VYPR

Sharepoint Foundation

by Microsoft

CVEs (231)

  • CVE-2020-16953MedOct 16, 2020
    risk 0.43cvss 6.5epss 0.04

    An information disclosure vulnerability exists when Microsoft SharePoint Server fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system. To exploit the…

  • CVE-2020-16948MedOct 16, 2020
    risk 0.43cvss 6.5epss 0.04

    An information disclosure vulnerability exists when Microsoft SharePoint Server fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system. To exploit the…

  • CVE-2019-1443MedNov 12, 2019
    risk 0.43cvss 6.5epss 0.05

    An information disclosure vulnerability exists in Microsoft SharePoint when an attacker uploads a specially crafted file to the SharePoint Server.An authenticated attacker who successfully exploited this vulnerability could potentially leverage SharePoint functionality to obtain…

  • CVE-2019-0956MedMay 16, 2019
    risk 0.43cvss 6.5epss 0.05

    An information disclosure vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Server Information Disclosure Vulnerability'.

  • CVE-2022-41122MedNov 9, 2022
    risk 0.42cvss 6.5epss 0.01

    Microsoft SharePoint Server Spoofing Vulnerability

  • CVE-2020-1103MedMay 21, 2020
    risk 0.42cvss 6.5epss 0.03

    An information disclosure vulnerability exists where certain modes of the search function in Microsoft SharePoint Server are vulnerable to cross-site search attacks (a variant of cross-site request forgery, CSRF).When users are simultaneously logged in to Microsoft SharePoint…

  • CVE-2019-1330MedOct 10, 2019
    risk 0.42cvss 6.5epss 0.03

    An elevation of privilege vulnerability exists in Microsoft SharePoint, aka 'Microsoft SharePoint Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1329.

  • CVE-2019-1260MedSep 11, 2019
    risk 0.42cvss 6.5epss 0.03

    An elevation of privilege vulnerability exists in Microsoft SharePoint, aka 'Microsoft SharePoint Elevation of Privilege Vulnerability'.

  • CVE-2020-1482MedSep 11, 2020
    risk 0.41cvss 6.3epss 0.02

    A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially crafted request to…

  • CVE-2020-1323MedJun 9, 2020
    risk 0.40cvss 6.1epss 0.02

    An open redirect vulnerability exists in Microsoft SharePoint that could lead to spoofing.To exploit the vulnerability, an attacker could send a link that has a specially crafted URL and convince the user to click the link, aka 'SharePoint Open Redirect Vulnerability'.

  • CVE-2020-1106MedMay 21, 2020
    risk 0.40cvss 6.1epss 0.03

    A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE-2020-1099,…

  • CVE-2019-0670MedMar 5, 2019
    risk 0.40cvss 6.1epss 0.02

    A spoofing vulnerability exists in Microsoft SharePoint when the application does not properly parse HTTP content, aka 'Microsoft SharePoint Spoofing Vulnerability'.

  • CVE-2017-0107MedMar 17, 2017
    risk 0.40cvss 6.1epss 0.07

    Microsoft SharePoint Server fails to sanitize crafted web requests, allowing remote attackers to run cross-script in local security context, aka "Microsoft SharePoint XSS Vulnerability."

  • CVE-2016-0039MedFeb 10, 2016
    risk 0.40cvss 6.1epss 0.07

    Cross-site scripting (XSS) vulnerability in SharePoint Server in Microsoft SharePoint Foundation 2013 SP1 allows remote attackers to inject arbitrary web script or HTML via a crafted request, aka "Microsoft SharePoint XSS Vulnerability."

  • CVE-2015-6117MedJan 13, 2016
    risk 0.40cvss 6.1epss 0.07

    Microsoft SharePoint Server 2013 SP1 and SharePoint Foundation 2013 SP1 allow remote authenticated users to bypass intended Access Control Policy restrictions and conduct cross-site scripting (XSS) attacks by modifying a webpart, aka "Microsoft SharePoint Security Feature…

  • CVE-2019-1262MedSep 11, 2019
    risk 0.38cvss 5.4epss 0.03

    A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'.

  • CVE-2021-31965MedJun 8, 2021
    risk 0.37cvss 5.7epss 0.05

    Microsoft SharePoint Server Information Disclosure Vulnerability

  • CVE-2019-0950MedMay 16, 2019
    risk 0.37cvss 5.7epss 0.02

    A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-0949, CVE-2019-0951.

  • CVE-2019-0949MedMay 16, 2019
    risk 0.37cvss 5.7epss 0.02

    A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-0950, CVE-2019-0951.

  • CVE-2020-1573MedAug 17, 2020
    risk 0.36cvss 5.5epss 0.02

    A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially crafted request to an…

Page 6 of 12