Vulnerabilities

Summary — last 7 days

New vulnerabilities2,635▼ 211 vs. last week
Critical / high1,376▲ 147 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)81▼ 449 vs. last week
–

145 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
Awaiting AnalysisHigh (8.8)1.7%—Microsoft Dynamics 365AI9/8/20269/9/2026
Deserialization of untrusted data in Microsoft Dynamics 365 allows an authorized attacker to execute code over a network.
AnalyzedHigh (8.8)0.99%—Microsoft Dynamics 3659/8/20269/29/2026
Improper control of generation of code ('code injection') in Microsoft Dynamics 365 allows an authorized attacker to execute code over a network.
AnalyzedMedium (6.5)1.00%—Microsoft Dynamics 3658/11/20268/17/2026
Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to disclose information over a network.
AnalyzedHigh (8.8)1.7%—Microsoft Dynamics 3658/11/20268/17/2026
Deserialization of untrusted data in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network.
AnalyzedMedium (6.5)0.84%—Microsoft Dynamics 365 Business Central 2024Microsoft Dynamics 365 Business Central 2025Microsoft Dynamics 365 Business Central 20268/11/20268/13/2026
Missing authorization in Dynamics Business Central allows an authorized attacker to disclose information over a network.
AnalyzedMedium (6.1)0.47%—Microsoft Dynamics 365 Customer Voice7/9/20267/9/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Customer Voice allows an unauthorized attacker to perform spoofing over a network.
AnalyzedCritical (9.9)0.78%—Microsoft Dynamics 3656/18/20266/25/2026
Improper access control in Microsoft Dynamics 365 allows an authorized attacker to elevate privileges over a network.
AnalyzedHigh (8.8)0.78%—Microsoft Dynamics 3656/9/20267/23/2026
Improper handling of insufficient permissions or privileges in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to elevate privileges over a network.
AnalyzedCritical (9.9)0.99%—Microsoft Dynamics 3655/12/20266/17/2026
Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network.
ModifiedCritical (9.1)0.93%—Microsoft Dynamics 3655/12/20266/17/2026
Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network.
AnalyzedHigh (7.8)0.30%—Microsoft Dynamics 365 Business Central5/12/20268/10/2026
Weak authentication in Dynamics Business Central allows an authorized attacker to elevate privileges locally.
AnalyzedCritical (9.9)0.77%—Microsoft Dynamics 365 Customer Insights5/12/20266/17/2026
Improper privilege management in Microsoft Dynamics 365 Customer Insights allows an authorized attacker to elevate privileges over a network.
AnalyzedHigh (7.5)0.73%—Microsoft Dynamics 3654/23/20266/17/2026
Server-side request forgery (ssrf) in Microsoft Dynamics 365 (Online) allows an unauthorized attacker to perform spoofing over a network.
AnalyzedMedium (5.5)0.35%—Microsoft Dynamics 3654/14/20267/24/2026
Improper access control in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to disclose information locally.
Awaiting AnalysisHigh (8.8)0.46%—Microsoft Dynamics 365 Customer EngagementAIMicrosoft SQL Server Reporting ServicesAI3/18/20266/17/2026
Microsoft Dynamics 365 Customer Engagement (on-premises) 1612 (9.0.2.3034) allows the generation of customized reports via raw SQL queries in an upload of a .rdl (Report Definition Language) file; this is then processed by the SQL Server Reporting Service. An account with the privilege Add Reporting Services Reports…
DeferredMedium (4.4)0.24%—Integrate Dynamics 365 CRMAI1/17/20266/17/2026
The Integrate Dynamics 365 CRM plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.1.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with…
DeferredHigh (8.6)0.30%—Progress Datadirect Connect FOR Jdbc FOR Amazon RedshiftAIProgress Datadirect Connect FOR Jdbc FOR Apache CassandraAIProgress Datadirect Connect FOR Jdbc FOR HiveAIProgress Datadirect Connect FOR Jdbc FOR Apache ImpalaAI+2811/19/20256/17/2026
Improper Control of Generation of Code ('Code Injection') vulnerability in Progress DataDirect Connect for JDBC drivers, Progress DataDirect Open Access JDBC driver and Hybrid Data Pipeline allows Remote Code Inclusion. The SpyAttribute connection option implemented by the DataDirect Connect for JDBC drivers,…
DeferredHigh (8.6)0.30%—Progress Datadirect Connect FOR Jdbc FOR Amazon RedshiftAIProgress Datadirect Connect FOR Jdbc FOR Apache CassandraAIProgress Datadirect Connect FOR Jdbc FOR HiveAIProgress Datadirect Connect FOR Jdbc FOR Apache ImpalaAI+2811/19/20256/17/2026
Improper Control of Generation of Code ('Code Injection') vulnerability in Progress DataDirect Connect for JDBC drivers, Progress DataDirect Open Access JDBC driver and Hybrid Data Pipeline allows Remote Code Inclusion. The SpyAttribute connection option implemented by the DataDirect Connect for JDBC drivers,…
AnalyzedHigh (8.7)0.60%—Microsoft Dynamics 36511/11/20256/17/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Field Service (online) allows an authorized attacker to perform spoofing over a network.
AnalyzedHigh (8.7)0.60%—Microsoft Dynamics 36511/11/20256/17/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Field Service (online) allows an authorized attacker to perform spoofing over a network.
AnalyzedMedium (6.5)0.92%—Microsoft Dynamics 36511/11/20256/17/2026
Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an unauthorized attacker to disclose information over a network.
DeferredMedium (6.5)0.27%—Integrate Dynamics 365 CRMAI10/4/20259/30/2026
The Integrate Dynamics 365 CRM plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 1.0.9. This is due to missing capability checks and nonce verification on functions hooked to 'init'. This makes it possible for unauthenticated attackers to deactivate the plugin, tamper with…
AnalyzedHigh (7.5)0.82%—Microsoft Dynamics 3659/4/20256/17/2026
Dynamics 365 FastTrack Implementation Assets Information Disclosure Vulnerability
AnalyzedHigh (7.5)0.81%—Microsoft Dynamics 365 GuidesMicrosoft Dynamics 365 Remote AssistMicrosoft TeamsMicrosoft Teams Panels+18/12/20256/17/2026
Heap-based buffer overflow in Microsoft Teams allows an unauthorized attacker to execute code over a network.
AnalyzedMedium (6.5)1.2%—Microsoft Dynamics 3658/12/20256/17/2026
Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an unauthorized attacker to disclose information over a network.