VendorsMicrosoftsharepoint_foundation2013
Vulnerabilities

Microsoft SharePoint Foundation 2013

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

191CVEs
CVE-2020-17115
Microsoft SharePoint Server Spoofing Vulnerability
Published 2020-12-09 · Modified
8.0EPSS 0.027
CVE-2021-1712
Microsoft SharePoint Elevation of Privilege Vulnerability
Published 2021-01-12 · Modified
8.0EPSS 0.022
CVE-2021-34468
Microsoft SharePoint Server Remote Code Execution Vulnerability
Published 2021-07-14 · Modified
8.0EPSS 0.021
CVE-2021-1726
Microsoft SharePoint Server Spoofing Vulnerability
Published 2021-02-25 · Modified
8.0EPSS 0.021
CVE-2022-21987
Microsoft SharePoint Server Spoofing Vulnerability
Published 2022-02-09 · Modified
8.0EPSS 0.020
CVE-2022-24472
Microsoft SharePoint Server Spoofing Vulnerability
Published 2022-04-15 · Modified
8.0EPSS 0.020
CVE-2021-28478
Microsoft SharePoint Server Spoofing Vulnerability
Published 2021-05-11 · Modified
7.6EPSS 0.016
CVE-2021-40484
Microsoft SharePoint Server Spoofing Vulnerability
Published 2021-10-13 · Modified
7.6EPSS 0.014
CVE-2021-38651
Microsoft SharePoint Server Spoofing Vulnerability
Published 2021-09-15 · Modified
7.6EPSS 0.013
CVE-2021-38652
Microsoft SharePoint Server Spoofing Vulnerability
Published 2021-09-15 · Modified
7.6EPSS 0.013
CVE-2021-43242
Microsoft SharePoint Server Spoofing Vulnerability
Published 2021-12-15 · Modified
7.6EPSS 0.012
CVE-2019-1006
An authentication bypass vulnerability exists in Windows Communication Foundation (WCF) and Windows Identity Foundation (WIF), allowing signing of SAML tokens with arbitrary symmetric keys, aka 'WCF/WIF SAML Token Authentication Bypass Vulnerability'.
Published 2019-07-15 · Modified
7.5EPSS 0.060
CVE-2020-1345
Microsoft Office SharePoint XSS Vulnerability
Published 2020-09-11 · Modified
7.4EPSS 0.027
CVE-2020-1198
Microsoft Office SharePoint XSS Vulnerability
Published 2020-09-11 · Modified
7.4EPSS 0.027
CVE-2021-31966
Microsoft SharePoint Server Remote Code Execution Vulnerability
Published 2021-06-08 · Modified
7.2EPSS 0.046
CVE-2021-42294
Microsoft SharePoint Server Remote Code Execution Vulnerability
Published 2021-12-15 · Modified
7.2EPSS 0.022
CVE-2021-31172
Microsoft SharePoint Server Spoofing Vulnerability
Published 2021-05-11 · Modified
7.1EPSS 0.018
CVE-2021-26418
Microsoft SharePoint Server Spoofing Vulnerability
Published 2021-05-11 · Modified
7.1EPSS 0.012
CVE-2020-17017
Microsoft SharePoint Information Disclosure Vulnerability
Published 2020-11-11 · Modified
6.8EPSS 0.038
CVE-2019-1443
An information disclosure vulnerability exists in Microsoft SharePoint when an attacker uploads a specially crafted file to the SharePoint Server.An authenticated attacker who successfully exploited this vulnerability could potentially leverage SharePoint functionality to obtain SMB hashes.The security update addresses the vulnerability by correcting how SharePoint checks file content., aka 'Microsoft SharePoint Information Disclosure Vulnerability'.
Published 2019-11-12 · Modified
6.5EPSS 0.057
CVE-2019-0956
An information disclosure vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Server Information Disclosure Vulnerability'.
Published 2019-05-16 · Modified
6.5EPSS 0.052
CVE-2021-31965
Microsoft SharePoint Server Information Disclosure Vulnerability
Published 2021-06-08 · Modified
6.5EPSS 0.045
CVE-2020-16948
Microsoft SharePoint Information Disclosure Vulnerability
