VYPR

Sharepoint Server

by Microsoft

CVEs (672)

  • CVE-2026-45467MedJun 9, 2026
    risk 0.30cvss 4.6epss 0.01

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

  • CVE-2026-45462MedJun 9, 2026
    risk 0.30cvss 4.6epss 0.01

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

  • CVE-2026-20959MedJan 13, 2026
    risk 0.30cvss 4.6epss 0.07

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

  • CVE-2021-26418MedMay 11, 2021
    risk 0.30cvss 4.6epss 0.01

    Microsoft SharePoint Server Spoofing Vulnerability

  • CVE-2021-24104MedMar 11, 2021
    risk 0.30cvss 4.6epss 0.01

    Microsoft SharePoint Server Spoofing Vulnerability

  • CVE-2021-1717MedJan 12, 2021
    risk 0.30cvss 4.6epss 0.02

    Microsoft SharePoint Server Spoofing Vulnerability

  • CVE-2021-1641MedJan 12, 2021
    risk 0.30cvss 4.6epss 0.02

    Microsoft SharePoint Server Spoofing Vulnerability

  • CVE-2020-1205MedSep 11, 2020
    risk 0.30cvss 4.6epss 0.02

    A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially crafted request to an affected…

  • CVE-2020-1444MedJul 14, 2020
    risk 0.29cvss 4.3epss 0.09

    A remote code execution vulnerability exists in the way Microsoft SharePoint software parses specially crafted email messages, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'.

  • CVE-2019-1202MedAug 14, 2019
    risk 0.29cvss 4.4epss 0.02

    An information disclosure vulnerability exists in the way Microsoft SharePoint handles session objects. An authenticated attacker who successfully exploited the vulnerability could hijack the session of another user. To exploit this vulnerability, the attacker could run a…

  • CVE-2010-3243MedOct 13, 2010
    risk 0.29cvss 4.3epss 0.16

    Cross-site scripting (XSS) vulnerability in the toStaticHTML function in Microsoft Internet Explorer 8, and the SafeHTML function in Microsoft Windows SharePoint Services 3.0 SP2 and Office SharePoint Server 2007 SP2, allows remote attackers to inject arbitrary web script or…

  • CVE-2023-33165MedJul 11, 2023
    risk 0.28cvss 4.3epss 0.01

    Microsoft SharePoint Server Security Feature Bypass Vulnerability

  • CVE-2022-21968MedFeb 9, 2022
    risk 0.28cvss 4.3epss 0.02

    Microsoft SharePoint Server Security Feature Bypass Vulnerability

  • CVE-2020-17015MedNov 11, 2020
    risk 0.28cvss 4.3epss 0.02

    Microsoft SharePoint Server Spoofing Vulnerability

  • CVE-2018-8580MedDec 12, 2018
    risk 0.28cvss 4.3epss 0.04

    An information disclosure vulnerability exists where certain modes of the search function in Microsoft SharePoint Server are vulnerable to cross-site search attacks (a variant of cross-site request forgery, CSRF), aka "Microsoft SharePoint Information Disclosure Vulnerability."…

  • CVE-2018-8578MedNov 14, 2018
    risk 0.28cvss 4.3epss 0.05

    An information disclosure vulnerability exists when Microsoft SharePoint Server improperly discloses its folder structure when rendering specific web pages, aka "Microsoft SharePoint Information Disclosure Vulnerability." This affects Microsoft SharePoint.

  • CVE-2021-31171MedMay 11, 2021
    risk 0.27cvss 4.1epss 0.01

    Microsoft SharePoint Information Disclosure Vulnerability

  • CVE-2020-16942MedOct 16, 2020
    risk 0.27cvss 4.1epss 0.01

    An information disclosure vulnerability exists when Microsoft SharePoint Server improperly discloses its folder structure when rendering specific web pages. An attacker who took advantage of this information disclosure could view the folder path of scripts loaded on the…

  • CVE-2020-16941MedOct 16, 2020
    risk 0.27cvss 4.1epss 0.01

    An information disclosure vulnerability exists when Microsoft SharePoint Server improperly discloses its folder structure when rendering specific web pages. An attacker who took advantage of this information disclosure could view the folder path of scripts loaded on the…

  • CVE-2018-0919LowMar 14, 2018
    risk 0.22cvss 3.3epss 0.12

    Microsoft Office 2010 SP2, 2013 SP1, and 2016, Microsoft Office 2016 Click-to-Run Microsoft Office 2016 for Mac, Microsoft Office Web Apps 2010 SP2, Microsoft Office Web Apps 2013 SP1, Microsoft SharePoint Enterprise Server 2013 SP1, Microsoft SharePoint Enterprise Server 2016,…

Page 27 of 34