Power Bi
by Microsoft
CVEs (8)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-65811 | Hig | 0.57 | 8.8 | 0.01 | Aug 11, 2026 | Improper input validation in Power BI allows an authorized attacker to execute code over a network. | ||
| CVE-2026-21229 | Hig | 0.52 | 8.0 | 0.01 | Feb 10, 2026 | Improper input validation in Power BI allows an authorized attacker to execute code over a network. | ||
| CVE-2021-31984 | Hig | 0.50 | 7.6 | 0.02 | Jul 14, 2021 | Power BI Remote Code Execution Vulnerability | ||
| CVE-2021-26859 | Hig | 0.50 | 7.7 | 0.03 | Mar 11, 2021 | Microsoft Power BI Information Disclosure Vulnerability | ||
| CVE-2026-26133 | Hig | 0.46 | 7.1 | 0.00 | Mar 16, 2026 | AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2022-23254 | Med | 0.32 | 4.9 | 0.03 | Feb 9, 2022 | Microsoft Power BI Information Disclosure Vulnerability | ||
| CVE-2022-23292 | Low | 0.24 | 3.7 | 0.01 | Apr 15, 2022 | Microsoft Power BI Spoofing Vulnerability | ||
| CVE-2026-58647 | Hig | 0.00 | 8.0 | 0.00 | Jul 14, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Power BI allows an authorized attacker to perform spoofing over a network. |
- risk 0.57cvss 8.8epss 0.01
Improper input validation in Power BI allows an authorized attacker to execute code over a network.
- risk 0.52cvss 8.0epss 0.01
Improper input validation in Power BI allows an authorized attacker to execute code over a network.
- risk 0.50cvss 7.6epss 0.02
Power BI Remote Code Execution Vulnerability
- risk 0.50cvss 7.7epss 0.03
Microsoft Power BI Information Disclosure Vulnerability
- risk 0.46cvss 7.1epss 0.00
AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.
- risk 0.32cvss 4.9epss 0.03
Microsoft Power BI Information Disclosure Vulnerability
- risk 0.24cvss 3.7epss 0.01
Microsoft Power BI Spoofing Vulnerability
- risk 0.00cvss 8.0epss 0.00
Improper neutralization of input during web page generation ('cross-site scripting') in Power BI allows an authorized attacker to perform spoofing over a network.