Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.5
CVE-2026-57975
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over…
Edge Chromium
150.0.4078.48+
HIGH 7.5
CVE-2026-57984
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Edge Chromium
150.0.4078.48+
HIGH 7.5
CVE-2026-57986
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Edge Chromium
150.0.4078.48+
HIGH 7.1
CVE-2026-57977
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attack…
Edge Chromium
150.0.4078.48+
MEDIUM 6.5
CVE-2026-57987
Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
Edge Chromium
150.0.4078.48+
HIGH 8.8
CVE-2026-56645
Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Edge Chromium
150.0.4078.48+
HIGH 8.8
CVE-2026-57974
Integer overflow or wraparound in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Edge Chromium
150.0.4078.48+
MEDIUM 6.5
CVE-2026-45489
Microsoft Edge (Chromium-based) Spoofing Vulnerability
Edge Chromium
150.0.4078.48+
MEDIUM 6.5
CVE-2026-56646
Exposure of sensitive information to an unauthorized actor in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing ove…
Edge Chromium
150.0.4078.48+
MEDIUM 5.9
CVE-2026-45488
User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing …
Edge Chromium
150.0.4078.48+
HIGH 8.8
CVE-2026-45499
Server-side request forgery (ssrf) in Azure OpenAI allows an authorized attacker to elevate privileges over a network.
Azure Openai
Mitigation only
HIGH 8.8
CVE-2026-54998
Incorrect authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network.
Exchange Online
No fix yet
HIGH 8.8
CVE-2026-57100
Server-side request forgery (ssrf) in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a ne…
Entra Provisioning Service
Mitigation only
CRITICAL 9.3
CVE-2026-41106
Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.
365 Copilot
Mitigation only
CRITICAL 9.8
CVE-2026-26145
Improper access control in Azure Synapse allows an authorized attacker to elevate privileges over a network.
Azure Synapse
No fix yet
HIGH 8.3
CVE-2026-50521
Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.
Edge Chromium
149.0.4022.67+
HIGH 7.5
CVE-2025-66389
GitHub Copilot 1.372.0 allows filesystem access outside of a workspace folder (without user approval) via a file-handler URI parameter to fetch_webpa…
Github Copilot
No fix yet
HIGH 7.5
CVE-2026-50519
Initialization of a resource with an insecure default in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose informatio…
Github Copilot Chat
Mitigation only
HIGH 8.8
CVE-2026-48584
Execution with unnecessary privileges in Azure Synapse allows an authorized attacker to elevate privileges over a network.
Azure Synapse
No fix yet
CRITICAL 9.6
CVE-2026-48582
Missing authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network.
Exchange Online
Mitigation only
HIGH 8.8
CVE-2026-47645
Url redirection to untrusted site ('open redirect') in Microsoft 365 Copilot's Business Chat allows an unauthorized attacker to elevate privileges ov…
365 Copilot
Mitigation only
CRITICAL 10.0
CVE-2026-45480
Improper authentication in Azure Active Directory allows an unauthorized attacker to elevate privileges over a network.
Azure Active Directory
No fix yet
HIGH 7.5
CVE-2026-42895
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform t…
365 Copilot
Mitigation only
MEDIUM 5.4
CVE-2026-32208
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Entra ID allows an authorized attacker to perform s…
Edge Chromium
Mitigation only
CRITICAL 9.1
CVE-2025-62821
Microsoft HEIF Image Extensions 1.2.22.0 has an out-of-bounds read because CHEIFItemInfoEntry_GetDataSize can return success while leaving the report…
Heif Image Extension
No fix yet
HIGH 7.5
CVE-2026-54130
Missing authentication for critical function in M365 Copilot allows an unauthorized attacker to disclose information over a network.
365 Copilot
Mitigation only
CRITICAL 9.9
CVE-2026-47647
Improper access control in Microsoft Dynamics 365 allows an authorized attacker to elevate privileges over a network.
Dynamics 365
Mitigation only
HIGH 7.5
CVE-2026-47633
Exposure of sensitive information to an unauthorized actor in Cost Management Interactive Experiences allows an unauthorized attacker to disclose inf…
Cost Management
No fix yet
HIGH 8.8
CVE-2026-32174
Improper authentication in Azure Bot Service allows an authorized attacker to elevate privileges over a network.
Azure Ai Bot Service
Mitigation only
HIGH 7.0
CVE-2026-50656EPSS 11%
Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "RogueP…
Malware Protection Engine
No fix yet