VendorsMicrosoftsharepoint_enterprise_server2013
Vulnerabilities

Microsoft Sharepoint Enterprise Server 2013

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

104CVEs
CVE-2020-1595
Microsoft SharePoint Remote Code Execution Vulnerability
Published 2020-09-11 · Modified
9.9EPSS 0.020
CVE-2020-1210
Microsoft SharePoint Remote Code Execution Vulnerability
Published 2020-09-11 · Modified
9.9EPSS 0.019
CVE-2023-21716
Microsoft Word Remote Code Execution Vulnerability
Published 2023-02-14 · Modified
9.8EPSS 0.823
CVE-2018-8284
A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka ".NET Framework Remote Code Injection Vulnerability." This affects Microsoft .NET Framework 2.0, Microsoft .NET Framework 3.0, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.5.2, Microsoft .NET Framework 4.6, Microsoft .NET Framework 4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.7.1/4.7.2, Microsoft .NET Framework 3.5, Microsoft .NET Framework 3.5.1, Microsoft .NET Framework 4.6/4.6.1/4.6.2, Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2, Microsoft .NET Framework 4.7.2.
Published 2018-07-11 · Modified
9.3EPSS 0.415
CVE-2018-0797
Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow a remote code execution vulnerability due to the way RTF content is handled, aka "Microsoft Word Memory Corruption Vulnerability".
Published 2018-01-10 · Modified
9.3EPSS 0.248
CVE-2017-8512
A remote code execution vulnerability exists in Microsoft Office when the software fails to properly handle objects in memory, aka "Office Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-8509, CVE-2017-8510, CVE-2017-8511, CVE-2017-0260, and CVE-2017-8506.
Published 2017-06-15 · Modified
9.3EPSS 0.221
CVE-2018-1028
A remote code execution vulnerability exists when the Office graphics component improperly handles specially crafted embedded fonts, aka "Microsoft Office Graphics Remote Code Execution Vulnerability." This affects Word, Microsoft Office, Microsoft SharePoint, Excel, Microsoft SharePoint Server.
Published 2018-04-12 · Modified
9.3EPSS 0.189
CVE-2018-0922
Microsoft Office 2010 SP2, 2013 SP1, and 2016, Microsoft Office 2016 Click-to-Run Microsoft Office 2016 for Mac, Microsoft Office Compatibility Pack SP2, Microsoft Office Web Apps 2010 SP2, Microsoft Office Web Apps 2013 SP1, Microsoft Office Word Viewer, Microsoft SharePoint Enterprise Server 2013 SP1, Microsoft SharePoint Enterprise Server 2016, Microsoft Office Compatibility Pack SP2, Microsoft Online Server 2016, Microsoft SharePoint Server 2010 SP2, Microsoft Word 2007 SP3, Microsoft Word 2010 SP2, Word 2013 and Microsoft Word 2016 allow a remote code execution vulnerability due to how objects are handled in memory, aka "Microsoft Office Memory Corruption Vulnerability".
Published 2018-03-14 · Modified
9.3EPSS 0.180
CVE-2020-0980
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'.
Published 2020-04-15 · Modified
9.3EPSS 0.118
CVE-2020-0892
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0850, CVE-2020-0851, CVE-2020-0852, CVE-2020-0855.
Published 2020-03-12 · Modified
9.3EPSS 0.118
CVE-2019-1034
Microsoft Word Remote Code Execution Vulnerability
Published 2019-06-12 · Modified
9.3EPSS 0.049
CVE-2019-1201
Microsoft Word Remote Code Execution Vulnerability
Published 2019-08-14 · Modified
9.3EPSS 0.049
CVE-2020-1495
Microsoft Excel Remote Code Execution Vulnerability
Published 2020-08-17 · Modified
9.3EPSS 0.042
CVE-2021-1715
Microsoft Word Remote Code Execution Vulnerability
Published 2021-01-12 · Modified
9.3EPSS 0.036
CVE-2021-1716
Microsoft Word Remote Code Execution Vulnerability
Published 2021-01-12 · Modified
9.3EPSS 0.036
CVE-2018-0789
Microsoft SharePoint Foundation 2010, Microsoft SharePoint Server 2013 and Microsoft SharePoint Server 2016 allow an elevation of privilege vulnerability due to the way web requests are handled, aka "Microsoft SharePoint Elevation of Privilege Vulnerability". This CVE is unique from CVE-2018-0790.
Published 2018-01-10 · Modified
9.0EPSS 0.064
CVE-2022-38053
Microsoft SharePoint Server Remote Code Execution Vulnerability
Published 2022-10-11 · Modified
8.8EPSS 0.764
CVE-2022-35823
Microsoft SharePoint Remote Code Execution Vulnerability
Published 2022-09-13 · Modified
8.8EPSS 0.536
CVE-2022-37961
Microsoft SharePoint Server Remote Code Execution Vulnerability
Published 2022-09-13 · Modified
