Skip to main content

Vendor/product archive

microsoft / dynamics_365 CVEs

Beta · best-effort

99 CVEs tagged to microsoft / dynamics_3655 Critical, 42 High, 52 Medium, 0 Low, 0 Unrated.

CVE-2026-47647

Published Jun 18, 2026

Improper access control in Microsoft Dynamics 365 allows an authorized attacker to elevate privileges over a network.

CVSS 9.9 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-40371

Published Jun 9, 2026

Improper handling of insufficient permissions or privileges in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to elevate privileges over a network.

CVSS 8.8 · High
evidence mentions
3
Buzz score
21.9
Vendor/product tagsBeta · best-effort

CVE-2026-42898

Published May 12, 2026

Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network.

CVSS 9.9 · Critical
evidence mentions
4
Buzz score
29.1
Vendor/product tagsBeta · best-effort

CVE-2026-42833

Published May 12, 2026

Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network.

CVSS 9.1 · Critical
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-32210

Published Apr 23, 2026

Server-side request forgery (ssrf) in Microsoft Dynamics 365 (Online) allows an unauthorized attacker to perform spoofing over a network.

CVSS 9.3 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-33103

Published Apr 14, 2026

Improper access control in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to disclose information locally.

CVSS 5.5 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2025-62211

Published Nov 11, 2025

Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Field Service (online) allows an authorized attacker to perform spoofing over…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2025-62210

Published Nov 11, 2025

Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Field Service (online) allows an authorized attacker to perform spoofing over…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2025-62206

Published Nov 11, 2025

Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an unauthorized attacker to disclose information over a network.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-53728

Published Aug 12, 2025

Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an unauthorized attacker to disclose information over a network.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-49745

Published Aug 12, 2025

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Dynamics 365 (on-premises) allows an unauthorized attacker to perform spoofing ov…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-49715

Published Jun 20, 2025

Exposure of private personal information to an unauthorized actor in Dynamics 365 FastTrack Implementation Assets allows an unauthorized attacker to disclose information over a ne…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-38182

Published Jul 31, 2024

Weak authentication in Microsoft Dynamics 365 allows an unauthenticated attacker to elevate privileges over a network.

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-35263

Published Jun 11, 2024

Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability

CVSS 5.7 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1-25 of 99 CVEsPage 1 of 4