Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.8
CVE-2025-24050
Heap-based buffer overflow in Role: Windows Hyper-V allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.7876 / 10.0.17763.7009+
MEDIUM 5.4
CVE-2025-24054 KEVEPSS 59%
External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.
Windows 10 1507
10.0.10240.20947 / 10.0.14393.7876+
HIGH 8.4
CVE-2025-24049
Improper neutralization of special elements used in a command ('command injection') in Azure Command Line Integration (CLI) allows an unauthorized at…
Azure Command Line Interface
2.69.0+
HIGH 8.1
CVE-2025-24045
Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.
Windows Server 2012
10.0.14393.7876 / 10.0.17763.7009+
HIGH 7.8
CVE-2025-24044
Use after free in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally.
Windows 10 1507
10.0.10240.20947 / 10.0.14393.7876+
HIGH 7.8
CVE-2025-24046
Use after free in Microsoft Streaming Service allows an authorized attacker to elevate privileges locally.
Windows 10 1507
10.0.10240.20947 / 10.0.14393.7876+
HIGH 7.8
CVE-2025-24048
Heap-based buffer overflow in Role: Windows Hyper-V allows an authorized attacker to elevate privileges locally.
Windows 10 1607
10.0.14393.7876 / 10.0.17763.7009+
HIGH 8.1
CVE-2025-24035
Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.
Windows 10 1507
10.0.10240.20947 / 10.0.14393.7876+
HIGH 7.5
CVE-2025-24043
Improper verification of cryptographic signature in .NET allows an authorized attacker to execute code over a network.
Windbg
1.2502.25002.0+
MEDIUM 6.7
CVE-2025-21199
Improper privilege management in Azure Agent Installer allows an authorized attacker to elevate privileges locally.
Azure Agent
2.0.9940.0 / 9.30+
HIGH 7.8
CVE-2025-21180
Heap-based buffer overflow in Windows exFAT File System allows an unauthorized attacker to execute code locally.
Windows 10 1507
10.0.10240.20947 / 10.0.14393.7876+
MEDIUM 5.4
CVE-2025-26643
The UI performs the wrong action in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
Edge Chromium
134.0.3124.51+
CRITICAL 9.8
CVE-2025-24989 KEV
An improper access control vulnerability in Power Pages allows an unauthorized attacker to elevate privileges over a network potentially bypassing th…
Power Pages
Patch available
CRITICAL 9.8
CVE-2025-21355
Missing Authentication for Critical Function in Microsoft Bing allows an unauthorized attacker to execute code over a network
Bing
Patch available
HIGH 7.3
CVE-2025-24042
Visual Studio Code JS Debug Extension Elevation of Privilege Vulnerability
Visual Studio Code
1.97.1+
HIGH 7.8
CVE-2025-21418 KEV
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
Windows 10 1607
10.0.10240.20915 / 10.0.17763.6893+
HIGH 7.8
CVE-2025-21420
Windows Disk Cleanup Tool Elevation of Privilege Vulnerability
Windows 10 1507
10.0.10240.20915 / 10.0.14393.7785+
HIGH 7.3
CVE-2025-24039
Visual Studio Code Elevation of Privilege Vulnerability
Visual Studio Code
1.97.1+
HIGH 7.1
CVE-2025-21419
Windows Setup Files Cleanup Elevation of Privilege Vulnerability
Windows 10 1507
10.0.10240.20915 / 10.0.14393.7785+
HIGH 7.0
CVE-2025-24036
Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability
Autoupdate
4.77.24121924+
HIGH 8.8
CVE-2025-21407
Windows Telephony Service Remote Code Execution Vulnerability
Windows 10 1507
10.0.10240.20915 / 10.0.14393.7785+
HIGH 8.8
CVE-2025-21410
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Windows Server 2008
10.0.14393.7785 / 10.0.17763.6893+
HIGH 7.0
CVE-2025-21414
Windows Core Messaging Elevation of Privileges Vulnerability
Windows 10 1507
10.0.10240.20915 / 10.0.14393.7785+
HIGH 8.8
CVE-2025-21406
Windows Telephony Service Remote Code Execution Vulnerability
Windows 10 1507
10.0.10240.20915 / 10.0.14393.7785+
HIGH 8.0
CVE-2025-21400EPSS 34%
Microsoft SharePoint Server Remote Code Execution Vulnerability
Sharepoint Server
16.0.17928.20396+
HIGH 7.8
CVE-2025-21394
Microsoft Excel Remote Code Execution Vulnerability
365 Apps
16.0.10416.20058+
HIGH 7.8
CVE-2025-21397
Microsoft Office Remote Code Execution Vulnerability
365 Apps
Patch available
HIGH 7.8
CVE-2025-21386
Microsoft Excel Remote Code Execution Vulnerability
365 Apps
16.0.10416.20058+
HIGH 7.8
CVE-2025-21387
Microsoft Excel Remote Code Execution Vulnerability
365 Apps
16.0.10416.20058+
HIGH 7.8
CVE-2025-21390
Microsoft Excel Remote Code Execution Vulnerability
365 Apps
16.0.10416.20058+