Sharepoint Server
by Microsoft
CVEs (672)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-45467 | Med | 0.30 | 4.6 | 0.01 | Jun 9, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | ||
| CVE-2026-45462 | Med | 0.30 | 4.6 | 0.01 | Jun 9, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | ||
| CVE-2026-20959 | Med | 0.30 | 4.6 | 0.07 | Jan 13, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | ||
| CVE-2021-26418 | Med | 0.30 | 4.6 | 0.01 | May 11, 2021 | Microsoft SharePoint Server Spoofing Vulnerability | ||
| CVE-2021-24104 | Med | 0.30 | 4.6 | 0.01 | Mar 11, 2021 | Microsoft SharePoint Server Spoofing Vulnerability | ||
| CVE-2021-1717 | Med | 0.30 | 4.6 | 0.02 | Jan 12, 2021 | Microsoft SharePoint Server Spoofing Vulnerability | ||
| CVE-2021-1641 | Med | 0.30 | 4.6 | 0.02 | Jan 12, 2021 | Microsoft SharePoint Server Spoofing Vulnerability | ||
| CVE-2020-1205 | Med | 0.30 | 4.6 | 0.02 | Sep 11, 2020 | A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially crafted request to an affected… | ||
| CVE-2020-1444 | Med | 0.29 | 4.3 | 0.09 | Jul 14, 2020 | A remote code execution vulnerability exists in the way Microsoft SharePoint software parses specially crafted email messages, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. | ||
| CVE-2019-1202 | Med | 0.29 | 4.4 | 0.02 | Aug 14, 2019 | An information disclosure vulnerability exists in the way Microsoft SharePoint handles session objects. An authenticated attacker who successfully exploited the vulnerability could hijack the session of another user. To exploit this vulnerability, the attacker could run a… | ||
| CVE-2010-3243 | Med | 0.29 | 4.3 | 0.16 | Oct 13, 2010 | Cross-site scripting (XSS) vulnerability in the toStaticHTML function in Microsoft Internet Explorer 8, and the SafeHTML function in Microsoft Windows SharePoint Services 3.0 SP2 and Office SharePoint Server 2007 SP2, allows remote attackers to inject arbitrary web script or… | ||
| CVE-2023-33165 | Med | 0.28 | 4.3 | 0.01 | Jul 11, 2023 | Microsoft SharePoint Server Security Feature Bypass Vulnerability | ||
| CVE-2022-21968 | Med | 0.28 | 4.3 | 0.02 | Feb 9, 2022 | Microsoft SharePoint Server Security Feature Bypass Vulnerability | ||
| CVE-2020-17015 | Med | 0.28 | 4.3 | 0.02 | Nov 11, 2020 | Microsoft SharePoint Server Spoofing Vulnerability | ||
| CVE-2018-8580 | Med | 0.28 | 4.3 | 0.04 | Dec 12, 2018 | An information disclosure vulnerability exists where certain modes of the search function in Microsoft SharePoint Server are vulnerable to cross-site search attacks (a variant of cross-site request forgery, CSRF), aka "Microsoft SharePoint Information Disclosure Vulnerability."… | ||
| CVE-2018-8578 | Med | 0.28 | 4.3 | 0.05 | Nov 14, 2018 | An information disclosure vulnerability exists when Microsoft SharePoint Server improperly discloses its folder structure when rendering specific web pages, aka "Microsoft SharePoint Information Disclosure Vulnerability." This affects Microsoft SharePoint. | ||
| CVE-2021-31171 | Med | 0.27 | 4.1 | 0.01 | May 11, 2021 | Microsoft SharePoint Information Disclosure Vulnerability | ||
| CVE-2020-16942 | Med | 0.27 | 4.1 | 0.01 | Oct 16, 2020 | An information disclosure vulnerability exists when Microsoft SharePoint Server improperly discloses its folder structure when rendering specific web pages. An attacker who took advantage of this information disclosure could view the folder path of scripts loaded on the… | ||
| CVE-2020-16941 | Med | 0.27 | 4.1 | 0.01 | Oct 16, 2020 | An information disclosure vulnerability exists when Microsoft SharePoint Server improperly discloses its folder structure when rendering specific web pages. An attacker who took advantage of this information disclosure could view the folder path of scripts loaded on the… | ||
