Dynamics Nav
by Microsoft
CVEs (11)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-41127 | Hig | 0.55 | 8.5 | 0.02 | Dec 13, 2022 | Microsoft Dynamics NAV and Microsoft Dynamics 365 Business Central (On Premises) Remote Code Execution Vulnerability | ||
| CVE-2020-1022 | Hig | 0.53 | 8.0 | 0.07 | Apr 15, 2020 | A remote code execution vulnerability exists in Microsoft Dynamics Business Central, aka 'Dynamics Business Central Remote Code Execution Vulnerability'. | ||
| CVE-2020-0905 | Hig | 0.53 | 8.0 | 0.11 | Mar 12, 2020 | An remote code execution vulnerability exists in Microsoft Dynamics Business Central, aka 'Dynamics Business Central Remote Code Execution Vulnerability'. | ||
| CVE-2020-1018 | Hig | 0.49 | 7.5 | 0.06 | Apr 15, 2020 | An information disclosure vulnerability exists when Microsoft Dynamics Business Central/NAV on-premise does not properly hide the value of a masked field when showing the records as a chart page.The attacker who successfully exploited the vulnerability could see the information… | ||
| CVE-2020-17133 | Med | 0.43 | 6.5 | 0.03 | Dec 10, 2020 | Microsoft Dynamics Business Central/NAV Information Disclosure Vulnerability | ||
| CVE-2021-1724 | Med | 0.40 | 6.1 | 0.01 | Feb 25, 2021 | Microsoft Dynamics Business Central Cross-site Scripting Vulnerability | ||
| CVE-2021-36946 | Med | 0.35 | 5.4 | 0.01 | Aug 12, 2021 | Microsoft Dynamics Business Central Cross-site Scripting Vulnerability | ||
| CVE-2018-8651 | Med | 0.35 | 5.4 | 0.01 | Dec 12, 2018 | A cross site scripting vulnerability exists when Microsoft Dynamics NAV does not properly sanitize a specially crafted web request to an affected Dynamics NAV server, aka "Microsoft Dynamics NAV Cross Site Scripting Vulnerability." This affects Microsoft Dynamics NAV. | ||
| CVE-2022-41066 | Med | 0.29 | 4.4 | 0.01 | Nov 9, 2022 | Microsoft Dynamics Business Central Information Disclosure Vulnerability | ||
| CVE-2019-19616 | Med | 0.28 | 4.3 | 0.01 | Dec 6, 2019 | An Insecure Direct Object Reference (IDOR) vulnerability in the Xtivia Web Time and Expense (WebTE) interface used for Microsoft Dynamics NAV before 2017 allows an attacker to download arbitrary files by specifying arbitrary values for the recId and filename parameters of the… | ||
| CVE-2026-55944 | Cri | 0.00 | 9.8 | 0.02 | Jul 14, 2026 | Deserialization of untrusted data in Microsoft Dynamics NAV allows an unauthorized attacker to execute code over a network. |
- risk 0.55cvss 8.5epss 0.02
Microsoft Dynamics NAV and Microsoft Dynamics 365 Business Central (On Premises) Remote Code Execution Vulnerability
- risk 0.53cvss 8.0epss 0.07
A remote code execution vulnerability exists in Microsoft Dynamics Business Central, aka 'Dynamics Business Central Remote Code Execution Vulnerability'.
- risk 0.53cvss 8.0epss 0.11
An remote code execution vulnerability exists in Microsoft Dynamics Business Central, aka 'Dynamics Business Central Remote Code Execution Vulnerability'.
- risk 0.49cvss 7.5epss 0.06
An information disclosure vulnerability exists when Microsoft Dynamics Business Central/NAV on-premise does not properly hide the value of a masked field when showing the records as a chart page.The attacker who successfully exploited the vulnerability could see the information…
- risk 0.43cvss 6.5epss 0.03
Microsoft Dynamics Business Central/NAV Information Disclosure Vulnerability
- risk 0.40cvss 6.1epss 0.01
Microsoft Dynamics Business Central Cross-site Scripting Vulnerability
- risk 0.35cvss 5.4epss 0.01
Microsoft Dynamics Business Central Cross-site Scripting Vulnerability
- risk 0.35cvss 5.4epss 0.01
A cross site scripting vulnerability exists when Microsoft Dynamics NAV does not properly sanitize a specially crafted web request to an affected Dynamics NAV server, aka "Microsoft Dynamics NAV Cross Site Scripting Vulnerability." This affects Microsoft Dynamics NAV.
- risk 0.29cvss 4.4epss 0.01
Microsoft Dynamics Business Central Information Disclosure Vulnerability
- risk 0.28cvss 4.3epss 0.01
An Insecure Direct Object Reference (IDOR) vulnerability in the Xtivia Web Time and Expense (WebTE) interface used for Microsoft Dynamics NAV before 2017 allows an attacker to download arbitrary files by specifying arbitrary values for the recId and filename parameters of the…
- risk 0.00cvss 9.8epss 0.02
Deserialization of untrusted data in Microsoft Dynamics NAV allows an unauthorized attacker to execute code over a network.