VYPR

Sharepoint Server

by Microsoft

CVEs (672)

  • CVE-2023-36890MedAug 8, 2023
    risk 0.42cvss 6.5epss 0.02

    Microsoft SharePoint Server Information Disclosure Vulnerability

  • CVE-2023-33142MedJun 14, 2023
    risk 0.42cvss 6.5epss 0.01

    Microsoft SharePoint Server Elevation of Privilege Vulnerability

  • CVE-2023-33129MedJun 14, 2023
    risk 0.42cvss 6.5epss 0.02

    Microsoft SharePoint Server Denial of Service Vulnerability

  • CVE-2023-24954MedMay 9, 2023
    risk 0.42cvss 6.5epss 0.02

    Microsoft SharePoint Server Information Disclosure Vulnerability

  • CVE-2022-41122MedNov 9, 2022
    risk 0.42cvss 6.5epss 0.01

    Microsoft SharePoint Server Spoofing Vulnerability

  • CVE-2020-1103MedMay 21, 2020
    risk 0.42cvss 6.5epss 0.03

    An information disclosure vulnerability exists where certain modes of the search function in Microsoft SharePoint Server are vulnerable to cross-site search attacks (a variant of cross-site request forgery, CSRF).When users are simultaneously logged in to Microsoft SharePoint…

  • CVE-2019-1330MedOct 10, 2019
    risk 0.42cvss 6.5epss 0.03

    An elevation of privilege vulnerability exists in Microsoft SharePoint, aka 'Microsoft SharePoint Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1329.

  • CVE-2019-1260MedSep 11, 2019
    risk 0.42cvss 6.5epss 0.03

    An elevation of privilege vulnerability exists in Microsoft SharePoint, aka 'Microsoft SharePoint Elevation of Privilege Vulnerability'.

  • CVE-2025-21393MedJan 14, 2025
    risk 0.41cvss 6.3epss 0.01

    Microsoft SharePoint Server Spoofing Vulnerability

  • CVE-2023-33132MedJun 14, 2023
    risk 0.41cvss 6.3epss 0.01

    Microsoft SharePoint Server Spoofing Vulnerability

  • CVE-2020-1482MedSep 11, 2020
    risk 0.41cvss 6.3epss 0.02

    A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially crafted request to…

  • CVE-2020-1440MedSep 11, 2020
    risk 0.41cvss 6.3epss 0.02

    A tampering vulnerability exists when Microsoft SharePoint Server fails to properly handle profile data. An attacker who successfully exploited this vulnerability could modify a targeted user's profile data. To exploit the vulnerability, an attacker would need to be…

  • CVE-2011-1252MedJun 16, 2011
    risk 0.41cvss 6.1epss 0.14

    Cross-site scripting (XSS) vulnerability in the SafeHTML function in the toStaticHTML API in Microsoft Internet Explorer 7 and 8, Office SharePoint Server 2007 SP2, Office SharePoint Server 2010 Gold and SP1, Groove Server 2010 Gold and SP1, Windows SharePoint Services 3.0 SP2,…

  • CVE-2023-38177MedNov 14, 2023
    risk 0.40cvss 6.1epss 0.03

    Microsoft SharePoint Server Remote Code Execution Vulnerability

  • CVE-2020-1323MedJun 9, 2020
    risk 0.40cvss 6.1epss 0.02

    An open redirect vulnerability exists in Microsoft SharePoint that could lead to spoofing.To exploit the vulnerability, an attacker could send a link that has a specially crafted URL and convince the user to click the link, aka 'SharePoint Open Redirect Vulnerability'.

  • CVE-2020-1106MedMay 21, 2020
    risk 0.40cvss 6.1epss 0.03

    A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE-2020-1099,…

  • CVE-2019-0670MedMar 5, 2019
    risk 0.40cvss 6.1epss 0.02

    A spoofing vulnerability exists in Microsoft SharePoint when the application does not properly parse HTTP content, aka 'Microsoft SharePoint Spoofing Vulnerability'.

  • CVE-2018-0799MedJan 10, 2018
    risk 0.40cvss 6.1epss 0.04

    Microsoft Access in Microsoft SharePoint Enterprise Server 2013 and Microsoft SharePoint Enterprise Server 2016 allows a cross-site-scripting (XSS) vulnerability due to the way image field values are handled, aka "Microsoft Access Tampering Vulnerability".

  • CVE-2017-0107MedMar 17, 2017
    risk 0.40cvss 6.1epss 0.07

    Microsoft SharePoint Server fails to sanitize crafted web requests, allowing remote attackers to run cross-script in local security context, aka "Microsoft SharePoint XSS Vulnerability."

  • CVE-2015-6117MedJan 13, 2016
    risk 0.40cvss 6.1epss 0.07

    Microsoft SharePoint Server 2013 SP1 and SharePoint Foundation 2013 SP1 allow remote authenticated users to bypass intended Access Control Policy restrictions and conduct cross-site scripting (XSS) attacks by modifying a webpart, aka "Microsoft SharePoint Security Feature…

Page 18 of 34