| CVE-2018-0919 | Low | 0.22 | 3.3 | 0.12 | Mar 14, 2018 | Microsoft Office 2010 SP2, 2013 SP1, and 2016, Microsoft Office 2016 Click-to-Run Microsoft Office 2016 for Mac, Microsoft Office Web Apps 2010 SP2, Microsoft Office Web Apps 2013 SP1, Microsoft SharePoint Enterprise Server 2013 SP1, Microsoft SharePoint Enterprise Server 2016,… |
- risk 0.30cvss 4.6epss 0.01
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
- risk 0.30cvss 4.6epss 0.01
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
- risk 0.30cvss 4.6epss 0.07
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
- risk 0.30cvss 4.6epss 0.01
Microsoft SharePoint Server Spoofing Vulnerability
- risk 0.30cvss 4.6epss 0.01
Microsoft SharePoint Server Spoofing Vulnerability
- risk 0.30cvss 4.6epss 0.02
Microsoft SharePoint Server Spoofing Vulnerability
- risk 0.30cvss 4.6epss 0.02
Microsoft SharePoint Server Spoofing Vulnerability
- risk 0.30cvss 4.6epss 0.02
A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially crafted request to an affected…
- risk 0.29cvss 4.3epss 0.09
A remote code execution vulnerability exists in the way Microsoft SharePoint software parses specially crafted email messages, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'.
- risk 0.29cvss 4.4epss 0.02
An information disclosure vulnerability exists in the way Microsoft SharePoint handles session objects. An authenticated attacker who successfully exploited the vulnerability could hijack the session of another user. To exploit this vulnerability, the attacker could run a…
- risk 0.29cvss 4.3epss 0.16
Cross-site scripting (XSS) vulnerability in the toStaticHTML function in Microsoft Internet Explorer 8, and the SafeHTML function in Microsoft Windows SharePoint Services 3.0 SP2 and Office SharePoint Server 2007 SP2, allows remote attackers to inject arbitrary web script or…
- risk 0.28cvss 4.3epss 0.01
Microsoft SharePoint Server Security Feature Bypass Vulnerability
- risk 0.28cvss 4.3epss 0.02
Microsoft SharePoint Server Security Feature Bypass Vulnerability
- risk 0.28cvss 4.3epss 0.02
Microsoft SharePoint Server Spoofing Vulnerability
- risk 0.28cvss 4.3epss 0.04
An information disclosure vulnerability exists where certain modes of the search function in Microsoft SharePoint Server are vulnerable to cross-site search attacks (a variant of cross-site request forgery, CSRF), aka "Microsoft SharePoint Information Disclosure Vulnerability."…
- risk 0.28cvss 4.3epss 0.05
An information disclosure vulnerability exists when Microsoft SharePoint Server improperly discloses its folder structure when rendering specific web pages, aka "Microsoft SharePoint Information Disclosure Vulnerability." This affects Microsoft SharePoint.
- risk 0.27cvss 4.1epss 0.01
Microsoft SharePoint Information Disclosure Vulnerability
- risk 0.27cvss 4.1epss 0.01
An information disclosure vulnerability exists when Microsoft SharePoint Server improperly discloses its folder structure when rendering specific web pages. An attacker who took advantage of this information disclosure could view the folder path of scripts loaded on the…
- risk 0.27cvss 4.1epss 0.01
An information disclosure vulnerability exists when Microsoft SharePoint Server improperly discloses its folder structure when rendering specific web pages. An attacker who took advantage of this information disclosure could view the folder path of scripts loaded on the…
- risk 0.22cvss 3.3epss 0.12
Microsoft Office 2010 SP2, 2013 SP1, and 2016, Microsoft Office 2016 Click-to-Run Microsoft Office 2016 for Mac, Microsoft Office Web Apps 2010 SP2, Microsoft Office Web Apps 2013 SP1, Microsoft SharePoint Enterprise Server 2013 SP1, Microsoft SharePoint Enterprise Server 2016,…
Page 27 of 34