VendorsMicrosoftsharepoint_enterprise_server2013
Vulnerabilities

Microsoft Sharepoint Enterprise Server 2013

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

104CVEs
CVE-2022-41062
Microsoft SharePoint Server Remote Code Execution Vulnerability
Published 2022-11-09 · Modified
8.8EPSS 0.016
CVE-2020-1576
Microsoft SharePoint Remote Code Execution Vulnerability
Published 2020-09-11 · Modified
8.8EPSS 0.016
CVE-2023-21717
Microsoft SharePoint Server Elevation of Privilege Vulnerability
Published 2023-02-14 · Modified
8.8EPSS 0.011
CVE-2020-1453
Microsoft SharePoint Remote Code Execution Vulnerability
Published 2020-09-11 · Modified
8.6EPSS 0.022
CVE-2020-1452
Microsoft SharePoint Remote Code Execution Vulnerability
Published 2020-09-11 · Modified
8.6EPSS 0.022
CVE-2020-1147
A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of XML file input, aka '.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability'.
Published 2020-07-14 · Analyzed
7.8KEV2 PoCEPSS 0.940
CVE-2021-40486
Microsoft Word Remote Code Execution Vulnerability
Published 2021-10-13 · Modified
7.8EPSS 0.060
CVE-2020-16929
Microsoft Excel Remote Code Execution Vulnerability
Published 2020-10-16 · Modified
7.8EPSS 0.037
CVE-2021-1714
Microsoft Excel Remote Code Execution Vulnerability
Published 2021-01-12 · Modified
7.8EPSS 0.031
CVE-2021-40485
Microsoft Excel Remote Code Execution Vulnerability
Published 2021-10-13 · Modified
7.8EPSS 0.027
CVE-2021-40442
Microsoft Excel Remote Code Execution Vulnerability
Published 2021-11-10 · Modified
7.8EPSS 0.023
CVE-2022-41061
Microsoft Word Remote Code Execution Vulnerability
Published 2022-11-09 · Modified
7.8EPSS 0.012
CVE-2021-36940
Microsoft SharePoint Server Spoofing Vulnerability
Published 2021-08-12 · Modified
7.6EPSS 0.040
CVE-2019-1006
An authentication bypass vulnerability exists in Windows Communication Foundation (WCF) and Windows Identity Foundation (WIF), allowing signing of SAML tokens with arbitrary symmetric keys, aka 'WCF/WIF SAML Token Authentication Bypass Vulnerability'.
Published 2019-07-15 · Modified
7.5EPSS 0.060
CVE-2021-42294
Microsoft SharePoint Server Remote Code Execution Vulnerability
Published 2021-12-15 · Modified
7.2EPSS 0.022
CVE-2022-41122
Microsoft SharePoint Server Spoofing Vulnerability
Published 2022-11-09 · Modified
6.5EPSS 0.016
CVE-2020-1440
Microsoft SharePoint Server Tampering Vulnerability
Published 2020-09-11 · Modified
6.3EPSS 0.018
CVE-2018-0799
Microsoft Access in Microsoft SharePoint Enterprise Server 2013 and Microsoft SharePoint Enterprise Server 2016 allows a cross-site-scripting (XSS) vulnerability due to the way image field values are handled, aka "Microsoft Access Tampering Vulnerability".
Published 2018-01-10 · Modified
6.1EPSS 0.036
CVE-2019-0670
A spoofing vulnerability exists in Microsoft SharePoint when the application does not properly parse HTTP content, aka 'Microsoft SharePoint Spoofing Vulnerability'.
Published 2019-03-06 · Modified
6.1EPSS 0.025
CVE-2020-17060
Microsoft SharePoint Server Spoofing Vulnerability
Published 2020-11-11 · Modified
5.8EPSS 0.019
CVE-2019-1446
An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka 'Microsoft Excel Information Disclosure Vulnerability'.
Published 2019-11-12 · Modified
5.5EPSS 0.089
CVE-2020-1342
An information disclosure vulnerability exists when Microsoft Office software reads out of bound memory due to an uninitialized variable, which could disclose the contents of memory, aka 'Microsoft Office Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-1445.
Published 2020-07-14 · Modified
5.5EPSS 0.064
CVE-2020-1445
