Power Platform
by Microsoft
CVEs (3)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-36019 | Cri | 0.64 | 9.6 | 0.16 | Dec 12, 2023 | Microsoft Power Platform Connector Spoofing Vulnerability | ||
| CVE-2024-38190 | Hig | 0.56 | 8.6 | 0.01 | Oct 15, 2024 | Missing authorization in Power Platform allows an unauthenticated attacker to view sensitive information through a network attack vector. | ||
| CVE-2024-35260 | Hig | 0.52 | 8.0 | 0.01 | Jun 27, 2024 | An authenticated attacker can exploit an untrusted search path vulnerability in Microsoft Dataverse to execute code over a network. |
- risk 0.64cvss 9.6epss 0.16
Microsoft Power Platform Connector Spoofing Vulnerability
- risk 0.56cvss 8.6epss 0.01
Missing authorization in Power Platform allows an unauthenticated attacker to view sensitive information through a network attack vector.
- risk 0.52cvss 8.0epss 0.01
An authenticated attacker can exploit an untrusted search path vulnerability in Microsoft Dataverse to execute code over a network.