📦 Dynamics 365

by Microsoft

🔍 What is Dynamics 365?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-38182

CRITICAL CVSS 9.0 Jul 31, 2024

This vulnerability in Microsoft Dynamics 365 allows unauthenticated attackers to bypass authentication mechanisms and gain elevated privileges over the network. Organizations using affected versions o...

CVE-2025-62210

HIGH CVSS 8.7 Nov 11, 2025

This cross-site scripting (XSS) vulnerability in Dynamics 365 Field Service allows authenticated attackers to inject malicious scripts into web pages. When exploited, it enables spoofing attacks where...

CVE-2025-62211

HIGH CVSS 8.7 Nov 11, 2025

This cross-site scripting (XSS) vulnerability in Dynamics 365 Field Service allows authenticated attackers to inject malicious scripts into web pages. When exploited, it enables spoofing attacks where...

CVE-2025-55238

HIGH CVSS 7.5 Sep 4, 2025

This vulnerability in Dynamics 365 FastTrack Implementation Assets allows unauthorized access to sensitive information. It affects organizations using Microsoft Dynamics 365 with FastTrack implementat...

CVE-2025-49715

HIGH CVSS 7.5 Jun 20, 2025

This vulnerability in Dynamics 365 FastTrack Implementation Assets allows unauthorized attackers to access private personal information over the network. It affects organizations using Microsoft Dynam...

CVE-2024-38211

HIGH CVSS 8.2 Aug 13, 2024

This vulnerability allows attackers to inject malicious scripts into Microsoft Dynamics 365 (on-premises) web pages, which are then executed in victims' browsers when they view those pages. It affects...

CVE-2024-21419

HIGH CVSS 7.6 Mar 12, 2024

This is a cross-site scripting (XSS) vulnerability in Microsoft Dynamics 365 on-premises deployments that allows attackers to inject malicious scripts into web pages viewed by other users. When exploi...

CVE-2024-21393

HIGH CVSS 7.6 Feb 13, 2024

This is a cross-site scripting (XSS) vulnerability in Microsoft Dynamics 365 on-premises that allows attackers to inject malicious scripts into web pages viewed by other users. Attackers could steal s...

CVE-2024-21395

HIGH CVSS 8.2 Feb 13, 2024

This vulnerability allows attackers to inject malicious scripts into Microsoft Dynamics 365 (on-premises) web pages, which are then executed in victims' browsers when they view those pages. It affects...

CVE-2024-21389

HIGH CVSS 7.6 Feb 13, 2024

This vulnerability allows attackers to inject malicious scripts into Microsoft Dynamics 365 (on-premises) web pages, which are then executed in victims' browsers when they view those pages. It affects...

CVE-2024-21328

HIGH CVSS 7.6 Feb 13, 2024

CVE-2024-21328 is a cross-site scripting (XSS) vulnerability in Microsoft Dynamics 365 Sales that allows attackers to inject malicious scripts into web pages viewed by other users. This affects organi...

CVE-2023-35621

HIGH CVSS 7.5 Dec 12, 2023

This vulnerability in Microsoft Dynamics 365 Finance and Operations allows attackers to cause a denial of service (DoS) condition by sending specially crafted requests to the application. Organization...

CVE-2023-36410

HIGH CVSS 7.6 Nov 14, 2023

This is a cross-site scripting (XSS) vulnerability in Microsoft Dynamics 365 on-premises that allows attackers to inject malicious scripts into web pages viewed by other users. It affects organization...

CVE-2023-36886

HIGH CVSS 7.6 Sep 12, 2023

This is a cross-site scripting (XSS) vulnerability in Microsoft Dynamics 365 on-premises that allows attackers to inject malicious scripts into web pages viewed by other users. Attackers could steal s...

CVE-2023-36800

HIGH CVSS 7.6 Sep 12, 2023

This is a cross-site scripting (XSS) vulnerability in Microsoft Dynamics 365 Finance and Operations that allows attackers to inject malicious scripts into web pages viewed by other users. When exploit...

CVE-2023-28309

HIGH CVSS 7.6 Apr 11, 2023

This vulnerability allows attackers to inject malicious scripts into Microsoft Dynamics 365 (on-premises) web pages, which are then executed in victims' browsers when they view those pages. It affects...

CVE-2023-21778

HIGH CVSS 8.0 Feb 14, 2023

This vulnerability allows remote attackers to execute arbitrary code on Microsoft Dynamics Unified Service Desk servers by sending specially crafted requests. It affects organizations using Microsoft ...

CVE-2022-23259

HIGH CVSS 8.8 Apr 15, 2022

This vulnerability allows remote attackers to execute arbitrary code on Microsoft Dynamics 365 On-Premises servers without authentication. It affects organizations running vulnerable versions of Dynam...

CVE-2022-21957

HIGH CVSS 7.2 Feb 9, 2022

This vulnerability allows remote attackers to execute arbitrary code on Microsoft Dynamics 365 On-Premises servers. Attackers can exploit this without authentication to gain full control of affected s...

