Dynamics 365
by Microsoft
CVEs (115)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-47647 | Cri | 0.64 | 9.9 | 0.01 | Jun 18, 2026 | Improper access control in Microsoft Dynamics 365 allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-42898 | Cri | 0.64 | 9.9 | 0.01 | May 12, 2026 | Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network. | ||
| CVE-2026-32210 | Cri | 0.60 | 9.3 | 0.01 | Apr 23, 2026 | Server-side request forgery (ssrf) in Microsoft Dynamics 365 (Online) allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2026-42833 | Cri | 0.59 | 9.1 | 0.01 | May 12, 2026 | Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network. | ||
| CVE-2024-38182 | Cri | 0.59 | 9.0 | 0.01 | Jul 31, 2024 | Weak authentication in Microsoft Dynamics 365 allows an unauthenticated attacker to elevate privileges over a network. | ||
| CVE-2018-8609 | Hig | 0.58 | 8.8 | 0.10 | Nov 14, 2018 | A remote code execution vulnerability exists in Microsoft Dynamics 365 (on-premises) version 8 when the server fails to properly sanitize web requests to an affected Dynamics server, aka "Microsoft Dynamics 365 (on-premises) version 8 Remote Code Execution Vulnerability." This… | ||
| CVE-2026-65815 | Hig | 0.57 | 8.8 | 0.01 | Aug 11, 2026 | Deserialization of untrusted data in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network. | ||
| CVE-2026-40371 | Hig | 0.57 | 8.8 | 0.01 | Jun 9, 2026 | Improper handling of insufficient permissions or privileges in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2025-62211 | Hig | 0.57 | 8.7 | 0.01 | Nov 11, 2025 | Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Field Service (online) allows an authorized attacker to perform spoofing over a network. | ||
| CVE-2025-62210 | Hig | 0.57 | 8.7 | 0.01 | Nov 11, 2025 | Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Field Service (online) allows an authorized attacker to perform spoofing over a network. | ||
| CVE-2025-21177 | Hig | 0.57 | 8.7 | 0.01 | Feb 6, 2025 | Server-side request forgery (ssrf) in Microsoft Dynamics 365 Sales allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2022-35805 | Hig | 0.57 | 8.8 | 0.02 | Sep 13, 2022 | Microsoft Dynamics CRM (on-premises) Remote Code Execution Vulnerability | ||
| CVE-2022-34700 | Hig | 0.57 | 8.8 | 0.03 | Sep 13, 2022 | Microsoft Dynamics CRM (on-premises) Remote Code Execution Vulnerability | ||
| CVE-2022-23259 | Hig | 0.57 | 8.8 | 0.03 | Apr 15, 2022 | Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability | ||
| CVE-2021-42316 | Hig | 0.57 | 8.8 | 0.02 | Nov 10, 2021 | Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability | ||
| CVE-2020-17158 | Hig | 0.57 | 8.8 | 0.03 | Dec 10, 2020 | Microsoft Dynamics 365 for Finance and Operations (on-premises) Remote Code Execution Vulnerability | ||
| CVE-2020-17152 | Hig | 0.57 | 8.8 | 0.03 | Dec 10, 2020 | Microsoft Dynamics 365 for Finance and Operations (on-premises) Remote Code Execution Vulnerability | ||
| CVE-2020-17147 | Hig | 0.57 | 8.7 | 0.01 | Dec 10, 2020 | Dynamics CRM Webclient Cross-site Scripting Vulnerability | ||
| CVE-2019-1229 | Hig | 0.57 | 8.8 | 0.03 | Aug 14, 2019 | An elevation of privilege vulnerability exists in Dynamics On-Premise v9. An attacker who successfully exploited the vulnerability could leverage a customizer privilege within Dynamics to gain control of the Web Role hosting the Dynamics installation. To exploit this… | ||
| CVE-2022-41127 | Hig | 0.55 | 8.5 | 0.02 | Dec 13, 2022 | Microsoft Dynamics NAV and Microsoft Dynamics 365 Business Central (On Premises) Remote Code Execution Vulnerability |
- risk 0.64cvss 9.9epss 0.01
Improper access control in Microsoft Dynamics 365 allows an authorized attacker to elevate privileges over a network.
- risk 0.64cvss 9.9epss 0.01
Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network.
- risk 0.60cvss 9.3epss 0.01
Server-side request forgery (ssrf) in Microsoft Dynamics 365 (Online) allows an unauthorized attacker to perform spoofing over a network.
- risk 0.59cvss 9.1epss 0.01
Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network.
- risk 0.59cvss 9.0epss 0.01
Weak authentication in Microsoft Dynamics 365 allows an unauthenticated attacker to elevate privileges over a network.
- risk 0.58cvss 8.8epss 0.10
A remote code execution vulnerability exists in Microsoft Dynamics 365 (on-premises) version 8 when the server fails to properly sanitize web requests to an affected Dynamics server, aka "Microsoft Dynamics 365 (on-premises) version 8 Remote Code Execution Vulnerability." This…
- risk 0.57cvss 8.8epss 0.01
Deserialization of untrusted data in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.01
Improper handling of insufficient permissions or privileges in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to elevate privileges over a network.
- risk 0.57cvss 8.7epss 0.01
Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Field Service (online) allows an authorized attacker to perform spoofing over a network.
- risk 0.57cvss 8.7epss 0.01
Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Field Service (online) allows an authorized attacker to perform spoofing over a network.
- risk 0.57cvss 8.7epss 0.01
Server-side request forgery (ssrf) in Microsoft Dynamics 365 Sales allows an authorized attacker to elevate privileges over a network.
- risk 0.57cvss 8.8epss 0.02
Microsoft Dynamics CRM (on-premises) Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.03
Microsoft Dynamics CRM (on-premises) Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.03
Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.02
Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.03
Microsoft Dynamics 365 for Finance and Operations (on-premises) Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.03
Microsoft Dynamics 365 for Finance and Operations (on-premises) Remote Code Execution Vulnerability
- risk 0.57cvss 8.7epss 0.01
Dynamics CRM Webclient Cross-site Scripting Vulnerability
- risk 0.57cvss 8.8epss 0.03
An elevation of privilege vulnerability exists in Dynamics On-Premise v9. An attacker who successfully exploited the vulnerability could leverage a customizer privilege within Dynamics to gain control of the Web Role hosting the Dynamics installation. To exploit this…
- risk 0.55cvss 8.5epss 0.02
Microsoft Dynamics NAV and Microsoft Dynamics 365 Business Central (On Premises) Remote Code Execution Vulnerability
Page 1 of 6