Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.0
CVE-2026-26149
Improper neutralization of escape, meta, or control sequences in Microsoft Power Apps allows an authorized attacker to perform spoofing over a networ…
Power Apps
3.26032.10.0+
HIGH 7.8
CVE-2026-26143
Improper input validation in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally.
Powershell
7.4.14 / 7.5.5+
HIGH 7.1
CVE-2026-26151
Insufficient ui warning of dangerous operations in Windows Remote Desktop allows an unauthorized attacker to perform spoofing over a network.
Windows 10 1607
10.0.14393.9060 / 10.0.17763.8644+
HIGH 7.0
CVE-2026-25184
Concurrent execution using shared resource with improper synchronization ('race condition') in Applocker Filter Driver (applockerfltr.sys) allows an …
Windows 11 23h2
10.0.22631.6936 / 10.0.25398.2274+
HIGH 7.8
CVE-2026-23657
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
365 Apps
Mitigation only
HIGH 7.5
CVE-2026-23666
Improper input validation in .NET Framework allows an unauthorized attacker to deny service over a network.
.net Framework
Mitigation only
MEDIUM 6.5
CVE-2026-23653
Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an authorized att…
Github Copilot Chat
0.37.3+
MEDIUM 5.7
CVE-2026-23670
Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a security feature local…
Windows 10 1607
10.0.14393.9060 / 10.0.17763.8644+
HIGH 7.8
CVE-2026-20930
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attac…
Windows 10 1809
10.0.17763.8644 / 10.0.19044.7184+
MEDIUM 5.4
CVE-2026-20945EPSS 25%
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to …
Sharepoint Server
16.0.19725.20210+
MEDIUM 6.7
CVE-2026-0390
Reliance on untrusted inputs in a security decision in Windows Boot Loader allows an authorized attacker to bypass a security feature locally.
Windows 10 1607
10.0.14393.9060 / 10.0.17763.8644+
MEDIUM 5.5
CVE-2026-20806
Access of resource using incompatible type ('type confusion') in Windows COM allows an authorized attacker to disclose information locally.
Windows 10 1809
10.0.17763.8644 / 10.0.19044.7184+
MEDIUM 5.4
CVE-2026-33119
User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing …
Edge
147.0.3912.60+
MEDIUM 6.1
CVE-2026-35199
SymCrypt is the core cryptographic function library currently used by Windows. From 103.5.0 to before 103.11.0, The SymCryptXmssSign function passes …
Symcrypt
103.11.0+
CRITICAL 9.8
CVE-2026-32186
Server-side request forgery (ssrf) in Microsoft Bing allows an unauthorized attacker to elevate privileges over a network.
Bing
No fix yet
CRITICAL 9.8
CVE-2026-33105
Improper authorization in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.
Azure Kubernetes Service
Mitigation only
CRITICAL 9.8
CVE-2026-33107
Server-side request forgery (ssrf) in Azure Databricks allows an unauthorized attacker to elevate privileges over a network.
Azure Databricks
Mitigation only
CRITICAL 9.8
CVE-2026-32213
Improper authorization in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.
Azure Ai Foundry
Mitigation only
HIGH 8.8
CVE-2026-26135
Server-side request forgery (ssrf) in Azure Custom Locations Resource Provider (RP) allows an authorized attacker to elevate privileges over a networ…
Azure Custom Locations Resource Provider
Mitigation only
HIGH 7.5
CVE-2026-32173
Improper authentication in Azure SRE Agent allows an unauthorized attacker to disclose information over a network.
Azure Sre Agent
Mitigation only
HIGH 7.5
CVE-2026-32211
Missing authentication for critical function in Azure MCP Server allows an unauthorized attacker to disclose information over a network.
Azure Web Apps
Mitigation only
MEDIUM 6.5
CVE-2026-34401
XML Notepad is a Windows program that provides a simple intuitive User Interface for browsing and editing XML documents. Prior to version 2.9.0.21, X…
Xml Notepad
2.9.0.21+
CRITICAL 9.8
CVE-2026-32194
Improper neutralization of special elements used in a command ('command injection') in Microsoft Bing Images allows an unauthorized attacker to execu…
Bing Images
No fix yet
CRITICAL 9.8
CVE-2026-32169
Server-side request forgery (ssrf) in Azure Cloud Shell allows an unauthorized attacker to elevate privileges over a network.
Azure Cloud Shell
Mitigation only
CRITICAL 9.8
CVE-2026-32191
Improper neutralization of special elements used in an os command ('os command injection') in Microsoft Bing Images allows an unauthorized attacker t…
Bing Images
Mitigation only
CRITICAL 10.0
CVE-2026-26138
Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network.
Purview
Mitigation only
CRITICAL 9.9
CVE-2026-26137
Server-side request forgery (ssrf) in Microsoft Exchange allows an authorized attacker to elevate privileges over a network.
365 Copilot Chat
No fix yet
HIGH 8.6
CVE-2026-26139
Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network.
Purview
No fix yet
HIGH 7.5
CVE-2026-26136
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose …
Copilot
Mitigation only
HIGH 7.5
CVE-2026-26120
Server-side request forgery (ssrf) in Microsoft Bing allows an unauthorized attacker to perform tampering over a network.
Bing
No fix yet