8.8EPSS 0.507
CVE-2020-1439
A remote code execution vulnerability exists in PerformancePoint Services for SharePoint Server when the software fails to check the source markup of XML file input, aka 'PerformancePoint Services Remote Code Execution Vulnerability'.
Published 2020-07-14 · Modified
8.8EPSS 0.203
CVE-2018-8300
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka "Microsoft SharePoint Remote Code Execution Vulnerability." This affects Microsoft SharePoint.
Published 2018-07-11 · Modified
8.8EPSS 0.136
CVE-2020-1446
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1447, CVE-2020-1448.
Published 2020-07-14 · Modified
8.8EPSS 0.112
CVE-2020-0931
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0920, CVE-2020-0929, CVE-2020-0932, CVE-2020-0971, CVE-2020-0974.
Published 2020-04-15 · Modified
8.8EPSS 0.107
CVE-2020-1447
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1446, CVE-2020-1448.
Published 2020-07-14 · Modified
8.8EPSS 0.106
CVE-2020-0850
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0851, CVE-2020-0852, CVE-2020-0855, CVE-2020-0892.
Published 2020-03-12 · Modified
8.8EPSS 0.088
CVE-2018-8635
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted authentication request to an affected SharePoint server, aka "Microsoft SharePoint Server Elevation of Privilege Vulnerability." This affects Microsoft SharePoint Server, Microsoft SharePoint.
Published 2018-12-12 · Modified
8.8EPSS 0.061
CVE-2018-0790
Microsoft SharePoint Foundation 2010, Microsoft SharePoint Server 2013 and Microsoft SharePoint Server 2016 allow an elevation of privilege vulnerability due to the way web requests are handled, aka "Microsoft SharePoint Elevation of Privilege Vulnerability". This CVE is unique from CVE-2018-0789.
Published 2018-01-10 · Modified
8.8EPSS 0.053
CVE-2020-1583
Microsoft Word Information Disclosure Vulnerability
Published 2020-08-17 · Modified
8.8EPSS 0.049
CVE-2018-0923
Microsoft SharePoint Enterprise Server 2016 allows an elevation of privilege vulnerability to due how specially crafted web requests are sanitized, aka "Microsoft SharePoint Elevation of Privilege Vulnerability". This CVE is unique from CVE-2018-0909, CVE-2018-0910. CVE-2018-0911, CVE-2018-0912, CVE-2018-0913 CVE-2018-0914, CVE-2018-0915, CVE-2018-0916, CVE-2018-0917, CVE-2018-0921, CVE-2018-0944 and CVE-2018-0947.
Published 2018-03-14 · Modified
8.8EPSS 0.045
CVE-2018-0947
Microsoft SharePoint Foundation 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation of privilege vulnerability to due how specially crafted web requests are sanitized, aka "Microsoft SharePoint Elevation of Privilege Vulnerability". This CVE is unique from CVE-2018-0909, CVE-2018-0910. CVE-2018-0911, CVE-2018-0912, CVE-2018-0913 CVE-2018-0914, CVE-2018-0915, CVE-2018-0916, CVE-2018-0917, CVE-2018-0921, CVE-2018-0923 and CVE-2018-0944.
Published 2018-03-14 · Modified
8.8EPSS 0.045
CVE-2019-0668
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Elevation of Privilege Vulnerability'.
Published 2019-03-06 · Modified
8.8EPSS 0.039
CVE-2020-1218
Microsoft Word Remote Code Execution Vulnerability
Published 2020-09-11 · Modified
8.8EPSS 0.038
CVE-2020-1460
Microsoft SharePoint Server Remote Code Execution Vulnerability
Published 2020-09-11 · Modified
8.8EPSS 0.037
CVE-2020-1178
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted authentication request to an affected SharePoint server, aka 'Microsoft SharePoint Server Elevation of Privilege Vulnerability'.
Published 2020-06-09 · Modified
8.8EPSS 0.031
CVE-2022-21840
Microsoft Office Remote Code Execution Vulnerability
Published 2022-01-11 · Modified
8.8EPSS 0.031
CVE-2020-1295
An elevation of privilege vulnerability exists in Microsoft SharePoint, aka 'Microsoft SharePoint Elevation of Privilege Vulnerability'.
Published 2020-06-09 · Modified
8.8EPSS 0.030
CVE-2022-38009
Microsoft SharePoint Server Remote Code Execution Vulnerability
Published 2022-09-13 · Modified
8.8EPSS 0.021
CVE-2022-38008
Microsoft SharePoint Server Remote Code Execution Vulnerability
Published 2022-09-13 · Modified
8.8EPSS 0.020
CVE-2022-44693
Microsoft SharePoint Server Remote Code Execution Vulnerability
Published 2022-12-13 · Modified
8.8EPSS 0.020
CVE-2021-43876
Microsoft SharePoint Elevation of Privilege Vulnerability
Published 2021-12-29 · Modified
8.8EPSS 0.019
1 / 3Next →