Home/Product/microsoft dynamics 365
Product

microsoft dynamics 365

97 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-42898
>= 9.1.1.914 and < 9.1.45.11
Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to
9.9CRITICAL
CVE-2026-42833
>= 9.1 and < 9.1.45.11
Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to
9.1CRITICAL
CVE-2026-32210
all versions
Server-side request forgery (ssrf) in Microsoft Dynamics 365 (Online) allows an unauthorized attacker to perform spoofing over a n
9.3CRITICAL
CVE-2026-33103
>= 9.0 and < 9.1.44.15
Improper access control in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to disclose information locally.
5.5MEDIUM
CVE-2025-62211
< 8.8.139.398
Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Field Service (online) allows
8.7HIGH
CVE-2025-62210
< 8.8.139.398
Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Field Service (online) allows
8.7HIGH
CVE-2025-62206
>= 9.1 and < 9.1.41.07
Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an unauthorized attacker
6.5MEDIUM
CVE-2025-55238
all versions
Dynamics 365 FastTrack Implementation Assets Information Disclosure Vulnerability
7.5HIGH
CVE-2025-53728
>= 9.1 and < 9.1.39.04
Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an unauthorized attacker
6.5MEDIUM
CVE-2025-49745
>= 9.1 and < 9.1.38.10
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Dynamics 365 (on-premises) allow
5.4MEDIUM
CVE-2025-49715
all versions
Exposure of private personal information to an unauthorized actor in Dynamics 365 FastTrack Implementation Assets allows an unauth
7.5HIGH
CVE-2024-43476
< 9.1.32
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
7.6HIGH
CVE-2024-38211
all versions
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
8.2HIGH
CVE-2024-38182
all versions
Weak authentication in Microsoft Dynamics 365 allows an unauthenticated attacker to elevate privileges over a network.
9.0CRITICAL
CVE-2024-30061
all versions
Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability
7.3HIGH
CVE-2024-35263
all versions
Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability
5.7MEDIUM
CVE-2024-21419
>= 9.1 and < 9.1.26
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
7.6HIGH
CVE-2024-21396
>= 9.1 and < 9.1.25.17
Dynamics 365 Sales Spoofing Vulnerability
7.6HIGH
CVE-2024-21395
>= 9.1 and < 9.1.25.17
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
8.2HIGH
CVE-2024-21394
>= 9.1 and < 9.1.25.17
Dynamics 365 Field Service Spoofing Vulnerability
7.6HIGH
CVE-2024-21393
>= 9.1 and < 9.1.25.17
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
7.6HIGH
CVE-2024-21389
>= 9.1 and < 9.1.25.17
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
7.6HIGH
CVE-2024-21328
>= 9.1 and < 9.1.25.17
Dynamics 365 Sales Spoofing Vulnerability
7.6HIGH
CVE-2024-21327
>= 9.1 and < 9.1.25.17
Microsoft Dynamics 365 Customer Engagement Cross-Site Scripting Vulnerability
7.6HIGH
CVE-2023-36020
>= 9.0 and < 9.0.51.06
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
7.6HIGH
CVE-2023-35621
all versions
Microsoft Dynamics 365 Finance and Operations Denial of Service Vulnerability
7.5HIGH
CVE-2023-36410
>= 9.1 and < 9.1.23.10
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
7.6HIGH
CVE-2023-36031
>= 9.1 and < 9.1.23.10
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
7.6HIGH
CVE-2023-36030
>= 9.0 and < 9.0.51.06
Microsoft Dynamics 365 Sales Spoofing Vulnerability
6.1MEDIUM
CVE-2023-36016
>= 9.0 and < 9.0.51.06
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
6.2MEDIUM
CVE-2023-36433
>= 9.0 and < 9.0.49.04
Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability
6.5MEDIUM
CVE-2023-36429
>= 9.0 and < 9.0.50.03
Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability
6.5MEDIUM
CVE-2023-36416
>= 9.0 and < 9.0.47.08
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
6.1MEDIUM
CVE-2023-38164
>= 9.0 and < 9.0.49.04
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
7.6HIGH
CVE-2023-36886
>= 9.0 and < 9.0.49.04
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
7.6HIGH
CVE-2023-36800
< 10.0.1695
Dynamics Finance and Operations Cross-site Scripting Vulnerability
7.6HIGH
CVE-2023-35389
>= 9.0 and < 9.0.47.08
Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability
6.5MEDIUM
CVE-2023-24896
< 10.0.32
Dynamics 365 Finance Spoofing Vulnerability
5.4MEDIUM
CVE-2023-35335
>= 9.0 and < 9.0.47.08
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
8.2HIGH
CVE-2023-33171
>= 9.0 and < 9.0.47.08
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
8.2HIGH
CVE-2023-28314
>= 9.0 and < 9.0.46.15
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
6.1MEDIUM
CVE-2023-28309
>= 9.0 and < 9.0.46.15
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
7.6HIGH
CVE-2023-24922
>= 9.0 and < 9.0.45.11
Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability
6.5MEDIUM
CVE-2023-24921
>= 9.0 and < 9.0.45.11
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
5.4MEDIUM
CVE-2023-24920
>= 9.0 and < 9.0.45.11
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
5.4MEDIUM
CVE-2023-24919
>= 9.0 and < 9.0.45.11
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
5.4MEDIUM
CVE-2023-24891
>= 9.0 and < 9.0.45.11
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
5.4MEDIUM
CVE-2023-24879
>= 9.0 and < 9.0.45.11
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
5.4MEDIUM
CVE-2023-21778
< 4.2.0.51
Microsoft Dynamics Unified Service Desk Remote Code Execution Vulnerability
8.0HIGH
CVE-2023-21807
> 9.0 and < 9.0.45.11
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
