Microsoft
Microsoft Power BI Report Server: vulnerabilidades y CVE
Microsoft Power BI Report Server tiene 11 vulnerabilidades publicadas, 3 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE11
Últimos 12 meses3
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-65811 | Alta (8.8) | 0.96% | — | 11 ago 2026 | Improper input validation in Power BI allows an authorized attacker to execute code over a network. |
| CVE-2026-58647 | Media (5.4) | 0.52% | — | 14 jul 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Power BI allows an authorized attacker to perform spoofing over a network. |
| CVE-2026-21229 | Alta (8.8) | 0.96% | — | 10 feb 2026 | Improper input validation in Power BI allows an authorized attacker to execute code over a network. |
| CVE-2024-43612 | Media (4.7) | 0.73% | — | 8 oct 2024 | Power BI Report Server Spoofing Vulnerability |
| CVE-2024-43481 | Alta (8.8) | 1.8% | — | 8 oct 2024 | Power BI Report Server Spoofing Vulnerability |
| CVE-2023-21806 | Alta (8.2) | 0.78% | — | 14 feb 2023 | Power BI Report Server Spoofing Vulnerability |
| CVE-2021-41372 | Crítica (9.6) | 0.68% | — | 10 nov 2021 | A Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) vulnerability exists when Power BI Report Server Template file (pbix) containing HTML files is uploaded to the server and HTML files are accessed… |
| CVE-2021-31984 | Alta (8.8) | 1.9% | — | 14 jul 2021 | Power BI Remote Code Execution Vulnerability |
| CVE-2021-26859 | Media (6.5) | 3.4% | — | 11 mar 2021 | Microsoft Power BI Information Disclosure Vulnerability |
| CVE-2020-1173 | Media (6.8) | 2.5% | — | 21 may 2020 | A spoofing vulnerability exists in Microsoft Power BI Report Server in the way it validates the content-type of uploaded attachments. An authenticated attacker could exploit the vulnerability by uploading a specially… |
| CVE-2019-1332 | Media (6.1) | 11% | — | 10 dic 2019 | A cross-site scripting (XSS) vulnerability exists when Microsoft SQL Server Reporting Services (SSRS) does not properly sanitize a specially-crafted web request to an affected SSRS server, aka 'Microsoft SQL Server… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.