CVE-2026-65811
- EPSS 0.51%
- Veröffentlicht 11.08.2026 17:05:03
- Zuletzt bearbeitet 19.08.2026 17:20:25
Improper input validation in Power BI allows an authorized attacker to execute code over a network.
CVE-2026-58647
- EPSS 0.35%
- Veröffentlicht 14.07.2026 17:05:38
- Zuletzt bearbeitet 19.08.2026 17:19:47
Improper neutralization of input during web page generation ('cross-site scripting') in Power BI allows an authorized attacker to perform spoofing over a network.
CVE-2026-21229
- EPSS 0.9%
- Veröffentlicht 10.02.2026 18:16:23
- Zuletzt bearbeitet 19.08.2026 17:18:41
Improper input validation in Power BI allows an authorized attacker to execute code over a network.
CVE-2024-43612
- EPSS 0.69%
- Veröffentlicht 08.10.2024 18:15:29
- Zuletzt bearbeitet 19.08.2026 17:18:34
Power BI Report Server Spoofing Vulnerability
CVE-2024-43481
- EPSS 1.83%
- Veröffentlicht 08.10.2024 18:15:10
- Zuletzt bearbeitet 19.08.2026 17:18:24
Power BI Report Server Spoofing Vulnerability
CVE-2023-21806
- EPSS 0.78%
- Veröffentlicht 14.02.2023 20:15:15
- Zuletzt bearbeitet 19.08.2026 17:18:17
Power BI Report Server Spoofing Vulnerability
CVE-2021-41372
- EPSS 0.64%
- Veröffentlicht 10.11.2021 01:19:30
- Zuletzt bearbeitet 19.08.2026 17:17:56
A Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) vulnerability exists when Power BI Report Server Template file (pbix) containing HTML files is uploaded to the server and HTML files are accessed directly by the victim. Combining the...
CVE-2021-31984
- EPSS 1.93%
- Veröffentlicht 14.07.2021 18:15:09
- Zuletzt bearbeitet 10.08.2026 16:17:36
Power BI Remote Code Execution Vulnerability
- EPSS 3.04%
- Veröffentlicht 11.03.2021 16:15:13
- Zuletzt bearbeitet 19.08.2026 17:17:38
Microsoft Power BI Information Disclosure Vulnerability
CVE-2020-1173
- EPSS 2.46%
- Veröffentlicht 21.05.2020 23:15:17
- Zuletzt bearbeitet 19.08.2026 17:17:28
A spoofing vulnerability exists in Microsoft Power BI Report Server in the way it validates the content-type of uploaded attachments. An authenticated attacker could exploit the vulnerability by uploading a specially crafted payload and sending it to...