Total
28117 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2023-33130 | 1 Microsoft | 1 Sharepoint Server | 2024-05-29 | N/A | 7.3 HIGH |
| Microsoft SharePoint Server Spoofing Vulnerability | |||||
| CVE-2023-32024 | 1 Microsoft | 1 Power Apps | 2024-05-29 | N/A | 3.0 LOW |
| Microsoft Power Apps Spoofing Vulnerability | |||||
| CVE-2023-28314 | 1 Microsoft | 1 Dynamics 365 | 2024-05-29 | N/A | 6.1 MEDIUM |
| Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | |||||
| CVE-2023-28313 | 1 Microsoft | 1 Send Customer Voice Survey From Dynamics 365 | 2024-05-29 | N/A | 6.1 MEDIUM |
| Microsoft Dynamics 365 Customer Voice Cross-Site Scripting Vulnerability | |||||
| CVE-2023-28309 | 1 Microsoft | 1 Dynamics 365 | 2024-05-29 | N/A | 5.4 MEDIUM |
| Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | |||||
| CVE-2023-24896 | 1 Microsoft | 1 Dynamics 365 | 2024-05-29 | N/A | 5.4 MEDIUM |
| Dynamics 365 Finance Spoofing Vulnerability | |||||
| CVE-2023-21806 | 1 Microsoft | 1 Power Bi Report Server | 2024-05-29 | N/A | 8.2 HIGH |
| Power BI Report Server Spoofing Vulnerability | |||||
| CVE-2023-21565 | 1 Microsoft | 1 Azure Devops Server | 2024-05-29 | N/A | 7.1 HIGH |
| Azure DevOps Server Spoofing Vulnerability | |||||
| CVE-2024-21396 | 1 Microsoft | 1 Dynamics 365 | 2024-05-29 | N/A | 7.6 HIGH |
| Dynamics 365 Sales Spoofing Vulnerability | |||||
| CVE-2024-21395 | 1 Microsoft | 1 Dynamics 365 | 2024-05-29 | N/A | 8.2 HIGH |
| Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | |||||
| CVE-2024-21394 | 1 Microsoft | 1 Dynamics 365 | 2024-05-29 | N/A | 7.6 HIGH |
| Dynamics 365 Field Service Spoofing Vulnerability | |||||
| CVE-2024-21393 | 1 Microsoft | 1 Dynamics 365 | 2024-05-29 | N/A | 7.6 HIGH |
| Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | |||||
| CVE-2024-21389 | 1 Microsoft | 1 Dynamics 365 | 2024-05-29 | N/A | 7.6 HIGH |
| Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | |||||
| CVE-2024-21328 | 1 Microsoft | 1 Dynamics 365 | 2024-05-29 | N/A | 7.6 HIGH |
| Dynamics 365 Sales Spoofing Vulnerability | |||||
| CVE-2024-21327 | 1 Microsoft | 1 Dynamics 365 | 2024-05-29 | N/A | 7.6 HIGH |
| Microsoft Dynamics 365 Customer Engagement Cross-Site Scripting Vulnerability | |||||
| CVE-2024-20679 | 1 Microsoft | 1 Azure Stack Hub | 2024-05-29 | N/A | 6.5 MEDIUM |
| Azure Stack Hub Spoofing Vulnerability | |||||
| CVE-2024-29049 | 2024-05-28 | N/A | 4.1 MEDIUM | ||
| Microsoft Edge (Chromium-based) Webview2 Spoofing Vulnerability | |||||
| CVE-2021-41372 | 1 Microsoft | 1 Power Bi Report Server | 2024-05-28 | 6.8 MEDIUM | 7.6 HIGH |
| A Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) vulnerability exists when Power BI Report Server Template file (pbix) containing HTML files is uploaded to the server and HTML files are accessed directly by the victim. Combining these 2 vulnerabilities together, an attacker is able to upload malicious Power BI templates files to the server using the victim's session and run scripts in the security context of the user and perform privilege escalation in case the victim has admin privileges when the victim access one of the HTML files present in the malicious Power BI template uploaded. The security update addresses the vulnerability by helping to ensure that Power BI Report Server properly sanitize file uploads. | |||||
| CVE-2024-5413 | 2024-05-28 | N/A | 7.1 HIGH | ||
| A vulnerability have been discovered in PhpMyBackupPro affecting version 2.3 that could allow an attacker to execute XSS through /phpmybackuppro/scheduled.php, all parameters. This vulnerabilities could allow an attacker to create a specially crafted URL and send it to a victim to retrieve their session details. | |||||
| CVE-2024-5414 | 2024-05-28 | N/A | 7.1 HIGH | ||
| A vulnerability have been discovered in PhpMyBackupPro affecting version 2.3 that could allow an attacker to execute XSS through /phpmybackuppro/get_file.php, 'view' parameter. This vulnerabilities could allow an attacker to create a specially crafted URL and send it to a victim to retrieve their session details. | |||||