Published 2020-10-16 · Modified
6.5EPSS 0.038
CVE-2020-16953
Microsoft SharePoint Information Disclosure Vulnerability
Published 2020-10-16 · Modified
6.5EPSS 0.038
CVE-2020-16979
Microsoft SharePoint Information Disclosure Vulnerability
Published 2020-11-11 · Modified
6.5EPSS 0.031
CVE-2020-17120
Microsoft SharePoint Information Disclosure Vulnerability
Published 2020-12-09 · Modified
6.5EPSS 0.031
CVE-2021-24071
Microsoft SharePoint Information Disclosure Vulnerability
Published 2021-02-25 · Modified
6.5EPSS 0.027
CVE-2019-1260
An elevation of privilege vulnerability exists in Microsoft SharePoint, aka 'Microsoft SharePoint Elevation of Privilege Vulnerability'.
Published 2019-09-11 · Modified
6.5EPSS 0.026
CVE-2019-1330
An elevation of privilege vulnerability exists in Microsoft SharePoint, aka 'Microsoft SharePoint Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1329.
Published 2019-10-10 · Modified
6.5EPSS 0.026
CVE-2020-1103
An information disclosure vulnerability exists where certain modes of the search function in Microsoft SharePoint Server are vulnerable to cross-site search attacks (a variant of cross-site request forgery, CSRF).When users are simultaneously logged in to Microsoft SharePoint Server and visit a malicious web page, the attacker can, through standard browser functionality, induce the browser to invoke search queries as the logged in user, aka 'Microsoft SharePoint Information Disclosure Vulnerability'.
Published 2020-05-21 · Modified
6.5EPSS 0.024
CVE-2021-31173
Microsoft SharePoint Server Information Disclosure Vulnerability
Published 2021-05-11 · Modified
6.5EPSS 0.021
CVE-2020-17015
Microsoft SharePoint Server Spoofing Vulnerability
Published 2020-11-11 · Modified
6.5EPSS 0.020
CVE-2022-41122
Microsoft SharePoint Server Spoofing Vulnerability
Published 2022-11-09 · Modified
6.5EPSS 0.016
CVE-2020-1482
Microsoft Office SharePoint XSS Vulnerability
Published 2020-09-11 · Modified
6.3EPSS 0.020
CVE-2017-0107
Microsoft SharePoint Server fails to sanitize crafted web requests, allowing remote attackers to run cross-script in local security context, aka "Microsoft SharePoint XSS Vulnerability."
Published 2017-03-17 · Modified
6.1EPSS 0.070
CVE-2015-6117
Microsoft SharePoint Server 2013 SP1 and SharePoint Foundation 2013 SP1 allow remote authenticated users to bypass intended Access Control Policy restrictions and conduct cross-site scripting (XSS) attacks by modifying a webpart, aka "Microsoft SharePoint Security Feature Bypass," a different vulnerability than CVE-2016-0011.
Published 2016-01-13 · Modified
6.1EPSS 0.069
CVE-2016-0039
Cross-site scripting (XSS) vulnerability in SharePoint Server in Microsoft SharePoint Foundation 2013 SP1 allows remote attackers to inject arbitrary web script or HTML via a crafted request, aka "Microsoft SharePoint XSS Vulnerability."
Published 2016-02-10 · Modified
6.1EPSS 0.060
CVE-2020-1106
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE-2020-1099, CVE-2020-1100, CVE-2020-1101.
Published 2020-05-21 · Modified
6.1EPSS 0.040
CVE-2019-0670
A spoofing vulnerability exists in Microsoft SharePoint when the application does not properly parse HTTP content, aka 'Microsoft SharePoint Spoofing Vulnerability'.
Published 2019-03-06 · Modified
6.1EPSS 0.025
CVE-2021-1717
Microsoft SharePoint Server Spoofing Vulnerability
Published 2021-01-12 · Modified
5.8EPSS 0.018
← Prev3 / 5Next →