an unauthorized attacker to deny service locally.
Windows 10 1607
10.0.14393.8868 / 10.0.17763.8389+
HIGH 8.8
CVE-2026-21510 KEVEPSS 26%
Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network.
Windows 10 1607
10.0.14393.8868 / 10.0.17763.8389+
HIGH 8.8
CVE-2026-21513 KEVEPSS 15%
Protection mechanism failure in MSHTML Framework allows an unauthorized attacker to bypass a security feature over a network.
Windows 10 1607
10.0.14393.8868 / 10.0.17763.8389+
HIGH 7.8
CVE-2026-21514 KEV
Reliance on untrusted inputs in a security decision in Microsoft Office Word allows an unauthorized attacker to bypass a security feature locally.
365 Apps
Mitigation only
HIGH 7.8
CVE-2026-21509 KEVEPSS 72%
Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.
365 Apps
Mitigation only
CRITICAL 9.8
CVE-2026-20963 KEVEPSS 32%
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
Sharepoint Server
16.0.19127.20442+
MEDIUM 5.5
CVE-2026-20805 KEVEPSS 5%
Exposure of sensitive information to an unauthorized actor in Desktop Windows Manager allows an authorized attacker to disclose information locally.
Windows 10 1607
10.0.14393.8783 / 10.0.17763.8276+
HIGH 7.8
CVE-2025-62221 KEV
Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.
Windows 10 1809
10.0.17763.8146 / 10.0.19044.6691+
HIGH 7.0
CVE-2025-62215 KEVEPSS 6%
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevat…
Windows 10 1809
10.0.17763.8027 / 10.0.19044.6575+
HIGH 7.8
CVE-2025-60710 KEV
Improper link resolution before file access ('link following') in Host Process for Windows Tasks allows an authorized attacker to elevate privileges …
Windows 11 24h2
10.0.26100.7392 / 10.0.26200.7392+
CRITICAL 9.8
CVE-2025-59287 KEVEPSS 100%
Deserialization of untrusted data in Windows Server Update Service allows an unauthorized attacker to execute code over a network.
Windows Server 2012
10.0.14393.8524 / 10.0.17763.7922+
HIGH 7.8
CVE-2025-59230 KEV
Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.
Windows 10 1507
10.0.10240.21161 / 10.0.14393.8519+
HIGH 7.8
CVE-2025-24990 KEVEPSS 6%
Microsoft is aware of vulnerabilities in the third party Agere Modem driver that ships natively with supported Windows operating systems. This is an…
Windows 10 1507
10.0.10240.21161 / 10.0.14393.8519+
CRITICAL 9.8
CVE-2025-53770 KEVEPSS 100%
Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network.
Microsof…
Sharepoint Server
16.0.18526.20508+
MEDIUM 6.5
CVE-2025-49706 KEVEPSS 100%
Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
Sharepoint Enterprise Server
16.0.18526.20424+