Sharepoint Server
by Microsoft
CVEs (672)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-36890 | Med | 0.42 | 6.5 | 0.02 | Aug 8, 2023 | Microsoft SharePoint Server Information Disclosure Vulnerability | ||
| CVE-2023-33142 | Med | 0.42 | 6.5 | 0.01 | Jun 14, 2023 | Microsoft SharePoint Server Elevation of Privilege Vulnerability | ||
| CVE-2023-33129 | Med | 0.42 | 6.5 | 0.02 | Jun 14, 2023 | Microsoft SharePoint Server Denial of Service Vulnerability | ||
| CVE-2023-24954 | Med | 0.42 | 6.5 | 0.02 | May 9, 2023 | Microsoft SharePoint Server Information Disclosure Vulnerability | ||
| CVE-2022-41122 | Med | 0.42 | 6.5 | 0.01 | Nov 9, 2022 | Microsoft SharePoint Server Spoofing Vulnerability | ||
| CVE-2020-1103 | Med | 0.42 | 6.5 | 0.03 | May 21, 2020 | An information disclosure vulnerability exists where certain modes of the search function in Microsoft SharePoint Server are vulnerable to cross-site search attacks (a variant of cross-site request forgery, CSRF).When users are simultaneously logged in to Microsoft SharePoint… | ||
| CVE-2019-1330 | Med | 0.42 | 6.5 | 0.03 | Oct 10, 2019 | An elevation of privilege vulnerability exists in Microsoft SharePoint, aka 'Microsoft SharePoint Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1329. | ||
| CVE-2019-1260 | Med | 0.42 | 6.5 | 0.03 | Sep 11, 2019 | An elevation of privilege vulnerability exists in Microsoft SharePoint, aka 'Microsoft SharePoint Elevation of Privilege Vulnerability'. | ||
| CVE-2025-21393 | Med | 0.41 | 6.3 | 0.01 | Jan 14, 2025 | Microsoft SharePoint Server Spoofing Vulnerability | ||
| CVE-2023-33132 | Med | 0.41 | 6.3 | 0.01 | Jun 14, 2023 | Microsoft SharePoint Server Spoofing Vulnerability | ||
| CVE-2020-1482 | Med | 0.41 | 6.3 | 0.02 | Sep 11, 2020 | A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially crafted request to… | ||
| CVE-2020-1440 | Med | 0.41 | 6.3 | 0.02 | Sep 11, 2020 | A tampering vulnerability exists when Microsoft SharePoint Server fails to properly handle profile data. An attacker who successfully exploited this vulnerability could modify a targeted user's profile data. To exploit the vulnerability, an attacker would need to be… | ||
| CVE-2011-1252 | Med | 0.41 | 6.1 | 0.14 | Jun 16, 2011 | Cross-site scripting (XSS) vulnerability in the SafeHTML function in the toStaticHTML API in Microsoft Internet Explorer 7 and 8, Office SharePoint Server 2007 SP2, Office SharePoint Server 2010 Gold and SP1, Groove Server 2010 Gold and SP1, Windows SharePoint Services 3.0 SP2,… | ||
| CVE-2023-38177 | Med | 0.40 | 6.1 | 0.03 | Nov 14, 2023 | Microsoft SharePoint Server Remote Code Execution Vulnerability | ||
| CVE-2020-1323 | Med | 0.40 | 6.1 | 0.02 | Jun 9, 2020 | An open redirect vulnerability exists in Microsoft SharePoint that could lead to spoofing.To exploit the vulnerability, an attacker could send a link that has a specially crafted URL and convince the user to click the link, aka 'SharePoint Open Redirect Vulnerability'. | ||
| CVE-2020-1106 | Med | 0.40 | 6.1 | 0.03 | May 21, 2020 | A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE-2020-1099,… | ||
| CVE-2019-0670 | Med | 0.40 | 6.1 | 0.02 | Mar 5, 2019 | A spoofing vulnerability exists in Microsoft SharePoint when the application does not properly parse HTTP content, aka 'Microsoft SharePoint Spoofing Vulnerability'. | ||
| CVE-2018-0799 | Med | 0.40 | 6.1 | 0.04 | Jan 10, 2018 | Microsoft Access in Microsoft SharePoint Enterprise Server 2013 and Microsoft SharePoint Enterprise Server 2016 allows a cross-site-scripting (XSS) vulnerability due to the way image field values are handled, aka "Microsoft Access Tampering Vulnerability". | ||
| CVE-2017-0107 | Med | 0.40 | 6.1 | 0.07 | Mar 17, 2017 | Microsoft SharePoint Server fails to sanitize crafted web requests, allowing remote attackers to run cross-script in local security context, aka "Microsoft SharePoint XSS Vulnerability." | ||
