VendorsMicrosoftsharepoint_foundation2010
Vulnerabilities

Microsoft SharePoint Foundation 2010

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

90CVEs
CVE-2020-17017
Microsoft SharePoint Information Disclosure Vulnerability
Published 2020-11-11 · Modified
6.8EPSS 0.038
CVE-2019-1443
An information disclosure vulnerability exists in Microsoft SharePoint when an attacker uploads a specially crafted file to the SharePoint Server.An authenticated attacker who successfully exploited this vulnerability could potentially leverage SharePoint functionality to obtain SMB hashes.The security update addresses the vulnerability by correcting how SharePoint checks file content., aka 'Microsoft SharePoint Information Disclosure Vulnerability'.
Published 2019-11-12 · Modified
6.5EPSS 0.057
CVE-2020-16948
Microsoft SharePoint Information Disclosure Vulnerability
Published 2020-10-16 · Modified
6.5EPSS 0.038
CVE-2020-17120
Microsoft SharePoint Information Disclosure Vulnerability
Published 2020-12-09 · Modified
6.5EPSS 0.031
CVE-2021-24071
Microsoft SharePoint Information Disclosure Vulnerability
Published 2021-02-25 · Modified
6.5EPSS 0.027
CVE-2019-1260
An elevation of privilege vulnerability exists in Microsoft SharePoint, aka 'Microsoft SharePoint Elevation of Privilege Vulnerability'.
Published 2019-09-11 · Modified
6.5EPSS 0.026
CVE-2021-28450
Microsoft SharePoint Denial of Service Vulnerability
Published 2021-04-13 · Modified
6.5EPSS 0.024
CVE-2020-1482
Microsoft Office SharePoint XSS Vulnerability
Published 2020-09-11 · Modified
6.3EPSS 0.020
CVE-2015-1700
Microsoft SharePoint Server 2007 SP3, SharePoint Foundation 2010 SP2, SharePoint Server 2010 SP2, and SharePoint Foundation 2013 SP1 allow remote authenticated users to execute arbitrary code via crafted page content, aka "Microsoft SharePoint Page Content Vulnerabilities."
Published 2015-05-13 · Modified
6.0EPSS 0.121
CVE-2020-1573
Microsoft Office SharePoint XSS Vulnerability
Published 2020-08-17 · Modified
5.5EPSS 0.019
CVE-2020-1499
Microsoft SharePoint Spoofing Vulnerability
Published 2020-08-17 · Modified
5.5EPSS 0.018
CVE-2020-16941
Microsoft SharePoint Information Disclosure Vulnerability
Published 2020-10-16 · Modified
5.5EPSS 0.009
CVE-2020-0972
A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Spoofing Vulnerability'. This CVE ID is unique from CVE-2020-0975, CVE-2020-0976, CVE-2020-0977.
Published 2020-04-15 · Modified
5.4EPSS 0.016
CVE-2020-0975
A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Spoofing Vulnerability'. This CVE ID is unique from CVE-2020-0972, CVE-2020-0976, CVE-2020-0977.
Published 2020-04-15 · Modified
5.4EPSS 0.016
CVE-2019-0951
A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-0949, CVE-2019-0950.
Published 2019-05-16 · Modified
5.4EPSS 0.016
CVE-2019-0831
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE-2019-0830.
Published 2019-04-09 · Modified
5.4EPSS 0.016
CVE-2020-1320
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE-2020-1177, CVE-2020-1183, CVE-2020-1297, CVE-2020-1298, CVE-2020-1318.
Published 2020-06-09 · Modified
5.4EPSS 0.015
CVE-2020-1298
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE-2020-1177, CVE-2020-1183, CVE-2020-1297, CVE-2020-1318, CVE-2020-1320.
Published 2020-06-09 · Modified
5.4EPSS 0.015
CVE-2019-1328
A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Spoofing Vulnerability'.
Published 2019-10-10 · Modified
5.4EPSS 0.015
CVE-2019-1329
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1330.
Published 2019-10-10 · Modified
5.4EPSS 0.015
CVE-2020-0925
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE-2020-0923, CVE-2020-0924, CVE-2020-0926, CVE-2020-0927, CVE-2020-0930, CVE-2020-0933, CVE-2020-0954, CVE-2020-0973, CVE-2020-0978.
Published 2020-04-15 · Modified
5.4EPSS 0.015
CVE-2020-0891
This vulnerability is caused when SharePoint Server does not properly sanitize a specially crafted request to an affected SharePoint server.An authenticated attacker could exploit this vulnerability by sending a specially crafted request to an affected SharePoint server, aka 'Microsoft SharePoint Reflective XSS Vulnerability'. This CVE ID is unique from CVE-2020-0795.
Published 2020-03-12 · Modified
5.4EPSS 0.015
CVE-2020-1297
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE-2020-1177, CVE-2020-1183, CVE-2020-1298, CVE-2020-1318, CVE-2020-1320.
Published 2020-06-09 · Modified
5.4EPSS 0.015
CVE-2020-1318
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE-2020-1177, CVE-2020-1183, CVE-2020-1297, CVE-2020-1298, CVE-2020-1320.
Published 2020-06-09 · Modified
5.4EPSS 0.015
CVE-2020-1289
