Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.3
CVE-2025-55247
Improper link resolution before file access ('link following') in .NET allows an authorized attacker to elevate privileges locally.
.net
8.0.21 / 9.0.10+
MEDIUM 5.7
CVE-2025-55248
Inadequate encryption strength in .NET, .NET Framework, Visual Studio allows an authorized attacker to disclose information over a network.
.net Framework
8.0.21 / 9.0.10+
HIGH 7.8
CVE-2025-50175
Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.
Windows 10 1809
10.0.17763.7919 / 10.0.19044.6456+
HIGH 7.8
CVE-2025-53150
Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally.
Windows 10 1809
10.0.17763.7919 / 10.0.19044.6456+
HIGH 7.8
CVE-2025-53768
Use after free in Xbox allows an authorized attacker to elevate privileges locally.
Windows 10 1507
10.0.10240.21161 / 10.0.14393.8519+
HIGH 7.1
CVE-2025-53139
Cleartext transmission of sensitive information in Windows Hello allows an unauthorized attacker to bypass a security feature locally.
Windows 10 21h2
10.0.19044.6456 / 10.0.19045.6456+
HIGH 7.0
CVE-2025-50174
Use after free in Windows Device Association Broker service allows an authorized attacker to elevate privileges locally.
Windows 11 24h2
10.0.26100.6899 / 10.0.26200.6899+
HIGH 7.0
CVE-2025-53717
Reliance on untrusted inputs in a security decision in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate p…
Windows 11 22h2
10.0.22621.6060 / 10.0.26100.6899+
CRITICAL 9.9
CVE-2025-49708
Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges over a network.
Windows 10 1809
10.0.17763.7919 / 10.0.19044.6456+
HIGH 7.8
CVE-2025-50152
Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.
Windows 10 1507
10.0.10240.21161 / 10.0.14393.8519+
HIGH 7.0
CVE-2025-47989
Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.
Azure Connected Machine Agent
1.57+
HIGH 7.0
CVE-2025-48004
Use after free in Microsoft Brokering File System allows an unauthorized attacker to elevate privileges locally.
Windows 11 22h2
10.0.22621.6060 / 10.0.25398.1913+
MEDIUM 5.5
CVE-2025-47979
Insertion of sensitive information into log file in Windows Failover Cluster allows an authorized attacker to disclose information locally.
Windows Server 2022 23h2
10.0.25398.1913+
HIGH 7.8
CVE-2025-24990 KEVEPSS 6%
Microsoft is aware of vulnerabilities in the third party Agere Modem driver that ships natively with supported Windows operating systems. This is an…
Windows 10 1507
10.0.10240.21161 / 10.0.14393.8519+
HIGH 7.3
CVE-2025-25004
Improper access control in Microsoft PowerShell allows an authorized attacker to elevate privileges locally.
Powershell
7.4.13 / 7.5.4+
HIGH 7.8
CVE-2025-24052
Microsoft is aware of vulnerabilities in the third party Agere Modem driver that ships natively with supported Windows operating systems. This is an…
Windows 10 1507
10.0.10240.21161 / 10.0.14393.8519+
CRITICAL 9.3
CVE-2025-59286
Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to disclose informatio…
365 Copilot Chat
Mitigation only
CRITICAL 9.8
CVE-2025-59246EPSS 7%
Azure Entra ID Elevation of Privilege Vulnerability
Entra Id
No fix yet
CRITICAL 9.8
CVE-2025-59247
Azure PlayFab Elevation of Privilege Vulnerability
Azure Playfab
No fix yet
CRITICAL 9.6
CVE-2025-59218
Azure Entra ID Elevation of Privilege Vulnerability
Entra Id
No fix yet
CRITICAL 9.3
CVE-2025-59252
Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to disclose informatio…
365 Word Copilot
Mitigation only
CRITICAL 9.3
CVE-2025-59272
Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to perform information…
365 Copilot Chat
Mitigation only
HIGH 8.7
CVE-2025-59271
Redis Enterprise Elevation of Privilege Vulnerability
Azure Cache For Redis
No fix yet
CRITICAL 9.3
CVE-2025-55321
Improper neutralization of input during web page generation ('cross-site scripting') in Azure Monitor allows an unauthorized attacker to perform spoo…
Azure Monitor
Mitigation only
HIGH 7.6
CVE-2025-59251
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Edge Chromium
140.0.3485.81+
HIGH 7.3
CVE-2025-55322
Binding to an unrestricted ip address in GitHub allows an unauthorized attacker to execute code over a network.
Omniparser
2.0.1+
HIGH 7.0
CVE-2025-59220
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bluetooth Service allows an authorized attacke…
Windows 10 21h2
10.0.19044.6332 / 10.0.19045.6332+
HIGH 7.0
CVE-2025-59215
Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
Windows 11 24h2
10.0.26100.6508+
HIGH 7.0
CVE-2025-59216
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized atta…
Windows 11 24h2
10.0.26100.6508+
CRITICAL 9.8
CVE-2025-55319
Ai command injection in Agentic AI and Visual Studio Code allows an unauthorized attacker to execute code over a network.
Visual Studio Code
1.104.0+