VendorsMicrosoftsharepoint_foundationall versions
Vulnerabilities

Microsoft SharePoint Foundation

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

226CVEs
CVE-2020-0920
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0929, CVE-2020-0931, CVE-2020-0932, CVE-2020-0971, CVE-2020-0974.
Published 2020-04-15 · Modified
8.8EPSS 0.104
CVE-2019-0952
A remote code execution vulnerability exists in Microsoft SharePoint Server when it fails to properly identify and filter unsafe ASP.Net web controls, aka 'Microsoft SharePoint Server Remote Code Execution Vulnerability'.
Published 2019-05-16 · Modified
8.8EPSS 0.096
CVE-2020-0850
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0851, CVE-2020-0852, CVE-2020-0855, CVE-2020-0892.
Published 2020-03-12 · Modified
8.8EPSS 0.088
CVE-2019-1296
A remote code execution vulnerability exists in Microsoft SharePoint where APIs aren't properly protected from unsafe data input, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1257, CVE-2019-1295.
Published 2019-09-11 · Modified
8.8EPSS 0.083
CVE-2019-1295
A remote code execution vulnerability exists in Microsoft SharePoint where APIs aren't properly protected from unsafe data input, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1257, CVE-2019-1296.
Published 2019-09-11 · Modified
8.8EPSS 0.083
CVE-2021-34467
Microsoft SharePoint Server Remote Code Execution Vulnerability
Published 2021-07-16 · Modified
8.8EPSS 0.066
CVE-2021-41344
Microsoft SharePoint Server Remote Code Execution Vulnerability
Published 2021-10-13 · Modified
8.8EPSS 0.065
CVE-2021-24066
Microsoft SharePoint Remote Code Execution Vulnerability
Published 2021-02-25 · Modified
8.8EPSS 0.063
CVE-2018-0790
Microsoft SharePoint Foundation 2010, Microsoft SharePoint Server 2013 and Microsoft SharePoint Server 2016 allow an elevation of privilege vulnerability due to the way web requests are handled, aka "Microsoft SharePoint Elevation of Privilege Vulnerability". This CVE is unique from CVE-2018-0789.
Published 2018-01-10 · Modified
8.8EPSS 0.053
CVE-2021-34520
Microsoft SharePoint Server Remote Code Execution Vulnerability
Published 2021-07-14 · Modified
8.8EPSS 0.044
CVE-2020-17061
Microsoft SharePoint Remote Code Execution Vulnerability
Published 2020-11-11 · Modified
8.8EPSS 0.043
CVE-2020-1069
A remote code execution vulnerability exists in Microsoft SharePoint Server when it fails to properly identify and filter unsafe ASP.Net web controls, aka 'Microsoft SharePoint Server Remote Code Execution Vulnerability'.
Published 2020-05-21 · Modified
8.8EPSS 0.040
CVE-2020-1024
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1023, CVE-2020-1102.
Published 2020-05-21 · Modified
8.8EPSS 0.037
CVE-2020-1023
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1024, CVE-2020-1102.
Published 2020-05-21 · Modified
8.8EPSS 0.037
CVE-2020-1460
Microsoft SharePoint Server Remote Code Execution Vulnerability
Published 2020-09-11 · Modified
8.8EPSS 0.037
CVE-2022-30158
Microsoft SharePoint Server Remote Code Execution Vulnerability
Published 2022-06-15 · Modified
8.8EPSS 0.034
CVE-2019-0958
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0957.
Published 2019-05-16 · Modified
8.8EPSS 0.033
CVE-2020-17016
Microsoft SharePoint Server Spoofing Vulnerability
Published 2020-11-11 · Modified
8.8EPSS 0.032
CVE-2020-17121
Microsoft SharePoint Remote Code Execution Vulnerability
Published 2020-12-09 · Modified
8.8EPSS 0.030
CVE-2021-26420
Microsoft SharePoint Server Remote Code Execution Vulnerability
Published 2021-06-08 · Modified
8.8EPSS 0.030
CVE-2022-41038
Microsoft SharePoint Server Remote Code Execution Vulnerability
Published 2022-10-11 · Modified
8.8EPSS 0.029
CVE-2023-21744
Microsoft SharePoint Server Remote Code Execution Vulnerability
Published 2023-01-10 · Modified
8.8EPSS 0.028
CVE-2021-42309
Microsoft SharePoint Server Remote Code Execution Vulnerability
Published 2021-12-15 · Modified
8.8EPSS 0.027
CVE-2021-1718
Microsoft SharePoint Server Tampering Vulnerability
Published 2021-01-12 · Modified
8.8EPSS 0.026
CVE-2021-24072
Microsoft SharePoint Server Remote Code Execution Vulnerability
Published 2021-02-25 · Modified
8.8EPSS 0.024
CVE-2022-38009
Microsoft SharePoint Server Remote Code Execution Vulnerability
Published 2022-09-13 · Modified
8.8EPSS 0.021
CVE-2021-31963
Microsoft SharePoint Server Remote Code Execution Vulnerability
Published 2021-06-08 · Modified
8.8EPSS 0.021
CVE-2022-38008
Microsoft SharePoint Server Remote Code Execution Vulnerability
Published 2022-09-13 · Modified
8.8EPSS 0.020
CVE-2022-44693
Microsoft SharePoint Server Remote Code Execution Vulnerability
Published 2022-12-13 · Modified
8.8EPSS 0.020
CVE-2022-41037
Microsoft SharePoint Server Remote Code Execution Vulnerability
Published 2022-10-11 · Modified
8.8EPSS 0.017
CVE-2022-41036
Microsoft SharePoint Server Remote Code Execution Vulnerability
Published 2022-10-11 · Modified
8.8EPSS 0.017
CVE-2022-41062
Microsoft SharePoint Server Remote Code Execution Vulnerability
Published 2022-11-09 · Modified
8.8EPSS 0.016
CVE-2020-1576
Microsoft SharePoint Remote Code Execution Vulnerability
Published 2020-09-11 · Modified
8.8EPSS 0.016
CVE-2019-1261
A spoofing vulnerability exists in Microsoft SharePoint when it improperly handles requests to authorize applications, resulting in cross-site request forgery (CSRF).To exploit this vulnerability, an attacker would need to create a page specifically designed to cause a cross-site request, aka 'Microsoft SharePoint Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-1259.
Published 2019-09-11 · Modified
8.8EPSS 0.016
CVE-2019-1259
A spoofing vulnerability exists in Microsoft SharePoint when it improperly handles requests to authorize applications, resulting in cross-site request forgery (CSRF).To exploit this vulnerability, an attacker would need to create a page specifically designed to cause a cross-site request, aka 'Microsoft SharePoint Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-1261.
Published 2019-09-11 · Modified
8.8EPSS 0.015
CVE-2023-21717
Microsoft SharePoint Server Elevation of Privilege Vulnerability
Published 2023-02-14 · Modified
8.8EPSS 0.011
CVE-2020-16944
Microsoft SharePoint Reflective XSS Vulnerability
Published 2020-10-16 · Modified
8.7EPSS 0.018
CVE-2020-16945
Microsoft Office SharePoint XSS Vulnerability
Published 2020-10-16 · Modified
8.7EPSS 0.017
CVE-2020-16946
Microsoft Office SharePoint XSS Vulnerability
Published 2020-10-16 · Modified
8.7EPSS 0.016
CVE-2020-16952
Microsoft SharePoint Remote Code Execution Vulnerability
Published 2020-10-16 · Modified
8.6EPSS 0.711
← Prev2 / 6Next →