VendorsMicrosoftsharepoint_foundationall versions
Vulnerabilities

Microsoft SharePoint Foundation

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

226CVEs
CVE-2020-1452
Microsoft SharePoint Remote Code Execution Vulnerability
Published 2020-09-11 · Modified
8.6EPSS 0.022
CVE-2020-1453
Microsoft SharePoint Remote Code Execution Vulnerability
Published 2020-09-11 · Modified
8.6EPSS 0.022
CVE-2020-1200
Microsoft SharePoint Remote Code Execution Vulnerability
Published 2020-09-11 · Modified
8.6EPSS 0.021
CVE-2020-16951
Microsoft SharePoint Remote Code Execution Vulnerability
Published 2020-10-16 · Modified
8.6EPSS 0.014
CVE-2023-28288
Microsoft SharePoint Server Spoofing Vulnerability
Published 2023-04-11 · Modified
8.11 PoCEPSS 0.062
CVE-2021-31950
Microsoft SharePoint Server Spoofing Vulnerability
Published 2021-06-08 · Modified
8.11 PoCEPSS 0.046
CVE-2021-31964
Microsoft SharePoint Server Spoofing Vulnerability
Published 2021-06-08 · Modified
8.1EPSS 0.015
CVE-2021-31948
Microsoft SharePoint Server Spoofing Vulnerability
Published 2021-06-08 · Modified
8.1EPSS 0.013
CVE-2020-17089
Microsoft SharePoint Elevation of Privilege Vulnerability
Published 2020-12-09 · Modified
8.0EPSS 0.029
CVE-2020-17115
Microsoft SharePoint Server Spoofing Vulnerability
Published 2020-12-09 · Modified
8.0EPSS 0.027
CVE-2021-1712
Microsoft SharePoint Elevation of Privilege Vulnerability
Published 2021-01-12 · Modified
8.0EPSS 0.022
CVE-2021-34468
Microsoft SharePoint Server Remote Code Execution Vulnerability
Published 2021-07-14 · Modified
8.0EPSS 0.021
CVE-2021-1726
Microsoft SharePoint Server Spoofing Vulnerability
Published 2021-02-25 · Modified
8.0EPSS 0.021
CVE-2022-21987
Microsoft SharePoint Server Spoofing Vulnerability
Published 2022-02-09 · Modified
8.0EPSS 0.020
CVE-2022-24472
Microsoft SharePoint Server Spoofing Vulnerability
Published 2022-04-15 · Modified
8.0EPSS 0.020
CVE-2013-0085
Buffer overflow in Microsoft SharePoint Server 2010 SP1 and SharePoint Foundation 2010 SP1 allows remote attackers to cause a denial of service (W3WP process crash and site outage) via a crafted URL, aka "Buffer Overflow Vulnerability."
Published 2013-03-13 · Modified
7.8EPSS 0.340
CVE-2021-28478
Microsoft SharePoint Server Spoofing Vulnerability
Published 2021-05-11 · Modified
7.6EPSS 0.016
CVE-2021-40484
Microsoft SharePoint Server Spoofing Vulnerability
Published 2021-10-13 · Modified
7.6EPSS 0.014
CVE-2021-38651
Microsoft SharePoint Server Spoofing Vulnerability
Published 2021-09-15 · Modified
7.6EPSS 0.013
CVE-2021-38652
Microsoft SharePoint Server Spoofing Vulnerability
Published 2021-09-15 · Modified
7.6EPSS 0.013
CVE-2021-43242
Microsoft SharePoint Server Spoofing Vulnerability
Published 2021-12-15 · Modified
7.6EPSS 0.012
CVE-2013-0084
Directory traversal vulnerability in Microsoft SharePoint Server 2010 SP1 and SharePoint Foundation 2010 SP1 allows remote attackers to bypass intended read restrictions for content, and hijack user accounts, via a crafted URL, aka "SharePoint Directory Traversal Vulnerability."
Published 2013-03-13 · Modified
7.5EPSS 0.214
CVE-2013-0080
Microsoft SharePoint Server 2010 SP1 and SharePoint Foundation 2010 SP1 allow remote attackers to bypass intended read restrictions for content, and hijack user accounts, via a crafted URL, aka "Callback Function Vulnerability."
Published 2013-03-13 · Modified
7.5EPSS 0.193
CVE-2019-1006
An authentication bypass vulnerability exists in Windows Communication Foundation (WCF) and Windows Identity Foundation (WIF), allowing signing of SAML tokens with arbitrary symmetric keys, aka 'WCF/WIF SAML Token Authentication Bypass Vulnerability'.
Published 2019-07-15 · Modified
7.5EPSS 0.060
CVE-2020-1345
Microsoft Office SharePoint XSS Vulnerability
Published 2020-09-11 · Modified
7.4EPSS 0.027
CVE-2020-1198
Microsoft Office SharePoint XSS Vulnerability
Published 2020-09-11 · Modified
7.4EPSS 0.027
CVE-2021-31966
Microsoft SharePoint Server Remote Code Execution Vulnerability
Published 2021-06-08 · Modified
7.2EPSS 0.046
CVE-2021-42294
Microsoft SharePoint Server Remote Code Execution Vulnerability
Published 2021-12-15 · Modified
7.2EPSS 0.022
CVE-2021-31172
Microsoft SharePoint Server Spoofing Vulnerability
Published 2021-05-11 · Modified
7.1EPSS 0.018
CVE-2021-26418
Microsoft SharePoint Server Spoofing Vulnerability
Published 2021-05-11 · Modified
7.1EPSS 0.012
CVE-2020-17017
Microsoft SharePoint Information Disclosure Vulnerability
Published 2020-11-11 · Modified
6.8EPSS 0.038
CVE-2019-1443
An information disclosure vulnerability exists in Microsoft SharePoint when an attacker uploads a specially crafted file to the SharePoint Server.An authenticated attacker who successfully exploited this vulnerability could potentially leverage SharePoint functionality to obtain SMB hashes.The security update addresses the vulnerability by correcting how SharePoint checks file content., aka 'Microsoft SharePoint Information Disclosure Vulnerability'.
Published 2019-11-12 · Modified
6.5EPSS 0.057
CVE-2019-0956
An information disclosure vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Server Information Disclosure Vulnerability'.
Published 2019-05-16 · Modified
6.5EPSS 0.052
CVE-2021-31965
Microsoft SharePoint Server Information Disclosure Vulnerability
Published 2021-06-08 · Modified
6.5EPSS 0.045
CVE-2020-16953
Microsoft SharePoint Information Disclosure Vulnerability
Published 2020-10-16 · Modified
6.5EPSS 0.038
CVE-2020-16948
Microsoft SharePoint Information Disclosure Vulnerability
Published 2020-10-16 · Modified
6.5EPSS 0.038
CVE-2020-16979
Microsoft SharePoint Information Disclosure Vulnerability
Published 2020-11-11 · Modified
6.5EPSS 0.031
CVE-2020-17120
Microsoft SharePoint Information Disclosure Vulnerability
Published 2020-12-09 · Modified
6.5EPSS 0.031
CVE-2021-24071
Microsoft SharePoint Information Disclosure Vulnerability
Published 2021-02-25 · Modified
6.5EPSS 0.027
CVE-2019-1330
An elevation of privilege vulnerability exists in Microsoft SharePoint, aka 'Microsoft SharePoint Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1329.
Published 2019-10-10 · Modified
6.5EPSS 0.026
← Prev3 / 6Next →