Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
145 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 1.6% | — | Microsoft Dynamics 365 | 11/9/2020 | 17/6/2026 | <p>A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially crafted web request to an affected Dynamics server. An authenticated attacker could exploit the vulnerability by sending a specially crafted request to an affected Dynamics server.</p> <p>The… | |
| Modificada | Alta (8.8) | 2.7% | — | Microsoft Dynamics 365 FOR Finance AND Operations | 11/9/2020 | 17/6/2026 | <p>A remote code execution vulnerability exists in Microsoft Dynamics 365 for Finance and Operations (on-premises) version 10.0.11. An attacker who successfully exploited this vulnerability could gain remote code execution via server-side script execution on the victim server.</p> <p>An authenticated attacker with… | |
| Modificada | Media (5.4) | 1.5% | — | Microsoft Dynamics 365 | 17/8/2020 | 17/6/2026 | A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially crafted web request to an affected Dynamics server. An authenticated attacker could exploit the vulnerability by sending a specially crafted request to an affected Dynamics server. The attacker… | |
| Modificada | Alta (8) | 2.8% | — | Microsoft Dynamics 365 FOR Finance AND Operations | 17/8/2020 | 17/6/2026 | A remote code execution vulnerability exists in Microsoft Dynamics 365 for Finance and Operations (on-premises) version 10.0.11. An attacker who successfully exploited this vulnerability could gain remote code execution via server-side script execution on the victim server. An authenticated attacker with privileges to… | |
| Modificada | Media (5.4) | 1.5% | — | Microsoft Dynamics 365 | 21/5/2020 | 19/8/2026 | A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially crafted web request to an affected Dynamics server. An authenticated attacker could exploit the vulnerability by sending a specially crafted request to an affected Dynamics server. The attacker… | |
| Modificada | Media (6.1) | 1.8% | — | Microsoft Dynamics 365 Server | 15/4/2020 | 17/6/2026 | A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially crafted web request to an affected Dynamics server, aka 'Microsoft Dynamics 365 (On-Premise) Cross Site Scripting Vulnerability'. This CVE ID is unique from CVE-2020-1049. | |
| Modificada | Media (5.4) | 1.5% | — | Microsoft Dynamics 365 Server | 15/4/2020 | 17/6/2026 | A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially crafted web request to an affected Dynamics server, aka 'Microsoft Dynamics 365 (On-Premise) Cross Site Scripting Vulnerability'. This CVE ID is unique from CVE-2020-1050. | |
| Modificada | Alta (8) | 6.8% | — | Microsoft Dynamics 365 Business CentralMicrosoft Dynamics NAV | 15/4/2020 | 17/6/2026 | A remote code execution vulnerability exists in Microsoft Dynamics Business Central, aka 'Dynamics Business Central Remote Code Execution Vulnerability'. | |
| Modificada | Alta (7.5) | 6.3% | — | Microsoft Dynamics 365 Business CentralMicrosoft Dynamics NAV | 15/4/2020 | 17/6/2026 | An information disclosure vulnerability exists when Microsoft Dynamics Business Central/NAV on-premise does not properly hide the value of a masked field when showing the records as a chart page.The attacker who successfully exploited the vulnerability could see the information that are in a masked field.The security… | |
| Modificada | Alta (8) | 11% | — | Microsoft Dynamics 365 Business CentralMicrosoft Dynamics NAV | 12/3/2020 | 17/6/2026 | An remote code execution vulnerability exists in Microsoft Dynamics Business Central, aka 'Dynamics Business Central Remote Code Execution Vulnerability'. | |
| Modificada | Media (6.5) | 1.8% | — | Microsoft Dynamics 365 | 24/1/2020 | 17/6/2026 | An elevation of privilege vulnerability exists in Microsoft Dynamics 365 Server, aka 'Microsoft Dynamics 365 Elevation of Privilege Vulnerability'. | |
| Modificada | Media (5.4) | 1.5% | — | Microsoft Dynamics 365 | 14/1/2020 | 17/6/2026 | A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially crafted web request to an affected Dynamics server, aka 'Microsoft Dynamics 365 (On-Premise) Cross Site Scripting Vulnerability'. | |
| Modificada | Media (5.4) | 1.6% | — | Microsoft Dynamics 365 | 10/10/2019 | 17/6/2026 | A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially crafted web request to an affected Dynamics server, aka 'Microsoft Dynamics 365 (On-Premise) Cross Site Scripting Vulnerability'. | |
| Modificada | Alta (8.8) | 3.5% | — | Microsoft Dynamics 365 | 14/8/2019 | 17/6/2026 | An elevation of privilege vulnerability exists in Dynamics On-Premise v9. An attacker who successfully exploited the vulnerability could leverage a customizer privilege within Dynamics to gain control of the Web Role hosting the Dynamics installation. To exploit this vulnerability, an attacker needs to have… | |
| Modificada | Media (5.9) | 2.8% | — | Microsoft Dynamics 365Microsoft Dynamics CRM 2015 | 16/5/2019 | 17/6/2026 | A security feature bypass vulnerability exists in Dynamics On Premise, aka 'Microsoft Dynamics On-Premise Security Feature Bypass'. | |
| Modificada | Alta (8.8) | 9.9% | — | Microsoft Dynamics 365 | 14/11/2018 | 17/6/2026 | A remote code execution vulnerability exists in Microsoft Dynamics 365 (on-premises) version 8 when the server fails to properly sanitize web requests to an affected Dynamics server, aka "Microsoft Dynamics 365 (on-premises) version 8 Remote Code Execution Vulnerability." This affects Microsoft Dynamics 365. | |
| Modificada | Media (5.4) | 1.6% | — | Microsoft Dynamics 365 | 14/11/2018 | 17/6/2026 | A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) version 8 does not properly sanitize a specially crafted web request to an affected Dynamics server, aka "Microsoft Dynamics 365 (on-premises) version 8 Cross Site Scripting Vulnerability." This affects Microsoft Dynamics 365. This… | |
| Modificada | Media (5.4) | 1.6% | — | Microsoft Dynamics 365 | 14/11/2018 | 17/6/2026 | A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) version 8 does not properly sanitize a specially crafted web request to an affected Dynamics server, aka "Microsoft Dynamics 365 (on-premises) version 8 Cross Site Scripting Vulnerability." This affects Microsoft Dynamics 365. This… | |
| Modificada | Media (5.4) | 1.6% | — | Microsoft Dynamics 365 | 14/11/2018 | 17/6/2026 | A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) version 8 does not properly sanitize a specially crafted web request to an affected Dynamics server, aka "Microsoft Dynamics 365 (on-premises) version 8 Cross Site Scripting Vulnerability." This affects Microsoft Dynamics 365. This… | |
| Modificada | Media (5.4) | 1.6% | — | Microsoft Dynamics 365 | 14/11/2018 | 17/6/2026 | A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) version 8 does not properly sanitize a specially crafted web request to an affected Dynamics server, aka "Microsoft Dynamics 365 (on-premises) version 8 Cross Site Scripting Vulnerability." This affects Microsoft Dynamics 365. This… |