« Volver al listado

Microsoft

Microsoft Power BI Report Server: vulnerabilidades y CVE

Microsoft Power BI Report Server tiene 11 vulnerabilidades publicadas, 3 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE11
Últimos 12 meses3
Críticas1
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-65811Alta (8.8)0.96%—11 ago 2026
Improper input validation in Power BI allows an authorized attacker to execute code over a network.
CVE-2026-58647Media (5.4)0.52%—14 jul 2026
Improper neutralization of input during web page generation ('cross-site scripting') in Power BI allows an authorized attacker to perform spoofing over a network.
CVE-2026-21229Alta (8.8)0.96%—10 feb 2026
Improper input validation in Power BI allows an authorized attacker to execute code over a network.
CVE-2024-43612Media (4.7)0.73%—8 oct 2024
Power BI Report Server Spoofing Vulnerability
CVE-2024-43481Alta (8.8)1.8%—8 oct 2024
Power BI Report Server Spoofing Vulnerability
CVE-2023-21806Alta (8.2)0.78%—14 feb 2023
Power BI Report Server Spoofing Vulnerability
CVE-2021-41372Crítica (9.6)0.68%—10 nov 2021
A Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) vulnerability exists when Power BI Report Server Template file (pbix) containing HTML files is uploaded to the server and HTML files are accessed…
CVE-2021-31984Alta (8.8)1.9%—14 jul 2021
Power BI Remote Code Execution Vulnerability
CVE-2021-26859Media (6.5)3.4%—11 mar 2021
Microsoft Power BI Information Disclosure Vulnerability
CVE-2020-1173Media (6.8)2.5%—21 may 2020
A spoofing vulnerability exists in Microsoft Power BI Report Server in the way it validates the content-type of uploaded attachments. An authenticated attacker could exploit the vulnerability by uploading a specially…
CVE-2019-1332Media (6.1)11%—10 dic 2019
A cross-site scripting (XSS) vulnerability exists when Microsoft SQL Server Reporting Services (SSRS) does not properly sanitize a specially-crafted web request to an affected SSRS server, aka 'Microsoft SQL Server…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1059 Command and Scripting Interpreter2
  2. T1210 Exploitation of Remote Services2
  3. T1059.007 JavaScript1
  4. T1190 Exploit Public-Facing Application1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

📰 Noticias relacionadas

Otros productos de Microsoft