Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2026-24307
Improper validation of specified type of input in M365 Copilot allows an unauthorized attacker to disclose information over a network.
365 Copilot
Mitigation only
CRITICAL 9.8
CVE-2026-24305
Azure Entra ID Elevation of Privilege Vulnerability
Entra Id
No fix yet
CRITICAL 9.8
CVE-2026-24306
Improper access control in Azure Front Door (AFD) allows an unauthorized attacker to elevate privileges over a network.
Azure Front Door
No fix yet
CRITICAL 9.8
CVE-2026-21227
Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privile…
Azure Logic Apps
Mitigation only
HIGH 7.5
CVE-2026-21520
Exposure of Sensitive Information to an Unauthorized Actor in Copilot Studio allows a unauthenticated attacker to view sensitive information through …
Copilot Studio
Mitigation only
HIGH 7.4
CVE-2026-21521
Improper neutralization of escape, meta, or control sequences in Copilot allows an unauthorized attacker to disclose information over a network.
365 Word Copilot
Mitigation only
HIGH 7.4
CVE-2026-21524
Exposure of sensitive information to an unauthorized actor in Azure Data Explorer allows an unauthorized attacker to disclose information over a netw…
Azure Data Explorer
No fix yet
MEDIUM 6.1
CVE-2026-21264
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Account allows an unauthorized attacker to perform …
Account
Mitigation only
HIGH 8.0
CVE-2026-20960
Improper authorization in Microsoft Power Apps allows an authorized attacker to execute code over a network.
Power Apps
3.25121+
HIGH 7.1
CVE-2026-21223
Improper privilege management in Microsoft Edge (Chromium-based) allows an authorized attacker to bypass a security feature locally.
Edge Chromium
144.0.3719.82+
HIGH 7.5
CVE-2026-21226
Deserialization of untrusted data in Azure Core shared client library for Python allows an authorized attacker to execute code over a network.
Azure Core Shared Client Library
1.38.0+
MEDIUM 6.4
CVE-2026-21265
Windows Secure Boot stores Microsoft certificates in the UEFI KEK and DB. These original certificates are approaching expiration, and devices contain…
Windows 10 1607
10.0.14393.8783 / 10.0.17763.8276+
CRITICAL 9.8
CVE-2026-20963 KEVEPSS 32%
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
Sharepoint Server
16.0.19127.20442+
HIGH 7.8
CVE-2026-21224
Stack-based buffer overflow in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.
Azure Connected Machine Agent
1.60+
HIGH 7.5
CVE-2026-20965
Improper verification of cryptographic signature in Windows Admin Center allows an authorized attacker to elevate privileges locally.
Windows Admin Center
0.70.0.0+
HIGH 7.0
CVE-2026-21219
Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.
Windows Software Development Kit
10.0.26100.7463+
HIGH 7.0
CVE-2026-21221
Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows a…
Windows 11 24h2
10.0.26100.7623 / 10.0.26100.32230+
HIGH 8.4
CVE-2026-20953
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
365 Apps
No fix yet
HIGH 7.8
CVE-2026-20955
Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
365 Apps
16.0.10417.20083+
HIGH 7.8
CVE-2026-20956
Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
365 Apps
Mitigation only
HIGH 7.8
CVE-2026-20957
Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
365 Apps
16.0.10417.20083+
MEDIUM 5.4
CVE-2026-20958
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.
Sharepoint Server
16.0.19127.20442+
MEDIUM 5.4
CVE-2026-20959EPSS 7%
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to …
Sharepoint Server
16.0.19127.20442+
HIGH 8.8
CVE-2026-20947EPSS 19%
Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to …
Sharepoint Server
16.0.19127.20442+
HIGH 8.4
CVE-2026-20952
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
365 Apps
No fix yet
HIGH 7.8
CVE-2026-20946
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
365 Apps
Mitigation only
HIGH 7.8
CVE-2026-20948
Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.
365 Apps
Mitigation only
HIGH 7.8
CVE-2026-20949
Improper access control in Microsoft Office Excel allows an unauthorized attacker to bypass a security feature locally.
365 Apps
No fix yet
HIGH 7.8
CVE-2026-20950
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
365 Apps
16.0.10417.20083+
HIGH 7.8
CVE-2026-20951
Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally.
Sharepoint Server
16.0.19127.20442+