Power Bi Report Server
by Microsoft
CVEs (10)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-21806 | Hig | 0.53 | 8.2 | 0.01 | Feb 14, 2023 | Power BI Report Server Spoofing Vulnerability | ||
| CVE-2026-21229 | Hig | 0.52 | 8.0 | 0.01 | Feb 10, 2026 | Improper input validation in Power BI allows an authorized attacker to execute code over a network. | ||
| CVE-2021-31984 | Hig | 0.50 | 7.6 | 0.02 | Jul 14, 2021 | Power BI Remote Code Execution Vulnerability | ||
| CVE-2021-26859 | Hig | 0.50 | 7.7 | 0.03 | Mar 11, 2021 | Microsoft Power BI Information Disclosure Vulnerability | ||
| CVE-2021-41372 | Hig | 0.49 | 7.6 | 0.01 | Nov 10, 2021 | A Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) vulnerability exists when Power BI Report Server Template file (pbix) containing HTML files is uploaded to the server and HTML files are accessed directly by the victim. Combining these 2 vulnerabilities… | ||
| CVE-2024-43612 | Med | 0.45 | 6.9 | 0.01 | Oct 8, 2024 | Power BI Report Server Spoofing Vulnerability | ||
| CVE-2020-1173 | Med | 0.44 | 6.8 | 0.02 | May 21, 2020 | A spoofing vulnerability exists in Microsoft Power BI Report Server in the way it validates the content-type of uploaded attachments, aka 'Microsoft Power BI Report Server Spoofing Vulnerability'. | ||
| CVE-2024-43481 | Med | 0.42 | 6.5 | 0.02 | Oct 8, 2024 | Power BI Report Server Spoofing Vulnerability | ||
| CVE-2019-1332 | Med | 0.40 | 6.1 | 0.07 | Dec 10, 2019 | A cross-site scripting (XSS) vulnerability exists when Microsoft SQL Server Reporting Services (SSRS) does not properly sanitize a specially-crafted web request to an affected SSRS server, aka 'Microsoft SQL Server Reporting Services XSS Vulnerability'. | ||
| CVE-2026-58647 | Hig | 0.00 | 8.0 | 0.00 | Jul 14, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Power BI allows an authorized attacker to perform spoofing over a network. |
- risk 0.53cvss 8.2epss 0.01
Power BI Report Server Spoofing Vulnerability
- risk 0.52cvss 8.0epss 0.01
Improper input validation in Power BI allows an authorized attacker to execute code over a network.
- risk 0.50cvss 7.6epss 0.02
Power BI Remote Code Execution Vulnerability
- risk 0.50cvss 7.7epss 0.03
Microsoft Power BI Information Disclosure Vulnerability
- risk 0.49cvss 7.6epss 0.01
A Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) vulnerability exists when Power BI Report Server Template file (pbix) containing HTML files is uploaded to the server and HTML files are accessed directly by the victim. Combining these 2 vulnerabilities…
- risk 0.45cvss 6.9epss 0.01
Power BI Report Server Spoofing Vulnerability
- risk 0.44cvss 6.8epss 0.02
A spoofing vulnerability exists in Microsoft Power BI Report Server in the way it validates the content-type of uploaded attachments, aka 'Microsoft Power BI Report Server Spoofing Vulnerability'.
- risk 0.42cvss 6.5epss 0.02
Power BI Report Server Spoofing Vulnerability
- risk 0.40cvss 6.1epss 0.07
A cross-site scripting (XSS) vulnerability exists when Microsoft SQL Server Reporting Services (SSRS) does not properly sanitize a specially-crafted web request to an affected SSRS server, aka 'Microsoft SQL Server Reporting Services XSS Vulnerability'.
- risk 0.00cvss 8.0epss 0.00
Improper neutralization of input during web page generation ('cross-site scripting') in Power BI allows an authorized attacker to perform spoofing over a network.