VYPR

Power Bi Report Server

by Microsoft

CVEs (10)

  • CVE-2023-21806HigFeb 14, 2023
    risk 0.53cvss 8.2epss 0.01

    Power BI Report Server Spoofing Vulnerability

  • CVE-2026-21229HigFeb 10, 2026
    risk 0.52cvss 8.0epss 0.01

    Improper input validation in Power BI allows an authorized attacker to execute code over a network.

  • CVE-2021-31984HigJul 14, 2021
    risk 0.50cvss 7.6epss 0.02

    Power BI Remote Code Execution Vulnerability

  • CVE-2021-26859HigMar 11, 2021
    risk 0.50cvss 7.7epss 0.03

    Microsoft Power BI Information Disclosure Vulnerability

  • CVE-2021-41372HigNov 10, 2021
    risk 0.49cvss 7.6epss 0.01

    A Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) vulnerability exists when Power BI Report Server Template file (pbix) containing HTML files is uploaded to the server and HTML files are accessed directly by the victim. Combining these 2 vulnerabilities…

  • CVE-2024-43612MedOct 8, 2024
    risk 0.45cvss 6.9epss 0.01

    Power BI Report Server Spoofing Vulnerability

  • CVE-2020-1173MedMay 21, 2020
    risk 0.44cvss 6.8epss 0.02

    A spoofing vulnerability exists in Microsoft Power BI Report Server in the way it validates the content-type of uploaded attachments, aka 'Microsoft Power BI Report Server Spoofing Vulnerability'.

  • CVE-2024-43481MedOct 8, 2024
    risk 0.42cvss 6.5epss 0.02

    Power BI Report Server Spoofing Vulnerability

  • CVE-2019-1332MedDec 10, 2019
    risk 0.40cvss 6.1epss 0.07

    A cross-site scripting (XSS) vulnerability exists when Microsoft SQL Server Reporting Services (SSRS) does not properly sanitize a specially-crafted web request to an affected SSRS server, aka 'Microsoft SQL Server Reporting Services XSS Vulnerability'.

  • CVE-2026-58647HigJul 14, 2026
    risk 0.00cvss 8.0epss 0.00

    Improper neutralization of input during web page generation ('cross-site scripting') in Power BI allows an authorized attacker to perform spoofing over a network.