Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2025-49712EPSS 18%
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Sharepoint Server
Mitigation only
MEDIUM 6.8
CVE-2025-49751
Missing synchronization in Windows Hyper-V allows an authorized attacker to deny service over an adjacent network.
Windows 10 1607
10.0.14393.8330 / 10.0.17763.7678+
MEDIUM 6.7
CVE-2025-49743
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized atta…
Windows 10 1507
10.0.10240.21100 / 10.0.14393.8330+
MEDIUM 5.4
CVE-2025-49745
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Dynamics 365 (on-premises) allows an unauthorized a…
Dynamics 365
9.1.38.10+
MEDIUM 5.5
CVE-2025-49707
Improper access control in Azure Virtual Machines allows an authorized attacker to perform spoofing locally.
Ecesv6 Series Azure Vm Firmware
No fix yet
HIGH 8.8
CVE-2025-47954
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privilege…
Sql Server 2022
16.0.1145.1 / 16.0.4210.1+
HIGH 7.5
CVE-2025-33051
Exposure of sensitive information to an unauthorized actor in Microsoft Exchange Server allows an unauthorized attacker to disclose information over …
Exchange Server
15.02.2562.020+
MEDIUM 6.7
CVE-2025-48807
Improper restriction of communication channel to intended endpoints in Windows Hyper-V allows an authorized attacker to execute code locally.
Windows 10 1607
10.0.14393.8246 / 10.0.17763.7558+
HIGH 8.8
CVE-2025-24999
Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.
Sql Server 2016
13.0.6465.1 / 13.0.7060.1+
MEDIUM 6.5
CVE-2025-25005
Improper input validation in Microsoft Exchange Server allows an authorized attacker to perform tampering over a network.
Exchange Server
15.02.2562.020+
MEDIUM 5.3
CVE-2025-25006
Improper handling of additional special element in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
Exchange Server
15.02.2562.020+
MEDIUM 5.3
CVE-2025-25007
Improper validation of syntactic correctness of input in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
Exchange Server
15.02.2562.020+
CRITICAL 10.0
CVE-2025-53767
Azure OpenAI Elevation of Privilege Vulnerability
Azure Openai
No fix yet
CRITICAL 9.1
CVE-2025-53792
Azure Portal Elevation of Privilege Vulnerability
Azure Portal
No fix yet
HIGH 7.5
CVE-2025-53774
Microsoft 365 Copilot BizChat Information Disclosure Vulnerability
365 Copilot Chat
No fix yet
HIGH 7.5
CVE-2025-53787
Microsoft 365 Copilot BizChat Information Disclosure Vulnerability
365 Copilot Chat
No fix yet
HIGH 8.0
CVE-2025-53786EPSS 7%
On April 18th 2025, Microsoft announced Exchange Server Security Changes for Hybrid Deployments and accompanying non-security Hot Fix. Microsoft made…
Exchange Server
15.02.2562.017+
MEDIUM 6.5
CVE-2025-53771EPSS 100%
Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
Sharepoint Server
16.0.18526.20508+
CRITICAL 9.8
CVE-2025-53770 KEVEPSS 100%
Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network.
Microsof…
Sharepoint Server
16.0.18526.20508+
CRITICAL 9.9
CVE-2025-53762
Permissive list of allowed inputs in Microsoft Purview allows an authorized attacker to elevate privileges over a network.
Purview
No fix yet
HIGH 8.8
CVE-2025-49746
Improper authorization in Azure Machine Learning allows an authorized attacker to elevate privileges over a network.
Azure Machine Learning
Mitigation only
HIGH 8.8
CVE-2025-49747
Missing authorization in Azure Machine Learning allows an authorized attacker to elevate privileges over a network.
Azure Machine Learning
Mitigation only
HIGH 8.8
CVE-2025-47995
Weak authentication in Azure Machine Learning allows an authorized attacker to elevate privileges over a network.
Azure Machine Learning
Mitigation only
CRITICAL 9.0
CVE-2025-47158
Authentication bypass by assumed-immutable data in Azure DevOps allows an unauthorized attacker to elevate privileges over a network.
Azure Devops
Mitigation only
MEDIUM 6.5
CVE-2025-47963
No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
Edge Chromium
138.0.3351.55+
MEDIUM 5.6
CVE-2025-47182
Improper input validation in Microsoft Edge (Chromium-based) allows an authorized attacker to bypass a security feature locally.
Edge Chromium
138.0.3351.55+
HIGH 8.8
CVE-2025-49740
Protection mechanism failure in Windows SmartScreen allows an unauthorized attacker to bypass a security feature over a network.
Windows 10 1507
10.0.10240.21073 / 10.0.14393.8246+
HIGH 8.8
CVE-2025-49753
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
Windows Server 2008
10.0.14393.8246 / 10.0.17763.7558+
HIGH 7.8
CVE-2025-49742
Integer overflow or wraparound in Microsoft Graphics Component allows an authorized attacker to execute code locally.
Windows 10 1507
10.0.10240.21073 / 10.0.14393.8246+
HIGH 7.0
CVE-2025-49744
Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
Windows 10 1507
10.0.10240.21073 / 10.0.14393.8246+