VendorsMicrosoftsharepoint_enterprise_serverall versions
Vulnerabilities

Microsoft Sharepoint Enterprise Server

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

256CVEs
CVE-2021-1717
Microsoft SharePoint Server Spoofing Vulnerability
Published 2021-01-12 · Modified
5.8EPSS 0.018
CVE-2021-1641
Microsoft SharePoint Server Spoofing Vulnerability
Published 2021-01-12 · Modified
5.8EPSS 0.018
CVE-2021-24104
Microsoft SharePoint Server Spoofing Vulnerability
Published 2021-03-11 · Modified
5.8EPSS 0.014
CVE-2019-1446
An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka 'Microsoft Excel Information Disclosure Vulnerability'.
Published 2019-11-12 · Modified
5.5EPSS 0.089
CVE-2020-1342
An information disclosure vulnerability exists when Microsoft Office software reads out of bound memory due to an uninitialized variable, which could disclose the contents of memory, aka 'Microsoft Office Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-1445.
Published 2020-07-14 · Modified
5.5EPSS 0.064
CVE-2020-1445
An information disclosure vulnerability exists when Microsoft Office improperly discloses the contents of its memory, aka 'Microsoft Office Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-1342.
Published 2020-07-14 · Modified
5.5EPSS 0.061
CVE-2020-1503
Microsoft Word Information Disclosure Vulnerability
Published 2020-08-17 · Modified
5.5EPSS 0.046
CVE-2020-1224
Microsoft Excel Information Disclosure Vulnerability
Published 2020-09-11 · Modified
5.5EPSS 0.044
CVE-2020-1573
Microsoft Office SharePoint XSS Vulnerability
Published 2020-08-17 · Modified
5.5EPSS 0.019
CVE-2020-1499
Microsoft SharePoint Spoofing Vulnerability
Published 2020-08-17 · Modified
5.5EPSS 0.018
CVE-2020-1500
Microsoft SharePoint Spoofing Vulnerability
Published 2020-08-17 · Modified
5.5EPSS 0.018
CVE-2020-1501
Microsoft SharePoint Spoofing Vulnerability
Published 2020-08-17 · Modified
5.5EPSS 0.017
CVE-2020-1505
Microsoft SharePoint Information Disclosure Vulnerability
Published 2020-08-17 · Modified
5.5EPSS 0.013
CVE-2022-41103
Microsoft Word Information Disclosure Vulnerability
Published 2022-11-09 · Modified
5.5EPSS 0.009
CVE-2020-16941
Microsoft SharePoint Information Disclosure Vulnerability
Published 2020-10-16 · Modified
5.5EPSS 0.009
CVE-2022-41060
Microsoft Word Information Disclosure Vulnerability
Published 2022-11-09 · Modified
5.5EPSS 0.008
CVE-2017-8514
An information disclosure vulnerability exists when Microsoft SharePoint software fails to properly sanitize a specially crafted requests, aka "Microsoft SharePoint Reflective XSS Vulnerability".
Published 2017-06-15 · Modified
5.4EPSS 0.030
CVE-2018-8518
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft SharePoint. This CVE ID is unique from CVE-2018-8480, CVE-2018-8488, CVE-2018-8498.
Published 2018-10-10 · Modified
5.4EPSS 0.028
CVE-2018-8299
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft SharePoint. This CVE ID is unique from CVE-2018-8323.
Published 2018-07-11 · Modified
5.4EPSS 0.025
CVE-2018-8323
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft SharePoint. This CVE ID is unique from CVE-2018-8299.
Published 2018-07-11 · Modified
5.4EPSS 0.025
CVE-2017-11820
Microsoft SharePoint Enterprise Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an attacker to exploit a cross-site scripting (XSS) vulnerability by sending a specially crafted request to an affected SharePoint server, due to how SharePoint Server sanitizes web requests, aka "Microsoft Office SharePoint XSS Vulnerability". This CVE ID is unique from CVE-2017-11775 and CVE-2017-11777.
Published 2017-10-13 · Modified
5.4EPSS 0.023
CVE-2017-11775
Microsoft SharePoint Enterprise Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an attacker to exploit a cross-site scripting (XSS) vulnerability by sending a specially crafted request to an affected SharePoint server, due to how SharePoint Server sanitizes web requests, aka "Microsoft Office SharePoint XSS Vulnerability". This CVE ID is unique from CVE-2017-11777 and CVE-2017-11820.
