Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2025-33074
Improper verification of cryptographic signature in Microsoft Azure Functions allows an authorized attacker to execute code over a network.
Azure Functions
Mitigation only
CRITICAL 9.8
CVE-2025-30389
Improper authorization in Azure Bot Framework SDK allows an unauthorized attacker to elevate privileges over a network.
Azure Ai Bot Service
Mitigation only
CRITICAL 9.8
CVE-2025-30392
Improper authorization in Azure Bot Framework SDK allows an unauthorized attacker to elevate privileges over a network.
Azure Ai Bot Service
Mitigation only
HIGH 8.8
CVE-2025-30390
Improper authorization in Azure allows an authorized attacker to elevate privileges over a network.
Azure Machine Learning
No fix yet
HIGH 7.5
CVE-2025-30391
Improper input validation in Microsoft Dynamics allows an unauthorized attacker to disclose information over a network.
Dynamics 365 Customer Service
Mitigation only
HIGH 8.8
CVE-2025-21416
Missing authorization in Azure Virtual Desktop allows an authorized attacker to elevate privileges over a network.
Azure Virtual Desktop
Mitigation only
MEDIUM 5.7
CVE-2025-29817
Uncontrolled search path element in Power Automate allows an authorized attacker to disclose information over a network.
Power Automate For Desktop
2.51.349.24355+
HIGH 7.5
CVE-2025-29834
Out-of-bounds read in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
Edge Chromium
134.0.3124.93+
MEDIUM 6.8
CVE-2025-32726
Improper access control in Visual Studio Code allows an authorized attacker to elevate privileges locally.
Visual Studio Code
1.99.1+
HIGH 7.3
CVE-2025-29803
Uncontrolled search path element in Visual Studio Tools for Applications and SQL Server Management Studio allows an authorized attacker to elevate pr…
Sql Server Management Studio
16.0.35907.0 / 17.0.35906.0+
HIGH 7.8
CVE-2025-29822
Incomplete list of disallowed inputs in Microsoft Office OneNote allows an unauthorized attacker to bypass a security feature locally.
Office
Mitigation only
HIGH 7.8
CVE-2025-29823
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
365 Apps
Mitigation only
HIGH 7.8
CVE-2025-29824 KEVEPSS 14%
Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
Windows 10 1507
10.0.10240.20978 / 10.0.14393.7969+
HIGH 7.8
CVE-2025-29812
Untrusted pointer dereference in Windows Kernel Memory allows an authorized attacker to elevate privileges locally.
Windows 11 22h2
10.0.20348.3453 / 10.0.22621.5189+
HIGH 7.8
CVE-2025-29820
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
365 Apps
Mitigation only
HIGH 7.5
CVE-2025-29816
Improper input validation in Microsoft Office Word allows an unauthorized attacker to bypass a security feature over a network.
365 Apps
No fix yet
MEDIUM 6.2
CVE-2025-29819
External control of file name or path in Azure Portal Windows Admin Center allows an unauthorized attacker to disclose information locally.
Windows Admin Center
0.45.0.0 / 2410+
MEDIUM 5.5
CVE-2025-29821
Improper input validation in Dynamics Business Central allows an authorized attacker to disclose information locally.
Dynamics 365 Business Central 2023
23.18.32409 / 24.12.32447+
HIGH 7.8
CVE-2025-29811
Improper input validation in Windows Mobile Broadband allows an authorized attacker to elevate privileges locally.
Windows 11 22h2
10.0.22621.5189 / 10.0.22631.5189+
HIGH 7.5
CVE-2025-29805
Exposure of sensitive information to an unauthorized actor in Outlook for Android allows an unauthorized attacker to disclose information over a netw…
Outlook
4.2509.0+
HIGH 7.5
CVE-2025-29810
Improper access control in Active Directory Domain Services allows an authorized attacker to elevate privileges over a network.
Windows 10 1507
10.0.10240.20978 / 10.0.14393.7969+
HIGH 7.3
CVE-2025-29802
Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally.
Visual Studio 2022
17.8.20 / 17.10.13+
HIGH 7.3
CVE-2025-29804
Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally.
Visual Studio 2022
17.8.20 / 17.10.13+
HIGH 7.1
CVE-2025-29809
Insecure storage of sensitive information in Windows Kerberos allows an authorized attacker to bypass a security feature locally.
Windows 10 1507
10.0.10240.20978 / 10.0.14393.7969+
MEDIUM 5.5
CVE-2025-29808
Use of a cryptographic primitive with a risky implementation in Windows Cryptographic Services allows an authorized attacker to disclose information …
Windows Server 2022
10.0.20348.3453+
HIGH 8.8
CVE-2025-29794
Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Sharepoint Enterprise Server
16.0.18526.20172+
HIGH 7.8
CVE-2025-29791
Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.
365 Apps
Mitigation only
HIGH 7.8
CVE-2025-29800
Improper privilege management in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges locally.
Autoupdate
4.78+
HIGH 7.8
CVE-2025-29801
Incorrect default permissions in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges locally.
Autoupdate
4.78+
HIGH 7.3
CVE-2025-29792
Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.
365 Apps
Mitigation only