| | CVE-2025-47964 | Microsoft | medium | 5.4 | 0.0%
| | Microsoft Edge (Chromium-based) Spoofing Vulnerability | Jul 11, 2025 | Feb 13, 2026 |
| | CVE-2025-47963 | Microsoft | medium | 6.3 | 0.1%
| | No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform … | Jul 11, 2025 | Feb 13, 2026 |
| | CVE-2025-49756 | Microsoft | low | 3.3 | 0.0%
| | Use of a broken or risky cryptographic algorithm in Office Developer Platform allows an authorized a… | Jul 8, 2025 | Feb 13, 2026 |
| | CVE-2025-49737 | Microsoft | high | 7.0 | 0.0%
| | Concurrent execution using shared resource with improper synchronization ('race condition') in Micro… | Jul 8, 2025 | Feb 13, 2026 |
| | CVE-2025-49731 | Microsoft | low | 3.1 | 0.1%
| | Improper handling of insufficient permissions or privileges in Microsoft Teams allows an authorized … | Jul 8, 2025 | Feb 13, 2026 |
| | CVE-2025-49706 | Microsoft | medium | 6.5 | 99.9%
| ⚠ KEV | Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform sp… | Jul 8, 2025 | Aug 4, 2026 |
| | CVE-2025-43019 | HPE | high | 7.8 | 0.0%
| | A potential security vulnerability has been identified in the HP Support Assistant, which allows a l… | Jul 8, 2025 | Jan 20, 2026 |
| | CVE-2024-55599 | Fortinet | medium | 4.9 | 0.3%
| | An Improperly Implemented Security Check for Standard vulnerability [CWE-358] in FortiOS version 7.6… | Jul 8, 2025 | Aug 11, 2026 |
| | CVE-2025-43025 | HPE | high | 7.5 | 0.1%
| | HP Universal Print Driver is potentially vulnerable to denial of service due to buffer overflow in v… | Jul 2, 2025 | Jan 20, 2026 |
| | CVE-2025-32897 | Apache | critical | 9.8 | 0.3%
| | Deserialization of Untrusted Data vulnerability in Apache Seata (incubating).
This security vulnera… | Jun 28, 2025 | Mar 30, 2026 |
| | CVE-2025-3773 | Trellix | medium | 5.5 | 0.0%
| | A sensitive information exposure vulnerability in System Information Reporter (SIR) 1.0.3 and prior… | Jun 26, 2025 | Feb 11, 2026 |
| | CVE-2025-3771 | Trellix | high | 7.1 | 0.0%
| | A path or symbolic link manipulation vulnerability in SIR 1.0.3 and prior versions allows an authent… | Jun 26, 2025 | Feb 11, 2026 |
| | CVE-2025-3722 | Trellix | medium | 4.4 | 0.0%
| | A path traversal vulnerability in System Information Reporter (SIR) 1.0.3 and prior allowed an auth… | Jun 26, 2025 | Feb 11, 2026 |
| | CVE-2025-24286 | Veeam | high | 7.2 | — | | A vulnerability allowing an authenticated user with the Backup Operator role to modify backup jobs, … | Jun 19, 2025 | Jul 16, 2025 |
| | CVE-2025-23121 | Veeam | high | 8.8 | — | | A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain… | Jun 19, 2025 | Jul 15, 2025 |
| | CVE-2025-32711 | Microsoft | critical | 9.3 | 3.4%
| | Ai command injection in M365 Copilot allows an unauthorized attacker to disclose information over a … | Jun 11, 2025 | Feb 20, 2026 |
| | CVE-2025-47176 | Microsoft | high | 7.8 | 0.5%
| | '.../...//' in Microsoft Office Outlook allows an authorized attacker to execute code locally. | Jun 10, 2025 | Feb 13, 2026 |
| | CVE-2025-31104 | Fortinet | high | 7.2 | 1.2%
| | A improper neutralization of special elements used in an os command ('os command injection') vulnera… | Jun 10, 2025 | Aug 31, 2026 |
| | CVE-2025-22254 | Fortinet | medium | 6.6 | 0.1%
| | An Improper Privilege Management vulnerability [CWE-269] vulnerability in Fortinet FortiOS 7.6.0 thr… | Jun 10, 2025 | Jan 14, 2026 |
| | CVE-2025-25250 | Fortinet | low | 3.9 | 0.5%
| | An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability … | Jun 10, 2025 | Aug 11, 2026 |
| | CVE-2025-24471 | Fortinet | medium | 6.0 | 0.3%
| | An Improper Certificate Validation vulnerability [CWE-295] in FortiOS version 7.6.1 and below, versi… | Jun 10, 2025 | Aug 11, 2026 |
| | CVE-2024-50562 | Fortinet | medium | 4.4 | 1.1%
| | An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL-VPN version 7.6.0, version… | Jun 10, 2025 | Aug 11, 2026 |
| | CVE-2025-43026 | HPE | high | 7.8 | 0.0%
| | A potential security vulnerability has been identified in the HP Support Assistant for versions prio… | Jun 5, 2025 | Jan 13, 2026 |
| | CVE-2025-48734 | Apache | medium | — | 0.3%
| | Improper Access Control vulnerability in Apache Commons.
