Vulnerabilities > Microsoft > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-08-06 CVE-2024-38166 Cross-site Scripting vulnerability in Microsoft Dynamics CRM Service Portal web Resource
An unauthenticated attacker can exploit improper neutralization of input during web page generation in Microsoft Dynamics 365 to spoof over a network by tricking a user to click on a link.
network
low complexity
microsoft CWE-79
6.1
2024-08-06 CVE-2024-38206 Server-Side Request Forgery (SSRF) vulnerability in Microsoft Copilot Studio
An authenticated attacker can bypass Server-Side Request Forgery (SSRF) protection in Microsoft Copilot Studio to leak sensitive information over a network.
network
low complexity
microsoft CWE-918
6.5
2024-07-25 CVE-2024-38103 Unspecified vulnerability in Microsoft Edge
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
network
high complexity
microsoft
5.9
2024-06-13 CVE-2024-30472 Unspecified vulnerability in Microsoft Telemetry Dashboard 1.0.0.8
Telemetry Dashboard v1.0.0.8 for Dell ThinOS 2402 contains a sensitive information disclosure vulnerability.
local
low complexity
microsoft
5.5
2024-05-25 CVE-2024-30056 Unspecified vulnerability in Microsoft Edge Chromium
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
network
low complexity
microsoft
5.4
2024-05-14 CVE-2024-30047 Cross-site Scripting vulnerability in Microsoft Dynamics 365 Customer Insights
Dynamics 365 Customer Insights Spoofing Vulnerability
network
low complexity
microsoft CWE-79
4.1
2024-05-14 CVE-2024-30048 Cross-site Scripting vulnerability in Microsoft Dynamics 365 Customer Insights
Dynamics 365 Customer Insights Spoofing Vulnerability
network
low complexity
microsoft CWE-79
4.1
2024-05-14 CVE-2024-30053 Cross-site Scripting vulnerability in Microsoft Azure Migrate
Azure Migrate Cross-Site Scripting Vulnerability
network
low complexity
microsoft CWE-79
5.4
2024-05-14 CVE-2024-30059 Unspecified vulnerability in Microsoft Intune Mobile Application Management
Microsoft Intune for Android Mobile Application Management Tampering Vulnerability
local
low complexity
microsoft
5.5
2024-04-09 CVE-2024-29063 Unspecified vulnerability in Microsoft Azure AI Search
Azure AI Search Information Disclosure Vulnerability
local
low complexity
microsoft
5.5