Search Results (133 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-40375 1 Microsoft 3 Dynamics 365 Business Central 2024, Dynamics 365 Business Central 2025, Dynamics 365 Business Central 2026 2026-08-13 6.5 Medium
Missing authorization in Dynamics Business Central allows an authorized attacker to disclose information over a network.
CVE-2026-65815 1 Microsoft 1 Dynamics 365 2026-08-12 8.8 High
Deserialization of untrusted data in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network.
CVE-2026-66301 1 Microsoft 1 Dynamics 365 2026-08-11 6.5 Medium
Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to disclose information over a network.
CVE-2024-21380 1 Microsoft 3 Dynamics 365 Business Central, Dynamics 365 Business Central 2022, Dynamics 365 Business Central 2023 2026-08-10 8 High
Microsoft Dynamics Business Central/NAV Information Disclosure Vulnerability
CVE-2021-34474 1 Microsoft 3 Dynamics 365 Business Central, Dynamics 365 Business Central 2020, Dynamics 365 Business Central 2021 2026-08-10 8 High
Microsoft Dynamics 365 Business Central Remote Code Execution Vulnerability
CVE-2023-38167 1 Microsoft 2 Dynamics 365 Business Central, Dynamics 365 Business Central 2023 2026-08-10 7.2 High
Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability
CVE-2022-41066 1 Microsoft 5 Dynamics 365 Business Central 2019, Dynamics 365 Business Central 2021, Dynamics 365 Business Central 2022 and 2 more 2026-08-10 4.4 Medium
Microsoft Dynamics Business Central Information Disclosure Vulnerability
CVE-2021-40440 1 Microsoft 3 Dynamics 365 Business Central, Dynamics 365 Business Central 2020, Dynamics 365 Business Central 2021 2026-08-10 5.4 Medium
Microsoft Dynamics Business Central Cross-site Scripting Vulnerability
CVE-2024-38225 1 Microsoft 3 Dynamics 365 Business Central, Dynamics 365 Business Central 2023, Dynamics 365 Business Central 2024 2026-08-10 8.8 High
Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability
CVE-2021-36950 1 Microsoft 1 Dynamics 365 2026-08-10 5.4 Medium
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
CVE-2021-36946 1 Microsoft 6 Dynamics 365 Business Central, Dynamics 365 Business Central 2019, Dynamics 365 Business Central 2020 and 3 more 2026-08-10 5.4 Medium
Microsoft Dynamics Business Central Cross-site Scripting Vulnerability
CVE-2021-34524 1 Microsoft 1 Dynamics 365 2026-08-10 8.1 High
Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability
CVE-2026-47646 1 Microsoft 1 Dynamics 365 Customer Voice 2026-07-09 9.3 Critical
Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Customer Voice allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-47647 1 Microsoft 1 Dynamics 365 2026-06-22 9.9 Critical
Improper access control in Microsoft Dynamics 365 allows an authorized attacker to elevate privileges over a network.
CVE-2026-40371 1 Microsoft 2 Dynamics 365, Dynamics 365 Server 2026-06-10 8.8 High
Improper handling of insufficient permissions or privileges in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to elevate privileges over a network.
CVE-2026-40417 1 Microsoft 8 Dynamics 365 Business Central, Dynamics 365 Business Central 2024, Dynamics 365 Business Central 2024 Wave 1 and 5 more 2026-06-03 7.8 High
Weak authentication in Dynamics Business Central allows an authorized attacker to elevate privileges locally.
CVE-2026-42833 1 Microsoft 1 Dynamics 365 2026-06-01 9.1 Critical
Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network.
CVE-2026-33821 1 Microsoft 2 Dynamics 365, Dynamics 365 Customer Insights 2026-05-15 7.7 High
Improper privilege management in Microsoft Dynamics 365 Customer Insights allows an authorized attacker to elevate privileges over a network.
CVE-2026-42898 1 Microsoft 1 Dynamics 365 2026-05-12 9.9 Critical
Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network.
CVE-2026-32210 1 Microsoft 2 Dynamics 365, Dynamics 365 Online 2026-05-05 9.3 Critical
Server-side request forgery (ssrf) in Microsoft Dynamics 365 (Online) allows an unauthorized attacker to perform spoofing over a network.