CVE-2022-21932

HIGH CVSS 7.6 Jan 11, 2022

This is a cross-site scripting (XSS) vulnerability in Microsoft Dynamics 365 Customer Engagement that allows attackers to inject malicious scripts into web pages viewed by other users. It affects orga...

CVE-2021-42316

HIGH CVSS 8.8 Nov 10, 2021

CVE-2021-42316 is a remote code execution vulnerability in Microsoft Dynamics 365 On-Premises that allows authenticated attackers to execute arbitrary code on affected servers. This affects organizati...

CVE-2021-40457

HIGH CVSS 7.4 Oct 13, 2021

CVE-2021-40457 is a cross-site scripting (XSS) vulnerability in Microsoft Dynamics 365 Customer Engagement that allows attackers to inject malicious scripts into web pages viewed by other users. This ...

CVE-2021-34524

HIGH CVSS 8.1 Aug 12, 2021

This vulnerability allows an authenticated attacker to execute arbitrary code on Microsoft Dynamics 365 On-Premises servers by sending specially crafted requests. It affects organizations running vuln...

CVE-2020-16862

HIGH CVSS 7.1 Sep 11, 2020

This is a remote code execution vulnerability in Microsoft Dynamics 365 (on-premises) where improper input sanitization allows authenticated attackers to execute arbitrary code. The vulnerability affe...

CVE-2020-16872

HIGH CVSS 7.6 Sep 11, 2020

This is a cross-site scripting (XSS) vulnerability in Microsoft Dynamics 365 (on-premises) that allows authenticated attackers to inject malicious scripts into web requests. When exploited, these scri...

CVE-2019-1229

HIGH CVSS 8.8 Aug 14, 2019

This is an elevation of privilege vulnerability in Microsoft Dynamics On-Premise v9 that allows authenticated users with customizer privileges to execute arbitrary code on the Web Role server. Attacke...

CVE-2025-62206

MEDIUM CVSS 6.5 Nov 11, 2025

This vulnerability in Microsoft Dynamics 365 (on-premises) allows unauthorized attackers to access sensitive information over the network. Attackers can exploit this to view confidential data without ...

CVE-2025-53728

MEDIUM CVSS 6.5 Aug 12, 2025

This vulnerability in Microsoft Dynamics 365 (on-premises) allows unauthorized attackers to access sensitive information over the network. Attackers can exploit this to disclose confidential data stor...

CVE-2025-49745

MEDIUM CVSS 5.4 Aug 12, 2025

This cross-site scripting (XSS) vulnerability in Microsoft Dynamics 365 (on-premises) allows attackers to inject malicious scripts into web pages. When exploited, it enables spoofing attacks where use...

CVE-2024-35263

MEDIUM CVSS 5.7 Jun 11, 2024

This vulnerability in Microsoft Dynamics 365 (On-Premises) allows an authenticated attacker to access sensitive information they shouldn't have permission to view. It affects organizations running on-...

CVE-2020-16978

MEDIUM CVSS 5.4 Oct 16, 2020

This is a cross-site scripting (XSS) vulnerability in Microsoft Dynamics 365 (on-premises) that allows authenticated attackers to inject malicious scripts into web requests. When exploited, these scri...

CVE-2020-16956

MEDIUM CVSS 5.4 Oct 16, 2020

This is a cross-site scripting (XSS) vulnerability in Microsoft Dynamics 365 (on-premises) that allows authenticated attackers to inject malicious scripts into web requests. When exploited, these scri...

CVE-2020-16943

MEDIUM CVSS 6.5 Oct 16, 2020

CVE-2020-16943 is an elevation of privilege vulnerability in Microsoft Dynamics 365 Commerce that allows unauthenticated attackers to update data without proper authorization by sending specially craf...

CVE-2020-16860

MEDIUM CVSS 6.8 Sep 11, 2020

This is a remote code execution vulnerability in Microsoft Dynamics 365 (on-premises) where improper input sanitization allows authenticated attackers to execute arbitrary code. The vulnerability affe...

CVE-2020-16871

MEDIUM CVSS 5.4 Sep 11, 2020

This is a cross-site scripting (XSS) vulnerability in Microsoft Dynamics 365 on-premises that allows authenticated attackers to inject malicious scripts. When exploited, these scripts execute with the...

CVE-2020-16878

MEDIUM CVSS 5.4 Sep 11, 2020

This is a cross-site scripting (XSS) vulnerability in Microsoft Dynamics 365 (on-premises) that allows authenticated attackers to inject malicious scripts into web requests. When exploited, these scri...

CVE-2020-16858

MEDIUM CVSS 5.4 Sep 11, 2020

This is a cross-site scripting (XSS) vulnerability in Microsoft Dynamics 365 (on-premises) that allows authenticated attackers to inject malicious scripts into web requests. When exploited, these scri...

CVE-2020-1591

MEDIUM CVSS 5.4 Aug 17, 2020

This is a cross-site scripting (XSS) vulnerability in Microsoft Dynamics 365 (on-premises) where improper input sanitization allows authenticated attackers to inject malicious scripts. Successful expl...