Dynamics 365
by Microsoft
CVEs (115)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-17133 | Med | 0.43 | 6.5 | 0.03 | Dec 10, 2020 | Microsoft Dynamics Business Central/NAV Information Disclosure Vulnerability | ||
| CVE-2025-62206 | Med | 0.42 | 6.5 | 0.01 | Nov 11, 2025 | Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2025-53728 | Med | 0.42 | 6.5 | 0.01 | Aug 12, 2025 | Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2023-36433 | Med | 0.42 | 6.5 | 0.02 | Oct 10, 2023 | Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability | ||
| CVE-2023-36429 | Med | 0.42 | 6.5 | 0.02 | Oct 10, 2023 | Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability | ||
| CVE-2023-35389 | Med | 0.42 | 6.5 | 0.01 | Aug 8, 2023 | Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability | ||
| CVE-2023-24922 | Med | 0.42 | 6.5 | 0.01 | Mar 14, 2023 | Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability | ||
| CVE-2023-21807 | Med | 0.42 | 6.5 | 0.01 | Feb 14, 2023 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | ||
| CVE-2023-21572 | Med | 0.42 | 6.5 | 0.01 | Feb 14, 2023 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | ||
| CVE-2021-24101 | Med | 0.42 | 6.5 | 0.03 | Feb 25, 2021 | Microsoft Dataverse Information Disclosure Vulnerability | ||
| CVE-2020-16943 | Med | 0.42 | 6.5 | 0.01 | Oct 16, 2020 | An elevation of privilege vulnerability exists in Microsoft Dynamics 365 Commerce. An unauthenticated attacker who successfully exploited this vulnerability could update data without proper authorization. To exploit the vulnerability, an attacker would need to send a… | ||
| CVE-2018-8654 | Med | 0.42 | 6.5 | 0.02 | Jan 24, 2020 | An elevation of privilege vulnerability exists in Microsoft Dynamics 365 Server, aka 'Microsoft Dynamics 365 Elevation of Privilege Vulnerability'. | ||
| CVE-2023-36030 | Med | 0.40 | 6.1 | 0.01 | Nov 14, 2023 | Microsoft Dynamics 365 Sales Spoofing Vulnerability | ||
| CVE-2023-36016 | Med | 0.40 | 6.2 | 0.01 | Nov 14, 2023 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | ||
| CVE-2023-36416 | Med | 0.40 | 6.1 | 0.01 | Oct 10, 2023 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | ||
| CVE-2023-28314 | Med | 0.40 | 6.1 | 0.01 | Apr 11, 2023 | Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | ||
| CVE-2021-28461 | Med | 0.40 | 6.1 | 0.01 | May 11, 2021 | Dynamics Finance and Operations Cross-site Scripting Vulnerability | ||
| CVE-2019-1008 | Med | 0.39 | 5.9 | 0.03 | May 16, 2019 | A security feature bypass vulnerability exists in Dynamics On Premise, aka 'Microsoft Dynamics On-Premise Security Feature Bypass'. | ||
| CVE-2024-35263 | Med | 0.37 | 5.7 | 0.02 | Jun 11, 2024 | Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability | ||
| CVE-2026-33103 | Med | 0.36 | 5.5 | 0.00 | Apr 14, 2026 | Improper access control in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to disclose information locally. |
- risk 0.43cvss 6.5epss 0.03
Microsoft Dynamics Business Central/NAV Information Disclosure Vulnerability
- risk 0.42cvss 6.5epss 0.01
Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an unauthorized attacker to disclose information over a network.
- risk 0.42cvss 6.5epss 0.01
Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an unauthorized attacker to disclose information over a network.
- risk 0.42cvss 6.5epss 0.02
Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability
- risk 0.42cvss 6.5epss 0.02
Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability
- risk 0.42cvss 6.5epss 0.01
Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability
- risk 0.42cvss 6.5epss 0.01
Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability
- risk 0.42cvss 6.5epss 0.01
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
- risk 0.42cvss 6.5epss 0.01
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
- risk 0.42cvss 6.5epss 0.03
Microsoft Dataverse Information Disclosure Vulnerability
- risk 0.42cvss 6.5epss 0.01
An elevation of privilege vulnerability exists in Microsoft Dynamics 365 Commerce. An unauthenticated attacker who successfully exploited this vulnerability could update data without proper authorization. To exploit the vulnerability, an attacker would need to send a…
- risk 0.42cvss 6.5epss 0.02
An elevation of privilege vulnerability exists in Microsoft Dynamics 365 Server, aka 'Microsoft Dynamics 365 Elevation of Privilege Vulnerability'.
- risk 0.40cvss 6.1epss 0.01
Microsoft Dynamics 365 Sales Spoofing Vulnerability
- risk 0.40cvss 6.2epss 0.01
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
- risk 0.40cvss 6.1epss 0.01
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
- risk 0.40cvss 6.1epss 0.01
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
- risk 0.40cvss 6.1epss 0.01
Dynamics Finance and Operations Cross-site Scripting Vulnerability
- risk 0.39cvss 5.9epss 0.03
A security feature bypass vulnerability exists in Dynamics On Premise, aka 'Microsoft Dynamics On-Premise Security Feature Bypass'.
- risk 0.37cvss 5.7epss 0.02
Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability
- risk 0.36cvss 5.5epss 0.00
Improper access control in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to disclose information locally.
Page 4 of 6