Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.5
CVE-2025-26636
Processor optimization removal or modification of security-critical code in Windows Kernel allows an authorized attacker to disclose information loca…
Windows 11 24h2
10.0.26100.4652+
HIGH 8.8
CVE-2025-49713
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over…
Edge Chromium
138.0.3351.65+
HIGH 7.5
CVE-2025-49741
No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
Edge Chromium
135.0.3179.98+
HIGH 7.5
CVE-2025-49715
Exposure of private personal information to an unauthorized actor in Dynamics 365 FastTrack Implementation Assets allows an unauthorized attacker to …
Dynamics 365
Mitigation only
HIGH 7.1
CVE-2025-47959EPSS 7%
Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an authorized attacker to execute code ov…
Visual Studio 2022
17.8.22 / 17.10.16+
HIGH 7.5
CVE-2025-30399
Untrusted search path in .NET and Visual Studio allows an unauthorized attacker to execute code over a network.
Visual Studio 2022
7.4.11 / 7.5.2+
HIGH 7.5
CVE-2025-32711EPSS 8%
Ai command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.
365 Copilot
No fix yet
HIGH 8.4
CVE-2025-32717
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
365 Apps
Mitigation only
HIGH 8.2
CVE-2025-47977
Improper neutralization of input during web page generation ('cross-site scripting') in Nuance Digital Engagement Platform allows an unauthorized att…
Nuance Digital Engagement Platform
5.64.x+
HIGH 7.8
CVE-2025-47968
Improper input validation in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges locally.
Autoupdate
4.79+
HIGH 7.8
CVE-2025-47962
Improper access control in Windows SDK allows an authorized attacker to elevate privileges locally.
Windows Software Development Kit
10.0.26100.4188+
HIGH 8.4
CVE-2025-47957
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
365 Apps
Mitigation only
MEDIUM 5.5
CVE-2025-47956
External control of file name or path in Windows Security App allows an authorized attacker to perform spoofing locally.
Windows Security App
1000.27840.0.1000+
HIGH 7.8
CVE-2025-47955
Improper privilege management in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.
Windows 10 1507
10.0.10240.21014 / 10.0.14393.8066+
HIGH 8.4
CVE-2025-47953
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
365 Apps
Mitigation only
HIGH 7.8
CVE-2025-47176
'.../...//' in Microsoft Office Outlook allows an authorized attacker to execute code locally.
365 Apps
No fix yet
HIGH 7.8
CVE-2025-47175
Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
365 Apps
Mitigation only
HIGH 7.8
CVE-2025-47174
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
365 Apps
Mitigation only
HIGH 7.8
CVE-2025-47173
Improper input validation in Microsoft Office allows an unauthorized attacker to execute code locally.
365 Apps
Mitigation only
HIGH 8.8
CVE-2025-47172
Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to …
Sharepoint Enterprise Server
after 16.0.18526.20396
MEDIUM 6.7
CVE-2025-47171
Improper input validation in Microsoft Office Outlook allows an authorized attacker to execute code locally.
365 Apps
Mitigation only
HIGH 7.8
CVE-2025-47170
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
365 Apps
Mitigation only
HIGH 7.8
CVE-2025-47169
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
365 Apps
Mitigation only
HIGH 7.8
CVE-2025-47168
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
365 Apps
Mitigation only
HIGH 8.4
CVE-2025-47167
Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.
365 Apps
16.0.18925.20000+
HIGH 8.8
CVE-2025-47166EPSS 15%
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Sharepoint Enterprise Server
16.0.18526.20396+
HIGH 7.8
CVE-2025-47165
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
365 Apps
16.0.10417.20018+
HIGH 8.4
CVE-2025-47164
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
365 Apps
No fix yet
HIGH 8.8
CVE-2025-47163EPSS 15%
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Sharepoint Enterprise Server
16.0.18526.20396+
HIGH 8.4
CVE-2025-47162
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
365 Apps
No fix yet