Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2025-64656
Out-of-bounds read in Application Gateway allows an unauthorized attacker to elevate privileges over a network.
Azure Application Gateway
Mitigation only
CRITICAL 9.8
CVE-2025-64657
Stack-based buffer overflow in Azure Application Gateway allows an unauthorized attacker to elevate privileges over a network.
Azure Application Gateway
Mitigation only
CRITICAL 9.8
CVE-2025-64655
Improper authorization in Dynamics OmniChannel SDK Storage Containers allows an unauthorized attacker to elevate privileges over a network.
Dynamics Omnichannel Sdk Storage Containers
No fix yet
HIGH 8.0
CVE-2025-64660
Improper access control in GitHub Copilot and Visual Studio Code allows an authorized attacker to execute code over a network.
Visual Studio Code
1.106.2+
MEDIUM 6.1
CVE-2025-62459
Microsoft Defender Portal Spoofing Vulnerability
365 Defender Portal
No fix yet
CRITICAL 9.8
CVE-2025-62207
Azure Monitor Elevation of Privilege Vulnerability
Azure Monitor
No fix yet
CRITICAL 9.8
CVE-2025-59245
Microsoft SharePoint Online Elevation of Privilege Vulnerability
Sharepoint Online
No fix yet
CRITICAL 10.0
CVE-2025-49752
Azure Bastion Elevation of Privilege Vulnerability
Azure Bastion Developer
No fix yet
HIGH 8.0
CVE-2025-62452
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network.
Windows 10 1607
10.0.14393.8594 / 10.0.17763.8027+
MEDIUM 6.8
CVE-2025-62449
Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code CoPilot Chat Extension allows an authorized atta…
Github Copilot Chat
0.32.0+
MEDIUM 5.0
CVE-2025-62453
Improper validation of generative ai output in GitHub Copilot and Visual Studio Code allows an authorized attacker to bypass a security feature local…
Visual Studio Code
1.105.0+
HIGH 8.8
CVE-2025-62220
Heap-based buffer overflow in Windows Subsystem for Linux GUI allows an unauthorized attacker to execute code over a network.
Windows Subsystem For Linux
2.6.2+
HIGH 8.8
CVE-2025-62222
Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code CoPilot Chat Extension allows an unauthoriz…
Github Copilot Chat
0.32.5+
HIGH 7.8
CVE-2025-62216
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
365 Apps
Mitigation only
HIGH 7.0
CVE-2025-62217
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows a…
Windows 10 1607
10.0.14393.8594 / 10.0.17763.8027+
HIGH 7.0
CVE-2025-62218
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Wireless Provisioning System allows an autho…
Windows 10 1607
10.0.14393.8594 / 10.0.17763.8027+
HIGH 7.0
CVE-2025-62219
Double free in Microsoft Wireless Provisioning System allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.8594 / 10.0.17763.8027+
HIGH 8.7
CVE-2025-62210
Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Field Service (online) allows an authorized atta…
Dynamics 365
8.8.139.398+
HIGH 8.7
CVE-2025-62211
Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Field Service (online) allows an authorized atta…
Dynamics 365
8.8.139.398+
HIGH 7.0
CVE-2025-62213
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.8594 / 10.0.17763.8027+
HIGH 7.0
CVE-2025-62215 KEVEPSS 6%
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevat…
Windows 10 1809
10.0.17763.8027 / 10.0.19044.6575+
MEDIUM 6.7
CVE-2025-62214
Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an authorized attacker to execute code lo…
Visual Studio 2022
17.14.17+
MEDIUM 5.5
CVE-2025-62209
Insertion of sensitive information into log file in Windows License Manager allows an authorized attacker to disclose information locally.
Windows 10 1507
10.0.10240.21161 / 10.0.14393.8519+
MEDIUM 6.5
CVE-2025-62206
Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an unauthorized attacker to disclose inform…
Dynamics 365
9.1.41.07+
MEDIUM 5.5
CVE-2025-62208
Insertion of sensitive information into log file in Windows License Manager allows an authorized attacker to disclose information locally.
Windows 10 1507
10.0.10240.21161 / 10.0.14393.8519+
HIGH 7.8
CVE-2025-62205
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
365 Apps
Mitigation only
HIGH 8.0
CVE-2025-62204
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Sharepoint Server
16.0.19127.20338+
HIGH 7.8
CVE-2025-62199
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
365 Apps
16.0.19426.20044+
HIGH 7.8
CVE-2025-62200
Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
365 Apps
16.0.10417.20068+
HIGH 7.8
CVE-2025-62201
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
365 Apps
16.0.10417.20068+