VendorsMicrosoftpower_bi_report_serverall versions
Vulnerabilities

Microsoft Power BI Report Server

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

11CVEs
CVE-2021-41372
Power BI Report Server Spoofing Vulnerability
Published 2021-11-10 · Modified
9.6EPSS 0.007
CVE-2021-31984
Power BI Remote Code Execution Vulnerability
Published 2021-07-14 · Modified
8.8EPSS 0.019
CVE-2024-43481
Power BI Report Server Spoofing Vulnerability
Published 2024-10-08 · Analyzed
8.8EPSS 0.018
CVE-2026-65811
Power BI Remote Code Execution Vulnerability
Published 2026-08-11 · Analyzed
8.8EPSS 0.010
CVE-2026-21229
Power BI Remote Code Execution Vulnerability
Published 2026-02-10 · Analyzed
8.8EPSS 0.009
CVE-2023-21806
Power BI Report Server Spoofing Vulnerability
Published 2023-02-14 · Modified
8.2EPSS 0.008
CVE-2026-58647
Microsoft PowerBI Report Server Spoofing Vulnerability
Published 2026-07-14 · Analyzed
8.0EPSS 0.005
CVE-2021-26859
Microsoft Power BI Information Disclosure Vulnerability
Published 2021-03-11 · Modified
7.7EPSS 0.030
CVE-2024-43612
Power BI Report Server Spoofing Vulnerability
Published 2024-10-08 · Analyzed
6.9EPSS 0.007
CVE-2020-1173
A spoofing vulnerability exists in Microsoft Power BI Report Server in the way it validates the content-type of uploaded attachments, aka 'Microsoft Power BI Report Server Spoofing Vulnerability'.
Published 2020-05-21 · Modified
6.8EPSS 0.025
CVE-2019-1332
A cross-site scripting (XSS) vulnerability exists when Microsoft SQL Server Reporting Services (SSRS) does not properly sanitize a specially-crafted web request to an affected SSRS server, aka 'Microsoft SQL Server Reporting Services XSS Vulnerability'.
Published 2019-12-10 · Modified
6.1EPSS 0.087