Vulnerabilities (CVE)

Filtered by vendor Microsoft Subscribe
Filtered by product Dynamics 365
Total 99 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-33103 1 Microsoft 1 Dynamics 365 2026-07-24 N/A 5.5 MEDIUM
Improper access control in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to disclose information locally.
CVE-2026-40371 1 Microsoft 1 Dynamics 365 2026-07-23 N/A 8.8 HIGH
Improper handling of insufficient permissions or privileges in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to elevate privileges over a network.
CVE-2024-35263 1 Microsoft 1 Dynamics 365 2026-07-20 N/A 5.7 MEDIUM
Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability
CVE-2026-47647 1 Microsoft 1 Dynamics 365 2026-06-25 N/A 9.9 CRITICAL
Improper access control in Microsoft Dynamics 365 allows an authorized attacker to elevate privileges over a network.
CVE-2026-42898 1 Microsoft 1 Dynamics 365 2026-06-17 N/A 9.9 CRITICAL
Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network.
CVE-2026-42833 1 Microsoft 1 Dynamics 365 2026-06-17 N/A 9.1 CRITICAL
Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network.
CVE-2026-32210 1 Microsoft 1 Dynamics 365 2026-06-17 N/A 9.3 CRITICAL
Server-side request forgery (ssrf) in Microsoft Dynamics 365 (Online) allows an unauthorized attacker to perform spoofing over a network.
CVE-2025-62211 1 Microsoft 1 Dynamics 365 2026-06-17 N/A 8.7 HIGH
Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Field Service (online) allows an authorized attacker to perform spoofing over a network.
CVE-2025-62210 1 Microsoft 1 Dynamics 365 2026-06-17 N/A 8.7 HIGH
Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Field Service (online) allows an authorized attacker to perform spoofing over a network.
CVE-2025-62206 1 Microsoft 1 Dynamics 365 2026-06-17 N/A 6.5 MEDIUM
Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an unauthorized attacker to disclose information over a network.
CVE-2025-55238 1 Microsoft 1 Dynamics 365 2026-06-17 N/A 7.5 HIGH
Dynamics 365 FastTrack Implementation Assets Information Disclosure Vulnerability
CVE-2025-53728 1 Microsoft 1 Dynamics 365 2026-06-17 N/A 6.5 MEDIUM
Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an unauthorized attacker to disclose information over a network.
CVE-2025-49745 1 Microsoft 1 Dynamics 365 2026-06-17 N/A 5.4 MEDIUM
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Dynamics 365 (on-premises) allows an unauthorized attacker to perform spoofing over a network.
CVE-2025-49715 1 Microsoft 1 Dynamics 365 2026-06-17 N/A 7.5 HIGH
Exposure of private personal information to an unauthorized actor in Dynamics 365 FastTrack Implementation Assets allows an unauthorized attacker to disclose information over a network.
CVE-2024-43476 1 Microsoft 1 Dynamics 365 2026-06-17 N/A 7.6 HIGH
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
CVE-2024-38211 1 Microsoft 1 Dynamics 365 2026-06-17 N/A 8.2 HIGH
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
CVE-2024-38182 1 Microsoft 1 Dynamics 365 2026-06-17 N/A 9.0 CRITICAL
Weak authentication in Microsoft Dynamics 365 allows an unauthenticated attacker to elevate privileges over a network.
CVE-2024-30061 1 Microsoft 1 Dynamics 365 2026-06-17 N/A 7.3 HIGH
Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability
CVE-2024-21419 1 Microsoft 1 Dynamics 365 2026-06-17 N/A 7.6 HIGH
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
CVE-2024-21396 1 Microsoft 1 Dynamics 365 2026-06-17 N/A 7.6 HIGH
Dynamics 365 Sales Spoofing Vulnerability