VYPR

Sharepoint Server

by Microsoft

CVEs (672)

  • CVE-2021-43242HigDec 15, 2021
    risk 0.49cvss 7.6epss 0.01

    Microsoft SharePoint Server Spoofing Vulnerability

  • CVE-2021-38652HigSep 15, 2021
    risk 0.49cvss 7.6epss 0.01

    Microsoft SharePoint Server Spoofing Vulnerability

  • CVE-2021-38651HigSep 15, 2021
    risk 0.49cvss 7.6epss 0.01

    Microsoft SharePoint Server Spoofing Vulnerability

  • CVE-2019-1006HigJul 15, 2019
    risk 0.49cvss 7.5epss 0.06

    An authentication bypass vulnerability exists in Windows Communication Foundation (WCF) and Windows Identity Foundation (WIF), allowing signing of SAML tokens with arbitrary symmetric keys, aka 'WCF/WIF SAML Token Authentication Bypass Vulnerability'.

  • CVE-2016-0025HigJun 16, 2016
    risk 0.49cvss 7.3epss 0.15

    Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Office 2016, Word 2016, Word for Mac 2011, Word 2016 for Mac, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2010 SP2, Word Automation Services on SharePoint…

  • CVE-2025-30384HigMay 13, 2025
    risk 0.48cvss 7.4epss 0.01

    Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally.

  • CVE-2025-29793HigApr 8, 2025
    risk 0.48cvss 7.2epss 0.22

    Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

  • CVE-2024-49070HigDec 12, 2024
    risk 0.48cvss 7.4epss 0.02

    Microsoft SharePoint Remote Code Execution Vulnerability

  • CVE-2023-36762HigSep 12, 2023
    risk 0.48cvss 7.3epss 0.01

    Microsoft Word Remote Code Execution Vulnerability

  • CVE-2023-33130HigJun 14, 2023
    risk 0.48cvss 7.3epss 0.01

    Microsoft SharePoint Server Spoofing Vulnerability

  • CVE-2023-24950MedMay 9, 2023
    risk 0.48cvss 6.5epss 0.67

    Microsoft SharePoint Server Spoofing Vulnerability

  • CVE-2020-1345HigSep 11, 2020
    risk 0.48cvss 7.4epss 0.03

    A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially crafted request to…

  • CVE-2020-1198HigSep 11, 2020
    risk 0.48cvss 7.4epss 0.03

    A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially crafted request to…

  • CVE-2016-7291HigDec 20, 2016
    risk 0.48cvss 7.1epss 0.23

    Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Office Compatibility Pack SP3, Word for Mac 2011, Word Automation Services on SharePoint Server 2010 SP2, and Office Web Apps 2010 SP2 allow remote attackers to obtain sensitive information from process memory or cause a…

  • CVE-2016-7290HigDec 20, 2016
    risk 0.48cvss 7.1epss 0.23

    Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Office Compatibility Pack SP3, Word for Mac 2011, Word Automation Services on SharePoint Server 2010 SP2, and Office Web Apps 2010 SP2 allow remote attackers to obtain sensitive information from process memory or cause a…

  • CVE-2016-7268HigDec 20, 2016
    risk 0.48cvss 7.1epss 0.23

    Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Office Compatibility Pack SP3, Word Viewer, Word for Mac 2011, Word Automation Services on SharePoint Server 2010 SP2, and Office Web Apps 2010 SP2 allow remote attackers to obtain sensitive information from process memory…

  • CVE-2016-7265HigDec 20, 2016
    risk 0.48cvss 7.1epss 0.23

    Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Office Compatibility Pack SP3, Excel Viewer, Excel Services on SharePoint Server 2007 SP3, and Excel Services on SharePoint Server 2010 SP2 allow remote attackers to obtain sensitive…

  • CVE-2026-70355HigAug 11, 2026
    risk 0.47cvss 7.3epss 0.00

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-64900HigAug 11, 2026
    risk 0.47cvss 7.3epss 0.00

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

  • CVE-2026-47634HigJun 9, 2026
    risk 0.47cvss 7.3epss 0.01

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Page 15 of 34