Published 2017-10-13 · Modified
5.4EPSS 0.023
CVE-2017-11777
Microsoft SharePoint Enterprise Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an attacker to exploit a cross-site scripting (XSS) vulnerability by sending a specially crafted request to an affected SharePoint server, due to how SharePoint Server sanitizes web requests, aka "Microsoft Office SharePoint XSS Vulnerability". This CVE ID is unique from CVE-2017-11775 and CVE-2017-11820.
Published 2017-10-13 · Modified
5.4EPSS 0.023
CVE-2018-8568
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft SharePoint Server, Microsoft SharePoint. This CVE ID is unique from CVE-2018-8572.
Published 2018-11-14 · Modified
5.4EPSS 0.023
CVE-2018-8488
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft SharePoint. This CVE ID is unique from CVE-2018-8480, CVE-2018-8498, CVE-2018-8518.
Published 2018-10-10 · Modified
5.4EPSS 0.023
CVE-2018-8498
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft SharePoint. This CVE ID is unique from CVE-2018-8480, CVE-2018-8488, CVE-2018-8518.
Published 2018-10-10 · Modified
5.4EPSS 0.023
CVE-2018-8431
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft SharePoint Server, Microsoft SharePoint. This CVE ID is unique from CVE-2018-8428.
Published 2018-09-13 · Modified
5.4EPSS 0.023
CVE-2020-1456
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE-2020-1450, CVE-2020-1451.
Published 2020-07-14 · Modified
5.4EPSS 0.022
CVE-2018-1032
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft SharePoint Server, Microsoft SharePoint. This CVE ID is unique from CVE-2018-1005, CVE-2018-1014, CVE-2018-1034.
Published 2018-04-12 · Modified
5.4EPSS 0.022
CVE-2018-1005
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft SharePoint. This CVE ID is unique from CVE-2018-1014, CVE-2018-1032, CVE-2018-1034.
Published 2018-04-12 · Modified
5.4EPSS 0.022
CVE-2018-1014
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft SharePoint. This CVE ID is unique from CVE-2018-1005, CVE-2018-1032, CVE-2018-1034.
Published 2018-04-12 · Modified
5.4EPSS 0.022
CVE-2018-1034
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft SharePoint. This CVE ID is unique from CVE-2018-1005, CVE-2018-1014, CVE-2018-1032.
Published 2018-04-12 · Modified
5.4EPSS 0.022
CVE-2018-0869
SharePoint Server 2016 allows an elevation of privilege vulnerability due to how web requests are handled, aka "Microsoft SharePoint Elevation of Privilege Vulnerability".
Published 2018-02-15 · Modified
5.4EPSS 0.022
CVE-2020-0976
A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Spoofing Vulnerability'. This CVE ID is unique from CVE-2020-0972, CVE-2020-0975, CVE-2020-0977.
Published 2020-04-15 · Modified
5.4EPSS 0.022
CVE-2020-0924
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE-2020-0923, CVE-2020-0925, CVE-2020-0926, CVE-2020-0927, CVE-2020-0930, CVE-2020-0933, CVE-2020-0954, CVE-2020-0973, CVE-2020-0978.
Published 2020-04-15 · Modified
5.4EPSS 0.018
CVE-2018-8428
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft SharePoint. This CVE ID is unique from CVE-2018-8431.
Published 2018-09-13 · Modified
5.4EPSS 0.017
CVE-2020-1099
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE-2020-1100, CVE-2020-1101, CVE-2020-1106.
Published 2020-05-21 · Modified
5.4EPSS 0.017
CVE-2020-1100
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE-2020-1099, CVE-2020-1101, CVE-2020-1106.
Published 2020-05-21 · Modified
5.4EPSS 0.017
CVE-2020-1101
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE-2020-1099, CVE-2020-1100, CVE-2020-1106.
Published 2020-05-21 · Modified
5.4EPSS 0.017
CVE-2019-1203
Microsoft Office SharePoint XSS Vulnerability
Published 2019-08-14 · Modified
5.4EPSS 0.017
← Prev5 / 7Next →