6.5MEDIUM
CVE-2023-21573
> 9.0 and < 9.0.45.11
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
5.4MEDIUM
CVE-2023-21572
> 9.0 and < 9.0.45.11
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
6.5MEDIUM
CVE-2023-21571
> 9.0 and < 9.0.45.11
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
5.4MEDIUM
CVE-2023-21570
>= 9.0 and < 9.0.45.11
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
5.4MEDIUM
CVE-2022-35805
all versions
Microsoft Dynamics CRM (on-premises) Remote Code Execution Vulnerability
8.8HIGH
CVE-2022-34700
all versions
Microsoft Dynamics CRM (on-premises) Remote Code Execution Vulnerability
8.8HIGH
CVE-2022-23259
all versions
Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability
8.8HIGH
CVE-2022-21957
all versions
Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability
7.2HIGH
CVE-2022-21932
all versions
Microsoft Dynamics 365 Customer Engagement Cross-Site Scripting Vulnerability
7.6HIGH
CVE-2021-42316
all versions
Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability
8.8HIGH
CVE-2021-41354
all versions
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
5.4MEDIUM
CVE-2021-41353
all versions
Microsoft Dynamics 365 (on-premises) Spoofing Vulnerability
5.4MEDIUM
CVE-2021-40457
all versions
Microsoft Dynamics 365 Customer Engagement Cross-Site Scripting Vulnerability
7.4HIGH
CVE-2021-36950
all versions
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
5.4MEDIUM
CVE-2021-34524
all versions
Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability
8.1HIGH
CVE-2021-28461
all versions
Dynamics Finance and Operations Cross-site Scripting Vulnerability
6.1MEDIUM
CVE-2021-24101
all versions
Microsoft Dataverse Information Disclosure Vulnerability
6.5MEDIUM
CVE-2020-17158
< 10.0.11
Microsoft Dynamics 365 for Finance and Operations (on-premises) Remote Code Execution Vulnerability
8.8HIGH
CVE-2020-17152
< 10.0.11
Microsoft Dynamics 365 for Finance and Operations (on-premises) Remote Code Execution Vulnerability
8.8HIGH
CVE-2020-17147
all versions
Dynamics CRM Webclient Cross-site Scripting Vulnerability
8.7HIGH
CVE-2020-17021
all versions
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
5.4MEDIUM
CVE-2020-17018
all versions
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
5.4MEDIUM
CVE-2020-17005
all versions
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
5.4MEDIUM
CVE-2020-16978
all versions
<p>A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially cr
5.4MEDIUM
CVE-2020-16956
all versions
<p>A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially cr
5.4MEDIUM
CVE-2020-16943
all versions
<p>An elevation of privilege vulnerability exists in Microsoft Dynamics 365 Commerce. An unauthenticated attacker who successfully
6.5MEDIUM
CVE-2020-16878
all versions
<p>A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially cr
5.4MEDIUM
CVE-2020-16872
all versions
<p>A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially cr
7.6HIGH
CVE-2020-16871
all versions
<p>A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially cr
5.4MEDIUM
CVE-2020-16864
all versions
<p>A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially cr
5.4MEDIUM
CVE-2020-16862
all versions
<p>A remote code execution vulnerability exists in Microsoft Dynamics 365 (on-premises) when the server fails to properly sanitize
7.1HIGH
CVE-2020-16861
all versions
<p>A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially cr
5.4MEDIUM
CVE-2020-16860
all versions
<p>A remote code execution vulnerability exists in Microsoft Dynamics 365 (on-premises) when the server fails to properly sanitize
6.8MEDIUM
CVE-2020-16859
all versions
<p>A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially cr
5.4MEDIUM
CVE-2020-16858
all versions
<p>A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially cr
5.4MEDIUM
CVE-2020-1591
all versions
A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially craft
5.4MEDIUM
CVE-2020-1063
all versions
A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially craft
5.4MEDIUM
CVE-2018-8654
all versions
An elevation of privilege vulnerability exists in Microsoft Dynamics 365 Server, aka 'Microsoft Dynamics 365 Elevation of Privileg
6.5MEDIUM
CVE-2020-0656
all versions
A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially craft
5.4MEDIUM
CVE-2019-1375
>= 9.0 and < 9.0.9.4
A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially craft
5.4MEDIUM
CVE-2019-1229
all versions
An elevation of privilege vulnerability exists in Dynamics On-Premise v9. An attacker who successfully exploited the vulnerability
8.8HIGH
CVE-2019-1008
all versions
A security feature bypass vulnerability exists in Dynamics On Premise, aka 'Microsoft Dynamics On-Premise Security Feature Bypass'
5.9MEDIUM
CVE-2018-8609
>= 8.0 and < 8.2.3.0003
A remote code execution vulnerability exists in Microsoft Dynamics 365 (on-premises) version 8 when the server fails to properly s
8.8HIGH
CVE-2018-8608
>= 8.0 and < 8.2.3.0003
A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) version 8 does not properly sanitize a speci
5.4MEDIUM
CVE-2018-8607
>= 8.0 and < 8.2.3.0003
A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) version 8 does not properly sanitize a speci
5.4MEDIUM
CVE-2018-8606
>= 8.0 and < 8.2.3.0003
A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) version 8 does not properly sanitize a speci
5.4MEDIUM
CVE-2018-8605
>= 8.0 and < 8.2.3.0003
A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) version 8 does not properly sanitize a speci
5.4MEDIUM
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin