Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2025-21223
Windows Telephony Service Remote Code Execution Vulnerability
Windows 10 1507
10.0.10240.20890 / 10.0.14393.7699+
HIGH 7.5
CVE-2025-21218
Windows Kerberos Denial of Service Vulnerability
Windows Server 2012
10.0.14393.7699 / 10.0.17763.6775+
HIGH 7.5
CVE-2025-21220
Microsoft Message Queuing Information Disclosure Vulnerability
Windows 10 1507
10.0.10240.20890 / 10.0.14393.7699+
MEDIUM 6.5
CVE-2025-21217
Windows NTLM Spoofing Vulnerability
Windows 10 1507
10.0.10240.20890 / 10.0.14393.7699+
HIGH 7.5
CVE-2025-21207
Windows Connected Devices Platform Service (Cdpsvc) Denial of Service Vulnerability
Windows 10 1809
10.0.17763.6775 / 10.0.19044.5371+
MEDIUM 6.8
CVE-2025-21211
Secure Boot Security Feature Bypass Vulnerability
Windows 10 1507
10.0.10240.20890 / 10.0.14393.7699+
HIGH 7.8
CVE-2025-21186
Microsoft Access Remote Code Execution Vulnerability
365 Apps
Patch available
HIGH 7.8
CVE-2025-21187
Microsoft Power Automate Remote Code Execution Vulnerability
Power Automate For Desktop
2.46.184.25013 / 2.47.126.25010+
MEDIUM 6.5
CVE-2025-21193
Active Directory Federation Server Spoofing Vulnerability
Windows Server 2016
10.0.14393.7699 / 10.0.17763.6775+
MEDIUM 6.1
CVE-2025-21202
Windows Recovery Environment Agent Elevation of Privilege Vulnerability
Windows 10 1507
10.0.10240.20890 / 10.0.14393.7699+
HIGH 8.8
CVE-2025-21176
.NET, .NET Framework, and Visual Studio Remote Code Execution Vulnerability
.net
15.9.69+
HIGH 8.8
CVE-2025-21178
Visual Studio Remote Code Execution Vulnerability
Visual Studio 2017
15.9.69 / 16.11.43+
HIGH 7.5
CVE-2025-21171
.NET Remote Code Execution Vulnerability
.net
17.6.22 / 17.8.17+
HIGH 7.5
CVE-2025-21172
.NET and Visual Studio Remote Code Execution Vulnerability
.net
17.6.22 / 17.8.17+
HIGH 7.3
CVE-2025-21173
.NET Elevation of Privilege Vulnerability
Visual Studio 2022
17.6.22 / 17.8.17+
MEDIUM 6.5
CVE-2025-21380
Improper access control in Azure SaaS Resources allows an authorized attacker to disclose information over a network.
Azure Marketplace
No fix yet
MEDIUM 6.5
CVE-2025-21385EPSS 24%
A Server-Side Request Forgery (SSRF) vulnerability in Microsoft Purview allows an authorized attacker to disclose information over a network.
Purview
No fix yet
CRITICAL 9.8
CVE-2024-42004
A library injection vulnerability exists in Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A specially crafted library can leverage…
Teams
No fix yet
CRITICAL 9.1
CVE-2024-41165
A library injection vulnerability exists in Microsoft Word 16.83 for macOS. A specially crafted library can leverage Word's access privileges, leadin…
Word
No fix yet
CRITICAL 9.1
CVE-2024-42220
A library injection vulnerability exists in Microsoft Outlook 16.83.3 for macOS. A specially crafted library can leverage Outlook's access privileges…
Outlook
No fix yet
CRITICAL 9.1
CVE-2024-43106
A library injection vulnerability exists in Microsoft Excel 16.83 for macOS. A specially crafted library can leverage Excel's access privileges, lead…
Excel
No fix yet
HIGH 7.1
CVE-2024-41159
A library injection vulnerability exists in Microsoft OneNote 16.83 for macOS. A specially crafted library can leverage OneNote's access privileges, …
Onenote
No fix yet
CRITICAL 9.8
CVE-2024-41138
A library injection vulnerability exists in the com.microsoft.teams2.modulehost.app helper app of Microsoft Teams (work or school) 24046.2813.2770.10…
Teams
No fix yet
CRITICAL 9.8
CVE-2024-41145
A library injection vulnerability exists in the WebView.app helper app of Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A speciall…
Teams
No fix yet
CRITICAL 9.1
CVE-2024-39804
A library injection vulnerability exists in Microsoft PowerPoint 16.83 for macOS. A specially crafted library can leverage PowerPoint's access privil…
Powerpoint
No fix yet
HIGH 7.5
CVE-2022-40732
An access violation vulnerability exists in the DirectComposition functionality win32kbase.sys driver version 10.0.22000.593 as part of Windows 11 ve…
Windows 11 21h2
No fix yet
MEDIUM 6.5
CVE-2022-40733
An access violation vulnerability exists in the DirectComposition functionality win32kbase.sys driver version 10.0.22000.593 as part of Windows 11 ve…
Windows 11 21h2
No fix yet
CRITICAL 9.8
CVE-2024-49147
Deserialization of untrusted data in Microsoft Update Catalog allows an unauthorized attacker to elevate privileges on the website’s webserver.
Update Catalog
Mitigation only
MEDIUM 6.5
CVE-2024-49071
Improper authorization of an index that contains sensitive information from a Global Files search in Windows Defender allows an authorized attacker t…
Defender For Endpoint
Mitigation only
HIGH 8.1
CVE-2024-49132
Windows Remote Desktop Services Remote Code Execution Vulnerability
Windows 10 1809
10.0.17763.6659 / 10.0.19044.5247+