| CVE-2015-6117 | Med | 0.40 | 6.1 | 0.07 | Jan 13, 2016 | Microsoft SharePoint Server 2013 SP1 and SharePoint Foundation 2013 SP1 allow remote authenticated users to bypass intended Access Control Policy restrictions and conduct cross-site scripting (XSS) attacks by modifying a webpart, aka "Microsoft SharePoint Security Feature… |
- risk 0.42cvss 6.5epss 0.02
Microsoft SharePoint Server Information Disclosure Vulnerability
- risk 0.42cvss 6.5epss 0.01
Microsoft SharePoint Server Elevation of Privilege Vulnerability
- risk 0.42cvss 6.5epss 0.02
Microsoft SharePoint Server Denial of Service Vulnerability
- risk 0.42cvss 6.5epss 0.02
Microsoft SharePoint Server Information Disclosure Vulnerability
- risk 0.42cvss 6.5epss 0.01
Microsoft SharePoint Server Spoofing Vulnerability
- risk 0.42cvss 6.5epss 0.03
An information disclosure vulnerability exists where certain modes of the search function in Microsoft SharePoint Server are vulnerable to cross-site search attacks (a variant of cross-site request forgery, CSRF).When users are simultaneously logged in to Microsoft SharePoint…
- risk 0.42cvss 6.5epss 0.03
An elevation of privilege vulnerability exists in Microsoft SharePoint, aka 'Microsoft SharePoint Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1329.
- risk 0.42cvss 6.5epss 0.03
An elevation of privilege vulnerability exists in Microsoft SharePoint, aka 'Microsoft SharePoint Elevation of Privilege Vulnerability'.
- risk 0.41cvss 6.3epss 0.01
Microsoft SharePoint Server Spoofing Vulnerability
- risk 0.41cvss 6.3epss 0.01
Microsoft SharePoint Server Spoofing Vulnerability
- risk 0.41cvss 6.3epss 0.02
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially crafted request to…
- risk 0.41cvss 6.3epss 0.02
A tampering vulnerability exists when Microsoft SharePoint Server fails to properly handle profile data. An attacker who successfully exploited this vulnerability could modify a targeted user's profile data. To exploit the vulnerability, an attacker would need to be…
- risk 0.41cvss 6.1epss 0.14
Cross-site scripting (XSS) vulnerability in the SafeHTML function in the toStaticHTML API in Microsoft Internet Explorer 7 and 8, Office SharePoint Server 2007 SP2, Office SharePoint Server 2010 Gold and SP1, Groove Server 2010 Gold and SP1, Windows SharePoint Services 3.0 SP2,…
- risk 0.40cvss 6.1epss 0.03
Microsoft SharePoint Server Remote Code Execution Vulnerability
- risk 0.40cvss 6.1epss 0.02
An open redirect vulnerability exists in Microsoft SharePoint that could lead to spoofing.To exploit the vulnerability, an attacker could send a link that has a specially crafted URL and convince the user to click the link, aka 'SharePoint Open Redirect Vulnerability'.
- risk 0.40cvss 6.1epss 0.03
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE-2020-1099,…
- risk 0.40cvss 6.1epss 0.02
A spoofing vulnerability exists in Microsoft SharePoint when the application does not properly parse HTTP content, aka 'Microsoft SharePoint Spoofing Vulnerability'.
- risk 0.40cvss 6.1epss 0.04
Microsoft Access in Microsoft SharePoint Enterprise Server 2013 and Microsoft SharePoint Enterprise Server 2016 allows a cross-site-scripting (XSS) vulnerability due to the way image field values are handled, aka "Microsoft Access Tampering Vulnerability".
- risk 0.40cvss 6.1epss 0.07
Microsoft SharePoint Server fails to sanitize crafted web requests, allowing remote attackers to run cross-script in local security context, aka "Microsoft SharePoint XSS Vulnerability."
- risk 0.40cvss 6.1epss 0.07
Microsoft SharePoint Server 2013 SP1 and SharePoint Foundation 2013 SP1 allow remote authenticated users to bypass intended Access Control Policy restrictions and conduct cross-site scripting (XSS) attacks by modifying a webpart, aka "Microsoft SharePoint Security Feature…
Page 18 of 34