An information disclosure vulnerability exists when Microsoft Office improperly discloses the contents of its memory, aka 'Microsoft Office Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-1342.
Published 2020-07-14 · Modified
5.5EPSS 0.061
CVE-2020-1503
Microsoft Word Information Disclosure Vulnerability
Published 2020-08-17 · Modified
5.5EPSS 0.046
CVE-2020-1224
Microsoft Excel Information Disclosure Vulnerability
Published 2020-09-11 · Modified
5.5EPSS 0.044
CVE-2020-1499
Microsoft SharePoint Spoofing Vulnerability
Published 2020-08-17 · Modified
5.5EPSS 0.018
CVE-2020-1500
Microsoft SharePoint Spoofing Vulnerability
Published 2020-08-17 · Modified
5.5EPSS 0.018
CVE-2022-41103
Microsoft Word Information Disclosure Vulnerability
Published 2022-11-09 · Modified
5.5EPSS 0.009
CVE-2022-41060
Microsoft Word Information Disclosure Vulnerability
Published 2022-11-09 · Modified
5.5EPSS 0.008
CVE-2018-8518
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft SharePoint. This CVE ID is unique from CVE-2018-8480, CVE-2018-8488, CVE-2018-8498.
Published 2018-10-10 · Modified
5.4EPSS 0.028
CVE-2018-8299
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft SharePoint. This CVE ID is unique from CVE-2018-8323.
Published 2018-07-11 · Modified
5.4EPSS 0.025
CVE-2018-8323
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft SharePoint. This CVE ID is unique from CVE-2018-8299.
Published 2018-07-11 · Modified
5.4EPSS 0.025
CVE-2017-11777
Microsoft SharePoint Enterprise Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an attacker to exploit a cross-site scripting (XSS) vulnerability by sending a specially crafted request to an affected SharePoint server, due to how SharePoint Server sanitizes web requests, aka "Microsoft Office SharePoint XSS Vulnerability". This CVE ID is unique from CVE-2017-11775 and CVE-2017-11820.
Published 2017-10-13 · Modified
5.4EPSS 0.023
CVE-2017-11775
Microsoft SharePoint Enterprise Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an attacker to exploit a cross-site scripting (XSS) vulnerability by sending a specially crafted request to an affected SharePoint server, due to how SharePoint Server sanitizes web requests, aka "Microsoft Office SharePoint XSS Vulnerability". This CVE ID is unique from CVE-2017-11777 and CVE-2017-11820.
Published 2017-10-13 · Modified
5.4EPSS 0.023
CVE-2017-11820
Microsoft SharePoint Enterprise Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an attacker to exploit a cross-site scripting (XSS) vulnerability by sending a specially crafted request to an affected SharePoint server, due to how SharePoint Server sanitizes web requests, aka "Microsoft Office SharePoint XSS Vulnerability". This CVE ID is unique from CVE-2017-11775 and CVE-2017-11777.
Published 2017-10-13 · Modified
5.4EPSS 0.023
CVE-2018-8488
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft SharePoint. This CVE ID is unique from CVE-2018-8480, CVE-2018-8498, CVE-2018-8518.
Published 2018-10-10 · Modified
5.4EPSS 0.023
CVE-2018-8498
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft SharePoint. This CVE ID is unique from CVE-2018-8480, CVE-2018-8488, CVE-2018-8518.
Published 2018-10-10 · Modified
5.4EPSS 0.023
CVE-2018-8431
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft SharePoint Server, Microsoft SharePoint. This CVE ID is unique from CVE-2018-8428.
Published 2018-09-13 · Modified
5.4EPSS 0.023
CVE-2020-1456
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE-2020-1450, CVE-2020-1451.
Published 2020-07-14 · Modified
5.4EPSS 0.022
CVE-2018-1032
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft SharePoint Server, Microsoft SharePoint. This CVE ID is unique from CVE-2018-1005, CVE-2018-1014, CVE-2018-1034.
Published 2018-04-12 · Modified
5.4EPSS 0.022
← Prev2 / 3Next →