CVE Tools

Microsoft Dynamics Nav

10 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Microsoft Dynamics Nav, a product in the enterprise software space. Use it to gauge the current risk picture and drill into individual advisories.

Microsoft Dynamics Nav CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Microsoft Dynamics Nav CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-110
2025-120
2026-010
2026-020
2026-030
2026-040
2026-050
2026-060
2026-070
2026-080
2026-090

Severity

How the 10 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • High440%
  • Medium660%

Latest CVEs

The 10 most recently published vulnerabilities affecting Microsoft Dynamics Nav.

  1. CVE-2022-41127Microsoft Dynamics NAV and Microsoft Dynamics 365 Business Central (On Premises) Remote Code Execution Vulnerability8.5
  2. CVE-2022-41066Microsoft Dynamics Business Central Information Disclosure Vulnerability4.4
  3. CVE-2021-36946Microsoft Dynamics Business Central Cross-site Scripting Vulnerability5.4
  4. CVE-2021-1724Microsoft Dynamics Business Central Cross-site Scripting Vulnerability6.1
  5. CVE-2020-17133Microsoft Dynamics Business Central/NAV Information Disclosure Vulnerability6.5
  6. CVE-2020-1022A remote code execution vulnerability exists in Microsoft Dynamics Business Central, aka 'Dynamics Business Central Remote Code Execution Vulnerability'.8.0
  7. CVE-2020-1018An information disclosure vulnerability exists when Microsoft Dynamics Business Central/NAV on-premise does not properly hide the value of a masked field when showing the records as a chart page.Th...7.5
  8. CVE-2020-0905An remote code execution vulnerability exists in Microsoft Dynamics Business Central, aka 'Dynamics Business Central Remote Code Execution Vulnerability'.8.0
  9. CVE-2019-19616An Insecure Direct Object Reference (IDOR) vulnerability in the Xtivia Web Time and Expense (WebTE) interface used for Microsoft Dynamics NAV before 2017 allows an attacker to download arbitrary fi...4.3
  10. CVE-2018-8651A cross site scripting vulnerability exists when Microsoft Dynamics NAV does not properly sanitize a specially crafted web request to an affected Dynamics NAV server, aka "Microsoft Dynamics NAV Cr...5.4

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store