A special BeanIntrospector class was add… | May 28, 2025 | Apr 29, 2026 |
| | CVE-2025-24473 | Fortinet | low | 3.7 | 0.1%
| | A exposure of sensitive system information to an unauthorized control sphere vulnerability in Fortin… | May 28, 2025 | Jan 8, 2026 |
| | CVE-2025-4123 | Grafana | high | 7.6 | 3.9%
| | A cross-site scripting (XSS) vulnerability exists in Grafana caused by combining a client path trave… | May 22, 2025 | Apr 29, 2026 |
| | CVE-2025-32756 | Fortinet | critical | 9.8 | 41.6%
| ⚠ KEV | A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 th… | May 13, 2025 | Jan 14, 2026 |
| | CVE-2024-35281 | Fortinet | low | 2.5 | 0.1%
| | An improper isolation or compartmentalization vulnerability [CWE-653] in FortiClientMac version 7.4.… | May 13, 2025 | Feb 5, 2026 |
| | CVE-2025-47732 | Microsoft | high | 8.7 | 2.7%
| | Deserialization of untrusted data in Microsoft Dataverse allows an authorized attacker to execute co… | May 8, 2025 | Feb 13, 2026 |
| | CVE-2025-29972 | Microsoft | critical | 9.9 | 4.5%
| | Server-side request forgery (ssrf) in Azure Storage Resource Provider allows an authorized attacker … | May 8, 2025 | Feb 13, 2026 |
| | CVE-2025-29813 | Microsoft | critical | 10.0 | 1.9%
| | Authentication bypass by assumed-immutable data in Azure DevOps allows an unauthorized attacker to e… | May 8, 2025 | Feb 13, 2026 |
| | CVE-2025-20182 | Cisco | high | 8.6 | 0.5%
| | A vulnerability in the Internet Key Exchange version 2 (IKEv2) protocol processing of Cisco Adaptive… | May 7, 2025 | Aug 11, 2026 |
| | CVE-2025-3891 | Apache | high | 7.5 | 1.2%
| | A flaw was found in the mod_auth_openidc module for Apache httpd. This flaw allows a remote, unauthe… | Apr 29, 2025 | Jun 29, 2026 |
| | CVE-2025-1697 | HPE | high | 7.8 | 0.1%
| | A potential security vulnerability has been identified in the HP Touchpoint Analytics Service for ce… | Apr 18, 2025 | Feb 24, 2026 |
| | CVE-2025-27391 | Apache | medium | 6.5 | 0.3%
| | Insertion of Sensitive Information into Log File vulnerability in Apache ActiveMQ Artemis. All the v… | Apr 9, 2025 | Jun 15, 2026 |
| | CVE-2025-29821 | Microsoft | medium | 5.5 | 0.6%
| | Improper input validation in Dynamics Business Central allows an authorized attacker to disclose inf… | Apr 8, 2025 | Aug 10, 2026 |
| | CVE-2025-26628 | Microsoft | high | 7.3 | 0.8%
| | Insufficiently protected credentials in Azure Local Cluster allows an authorized attacker to disclos… | Apr 8, 2025 | Jan 16, 2026 |
| | CVE-2025-25002 | Microsoft | medium | 6.8 | 1.8%
| | Insertion of sensitive information into log file in Azure Local Cluster allows an authorized attacke… | Apr 8, 2025 | Jan 16, 2026 |
| | CVE-2023-37930 | Fortinet | high | 7.5 | 0.6%
| | Multiple issues including the use of uninitialized ressources [CWE-908] and excessive iteration [CWE… | Apr 8, 2025 | Jan 14, 2026 |
| | CVE-2024-32122 | Fortinet | low | 2.1 | 0.2%
| | A storing passwords in a recoverable format in Fortinet FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all… | Apr 8, 2025 | Aug 11, 2026 |
| | CVE-2025-27427 | Apache | medium | 4.3 | 0.5%
| | A vulnerability exists in Apache ActiveMQ Artemis whereby a user with the createDurableQueue or crea… | Apr 1, 2025 | Jun 15, 2026 |
| | CVE-2025-23120 | Veeam | high | 8.8 | — | | A vulnerability allowing remote code execution (RCE) for domain users. | Mar 20, 2025 | Apr 2, 2025 |
| | CVE-2024-47552 | Apache | critical | 9.8 | 0.2%
| | Deserialization of Untrusted Data vulnerability in Apache Seata (incubating).
This issue affect… | Mar 20, 2025 | Mar 30, 2026 |
| | CVE-2025-2240 | Apache | high | 7.5 | 0.9%
| | A flaw was found in Smallrye, where smallrye-fault-tolerance is vulnerable to an out-of-memory (OOM)… | Mar 12, 2025 | Aug 4, 2026 |
| | CVE-2025-26627 | Microsoft | high | 7.0 | 0.1%
| | Improper neutralization of special elements used in a command ('command injection') in Azure Arc all… | Mar 11, 2025 | Jan 20, 2026 |
| | CVE-2025-26633 | Microsoft | high | 7.0 | 31.9%
| ⚠ KEV | Improper neutralization in Microsoft Management Console allows an unauthorized attacker to bypass a … | Mar 11, 2025 | Aug 5, 2026 |
| | CVE-2024-54026 | Fortinet | medium | 4.3 | 0.1%
| | An improper neutralization of special elements used in an sql command ('sql injection') in Fortinet … | Mar 11, 2025 | Jan 14, 2026 |
| | CVE-2024-52961 | Fortinet | high | 8.8 | 0.2%
| | An improper neutralization of special elements used in an OS Command vulnerability [CWE-78] vulnerab… | Mar 11, 2025 | Jan 14, 2026 |
| | CVE-2025-22225 | VMware | high | 8.2 | 1.0%
| ⚠ KEV | VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the … | Mar 4, 2025 | Aug 4, 2026 |
| | CVE-2025-26466 | Fortinet | medium | 5.9 | 38.5%
| | A flaw was found in the OpenSSH package. For each ping packet the SSH server receives, a pong packet… | Feb 28, 2025 | Jun 30, 2026 |