Vulnerabilities
Summary — last 7 days
New vulnerabilities2,635▼ 211 vs. last week
Critical / high1,376▲ 147 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)81▼ 449 vs. last week
145 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Awaiting Analysis | High (8.8) | 1.7% | — | Microsoft Dynamics 365AI | 9/8/2026 | 9/9/2026 | Deserialization of untrusted data in Microsoft Dynamics 365 allows an authorized attacker to execute code over a network. | |
| Analyzed | High (8.8) | 0.99% | — | Microsoft Dynamics 365 | 9/8/2026 | 9/29/2026 | Improper control of generation of code ('code injection') in Microsoft Dynamics 365 allows an authorized attacker to execute code over a network. | |
| Analyzed | Medium (6.5) | 1.00% | — | Microsoft Dynamics 365 | 8/11/2026 | 8/17/2026 | Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to disclose information over a network. | |
| Analyzed | High (8.8) | 1.7% | — | Microsoft Dynamics 365 | 8/11/2026 | 8/17/2026 | Deserialization of untrusted data in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network. | |
| Analyzed | Medium (6.5) | 0.84% | — | Microsoft Dynamics 365 Business Central 2024Microsoft Dynamics 365 Business Central 2025Microsoft Dynamics 365 Business Central 2026 | 8/11/2026 | 8/13/2026 | Missing authorization in Dynamics Business Central allows an authorized attacker to disclose information over a network. | |
| Analyzed | Medium (6.1) | 0.47% | — | Microsoft Dynamics 365 Customer Voice | 7/9/2026 | 7/9/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Customer Voice allows an unauthorized attacker to perform spoofing over a network. | |
| Analyzed | Critical (9.9) | 0.78% | — | Microsoft Dynamics 365 | 6/18/2026 | 6/25/2026 | Improper access control in Microsoft Dynamics 365 allows an authorized attacker to elevate privileges over a network. | |
| Analyzed | High (8.8) | 0.78% | — | Microsoft Dynamics 365 | 6/9/2026 | 7/23/2026 | Improper handling of insufficient permissions or privileges in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to elevate privileges over a network. | |
| Analyzed | Critical (9.9) | 0.99% | — | Microsoft Dynamics 365 | 5/12/2026 | 6/17/2026 | Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network. | |
| Modified | Critical (9.1) | 0.93% | — | Microsoft Dynamics 365 | 5/12/2026 | 6/17/2026 | Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network. | |
| Analyzed | High (7.8) | 0.30% | — | Microsoft Dynamics 365 Business Central | 5/12/2026 | 8/10/2026 | Weak authentication in Dynamics Business Central allows an authorized attacker to elevate privileges locally. | |
| Analyzed | Critical (9.9) | 0.77% | — | Microsoft Dynamics 365 Customer Insights | 5/12/2026 | 6/17/2026 | Improper privilege management in Microsoft Dynamics 365 Customer Insights allows an authorized attacker to elevate privileges over a network. | |
| Analyzed | High (7.5) | 0.73% | — | Microsoft Dynamics 365 | 4/23/2026 | 6/17/2026 | Server-side request forgery (ssrf) in Microsoft Dynamics 365 (Online) allows an unauthorized attacker to perform spoofing over a network. | |
| Analyzed | Medium (5.5) | 0.35% | — | Microsoft Dynamics 365 | 4/14/2026 | 7/24/2026 | Improper access control in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to disclose information locally. | |
| Awaiting Analysis | High (8.8) | 0.46% | — | Microsoft Dynamics 365 Customer EngagementAIMicrosoft SQL Server Reporting ServicesAI | 3/18/2026 | 6/17/2026 | Microsoft Dynamics 365 Customer Engagement (on-premises) 1612 (9.0.2.3034) allows the generation of customized reports via raw SQL queries in an upload of a .rdl (Report Definition Language) file; this is then processed by the SQL Server Reporting Service. An account with the privilege Add Reporting Services Reports… | |
| Deferred | Medium (4.4) | 0.24% | — | Integrate Dynamics 365 CRMAI | 1/17/2026 | 6/17/2026 | The Integrate Dynamics 365 CRM plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.1.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Deferred | High (8.6) | 0.30% | — | Progress Datadirect Connect FOR Jdbc FOR Amazon RedshiftAIProgress Datadirect Connect FOR Jdbc FOR Apache CassandraAIProgress Datadirect Connect FOR Jdbc FOR HiveAIProgress Datadirect Connect FOR Jdbc FOR Apache ImpalaAI+28 | 11/19/2025 | 6/17/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Progress DataDirect Connect for JDBC drivers, Progress DataDirect Open Access JDBC driver and Hybrid Data Pipeline allows Remote Code Inclusion. The SpyAttribute connection option implemented by the DataDirect Connect for JDBC drivers,… | |
| Deferred | High (8.6) | 0.30% | — | Progress Datadirect Connect FOR Jdbc FOR Amazon RedshiftAIProgress Datadirect Connect FOR Jdbc FOR Apache CassandraAIProgress Datadirect Connect FOR Jdbc FOR HiveAIProgress Datadirect Connect FOR Jdbc FOR Apache ImpalaAI+28 | 11/19/2025 | 6/17/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Progress DataDirect Connect for JDBC drivers, Progress DataDirect Open Access JDBC driver and Hybrid Data Pipeline allows Remote Code Inclusion. The SpyAttribute connection option implemented by the DataDirect Connect for JDBC drivers,… | |
| Analyzed | High (8.7) | 0.60% | — | Microsoft Dynamics 365 | 11/11/2025 | 6/17/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Field Service (online) allows an authorized attacker to perform spoofing over a network. | |
| Analyzed | High (8.7) | 0.60% | — | Microsoft Dynamics 365 | 11/11/2025 | 6/17/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Field Service (online) allows an authorized attacker to perform spoofing over a network. | |
| Analyzed | Medium (6.5) | 0.92% | — | Microsoft Dynamics 365 | 11/11/2025 | 6/17/2026 | Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an unauthorized attacker to disclose information over a network. | |
| Deferred | Medium (6.5) | 0.27% | — | Integrate Dynamics 365 CRMAI | 10/4/2025 | 9/30/2026 | The Integrate Dynamics 365 CRM plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 1.0.9. This is due to missing capability checks and nonce verification on functions hooked to 'init'. This makes it possible for unauthenticated attackers to deactivate the plugin, tamper with… | |
| Analyzed | High (7.5) | 0.82% | — | Microsoft Dynamics 365 | 9/4/2025 | 6/17/2026 | Dynamics 365 FastTrack Implementation Assets Information Disclosure Vulnerability | |
| Analyzed | High (7.5) | 0.81% | — | Microsoft Dynamics 365 GuidesMicrosoft Dynamics 365 Remote AssistMicrosoft TeamsMicrosoft Teams Panels+1 | 8/12/2025 | 6/17/2026 | Heap-based buffer overflow in Microsoft Teams allows an unauthorized attacker to execute code over a network. | |
| Analyzed | Medium (6.5) | 1.2% | — | Microsoft Dynamics 365 | 8/12/2025 | 6/17/2026 | Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an unauthorized attacker to disclose information over a network. |