A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Spoofing Vulnerability'. This CVE ID is unique from CVE-2020-1148.
Published 2020-06-09 · Modified
5.4EPSS 0.015
CVE-2020-0894
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE-2020-0893.
Published 2020-03-12 · Modified
5.4EPSS 0.013
CVE-2013-0081
Microsoft SharePoint Portal Server 2003 SP3 and SharePoint Server 2007 SP3, 2010 SP1 and SP2, and 2013 do not properly process unassigned workflows, which allows remote attackers to cause a denial of service (W3WP process hang) via a crafted URL, aka "SharePoint Denial of Service Vulnerability."
Published 2013-09-11 · Modified
5.0EPSS 0.767
CVE-2013-0086
Microsoft OneNote 2010 SP1 does not properly determine buffer sizes during memory allocation, which allows remote attackers to obtain sensitive information via a crafted OneNote file, aka "Buffer Size Validation Vulnerability."
Published 2013-03-13 · Modified
5.0EPSS 0.240
CVE-2020-1205
Microsoft SharePoint Spoofing Vulnerability
Published 2020-09-11 · Modified
4.9EPSS 0.018
CVE-2019-1202
SharePoint Information Disclosure Vulnerability
Published 2019-08-14 · Modified
4.4EPSS 0.016
CVE-2020-16942
Microsoft SharePoint Information Disclosure Vulnerability
Published 2020-10-16 · Modified
4.4EPSS 0.009
CVE-2013-3180
Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2010 SP1 and SP2 and 2013 allows remote attackers to inject arbitrary web script or HTML via a crafted POST request, aka "POST XSS Vulnerability."
Published 2013-09-11 · Modified
4.3EPSS 0.656
CVE-2012-2520
Cross-site scripting (XSS) vulnerability in Microsoft InfoPath 2007 SP2 and SP3 and 2010 SP1, Communicator 2007 R2, Lync 2010 and 2010 Attendee, SharePoint Server 2007 SP2 and SP3 and 2010 SP1, Groove Server 2010 SP1, Windows SharePoint Services 3.0 SP2, SharePoint Foundation 2010 SP1, and Office Web Apps 2010 SP1 allows remote attackers to inject arbitrary web script or HTML via a crafted string, aka "HTML Sanitization Vulnerability."
Published 2012-10-09 · Modified
4.3EPSS 0.285
CVE-2010-3324
The toStaticHTML function in Microsoft Internet Explorer 8, and the SafeHTML function in Microsoft Windows SharePoint Services 3.0 SP2, SharePoint Foundation 2010, Office SharePoint Server 2007 SP2, Groove Server 2010, and Office Web Apps, allows remote attackers to bypass the cross-site scripting (XSS) protection mechanism and conduct XSS attacks via a crafted use of the Cascading Style Sheets (CSS) @import rule, aka "HTML Sanitization Vulnerability," a different vulnerability than CVE-2010-1257.
Published 2010-09-17 · Modified
4.31 PoCEPSS 0.250
CVE-2012-1859
Cross-site scripting (XSS) vulnerability in scriptresx.ashx in Microsoft SharePoint Server 2010 Gold and SP1, SharePoint Foundation 2010 Gold and SP1, and Office Web Apps 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via crafted JavaScript elements in a URL, aka "XSS scriptresx.ashx Vulnerability."
Published 2012-07-10 · Modified
4.3EPSS 0.231
CVE-2012-1863
Cross-site scripting (XSS) vulnerability in Microsoft Office SharePoint Server 2007 SP2 and SP3 Windows SharePoint Services 3.0 SP2, and SharePoint Foundation 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via crafted JavaScript elements in a URL, aka "SharePoint Reflected List Parameter Vulnerability."
Published 2012-07-10 · Modified
4.3EPSS 0.231
CVE-2011-1890
Cross-site scripting (XSS) vulnerability in EditForm.aspx in Microsoft Office SharePoint Server 2010 and SharePoint Foundation 2010 allows remote attackers to inject arbitrary web script or HTML via a post, aka "Editform Script Injection Vulnerability."
Published 2011-09-15 · Modified
4.3EPSS 0.198
CVE-2012-0144
Cross-site scripting (XSS) vulnerability in themeweb.aspx in Microsoft Office SharePoint Server 2010 Gold and SP1 and SharePoint Foundation 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via JavaScript sequences in a URL, aka "XSS in themeweb.aspx Vulnerability."
Published 2012-02-14 · Modified
4.3EPSS 0.180
CVE-2012-0145
Cross-site scripting (XSS) vulnerability in wizardlist.aspx in Microsoft Office SharePoint Server 2010 Gold and SP1 and SharePoint Foundation 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via JavaScript sequences in a URL, aka "XSS in wizardlist.aspx Vulnerability."
Published 2012-02-14 · Modified
4.3EPSS 0.180
CVE-2012-0017
Cross-site scripting (XSS) vulnerability in inplview.aspx in Microsoft SharePoint Foundation 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via JavaScript sequences in a URL, aka "XSS in inplview.aspx Vulnerability."
Published 2012-02-14 · Modified
4.3EPSS 0.180
← Prev2 / 3Next →