CVEs (9)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Improper input validation in Power BI allows an authorized attacker to execute code over a network. |
Power BI Report Server Spoofing Vulnerability |
Power BI Report Server Spoofing Vulnerability |
Power BI Report Server Spoofing Vulnerability |
1Microsoft 1Power Bi Report Server Jun 17, 2026 Nov 10, 2021 N/A· v4 9.6 CRITICAL· v3 6.8 MEDIUM· v2 A Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) vulnerability exists when Power BI Report Server Template file (pbix) containing HTML files is uploaded to the server and HTML files are accessed directl...Show more |
1Microsoft 1Power Bi Report Server Jun 17, 2026 Jul 14, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Power BI Remote Code Execution Vulnerability |
1Microsoft 1Power Bi Report Server Jun 17, 2026 Mar 11, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Microsoft Power BI Information Disclosure Vulnerability |
1Microsoft 1Power Bi Report Server Jun 17, 2026 May 21, 2020 N/A· v4 6.8 MEDIUM· v3 3.5 LOW· v2 A spoofing vulnerability exists in Microsoft Power BI Report Server in the way it validates the content-type of uploaded attachments, aka 'Microsoft Power BI Report Server Spoofing Vulnerability'. |
1Microsoft 3Power Bi Report Server Sql Server 2017 Reporting ServicesSql Server 2019 Reporting ServicesJun 17, 2026 Dec 10, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A cross-site scripting (XSS) vulnerability exists when Microsoft SQL Server Reporting Services (SSRS) does not properly sanitize a specially-crafted web request to an affected SSRS server, aka 'Microsoft SQL Server Repor...Show more |