VendorsMicrosoftsharepoint_foundationall versions
Vulnerabilities

Microsoft SharePoint Foundation

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

226CVEs
CVE-2019-1260
An elevation of privilege vulnerability exists in Microsoft SharePoint, aka 'Microsoft SharePoint Elevation of Privilege Vulnerability'.
Published 2019-09-11 · Modified
6.5EPSS 0.026
CVE-2021-28450
Microsoft SharePoint Denial of Service Vulnerability
Published 2021-04-13 · Modified
6.5EPSS 0.024
CVE-2020-1103
An information disclosure vulnerability exists where certain modes of the search function in Microsoft SharePoint Server are vulnerable to cross-site search attacks (a variant of cross-site request forgery, CSRF).When users are simultaneously logged in to Microsoft SharePoint Server and visit a malicious web page, the attacker can, through standard browser functionality, induce the browser to invoke search queries as the logged in user, aka 'Microsoft SharePoint Information Disclosure Vulnerability'.
Published 2020-05-21 · Modified
6.5EPSS 0.024
CVE-2021-31173
Microsoft SharePoint Server Information Disclosure Vulnerability
Published 2021-05-11 · Modified
6.5EPSS 0.021
CVE-2020-17015
Microsoft SharePoint Server Spoofing Vulnerability
Published 2020-11-11 · Modified
6.5EPSS 0.020
CVE-2022-41122
Microsoft SharePoint Server Spoofing Vulnerability
Published 2022-11-09 · Modified
6.5EPSS 0.016
CVE-2020-1482
Microsoft Office SharePoint XSS Vulnerability
Published 2020-09-11 · Modified
6.3EPSS 0.020
CVE-2017-0107
Microsoft SharePoint Server fails to sanitize crafted web requests, allowing remote attackers to run cross-script in local security context, aka "Microsoft SharePoint XSS Vulnerability."
Published 2017-03-17 · Modified
6.1EPSS 0.070
CVE-2015-6117
Microsoft SharePoint Server 2013 SP1 and SharePoint Foundation 2013 SP1 allow remote authenticated users to bypass intended Access Control Policy restrictions and conduct cross-site scripting (XSS) attacks by modifying a webpart, aka "Microsoft SharePoint Security Feature Bypass," a different vulnerability than CVE-2016-0011.
Published 2016-01-13 · Modified
6.1EPSS 0.069
CVE-2016-0039
Cross-site scripting (XSS) vulnerability in SharePoint Server in Microsoft SharePoint Foundation 2013 SP1 allows remote attackers to inject arbitrary web script or HTML via a crafted request, aka "Microsoft SharePoint XSS Vulnerability."
Published 2016-02-10 · Modified
6.1EPSS 0.060
CVE-2020-1106
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE-2020-1099, CVE-2020-1100, CVE-2020-1101.
Published 2020-05-21 · Modified
6.1EPSS 0.040
CVE-2019-0670
A spoofing vulnerability exists in Microsoft SharePoint when the application does not properly parse HTTP content, aka 'Microsoft SharePoint Spoofing Vulnerability'.
Published 2019-03-06 · Modified
6.1EPSS 0.025
CVE-2015-1700
Microsoft SharePoint Server 2007 SP3, SharePoint Foundation 2010 SP2, SharePoint Server 2010 SP2, and SharePoint Foundation 2013 SP1 allow remote authenticated users to execute arbitrary code via crafted page content, aka "Microsoft SharePoint Page Content Vulnerabilities."
Published 2015-05-13 · Modified
6.0EPSS 0.121
CVE-2021-1641
Microsoft SharePoint Server Spoofing Vulnerability
Published 2021-01-12 · Modified
5.8EPSS 0.018
CVE-2021-1717
Microsoft SharePoint Server Spoofing Vulnerability
Published 2021-01-12 · Modified
5.8EPSS 0.018
CVE-2021-24104
Microsoft SharePoint Server Spoofing Vulnerability
Published 2021-03-11 · Modified
5.8EPSS 0.014
CVE-2019-0949
A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-0950, CVE-2019-0951.
Published 2019-05-16 · Modified
5.7EPSS 0.025
CVE-2019-0950
A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-0949, CVE-2019-0951.
Published 2019-05-16 · Modified
5.7EPSS 0.025
CVE-2020-1573
Microsoft Office SharePoint XSS Vulnerability
Published 2020-08-17 · Modified
5.5EPSS 0.019
CVE-2020-1499
Microsoft SharePoint Spoofing Vulnerability
Published 2020-08-17 · Modified
5.5EPSS 0.018
CVE-2020-1501
Microsoft SharePoint Spoofing Vulnerability
Published 2020-08-17 · Modified
5.5EPSS 0.017
CVE-2020-1505
Microsoft SharePoint Information Disclosure Vulnerability
Published 2020-08-17 · Modified
5.5EPSS 0.013
CVE-2020-16941
Microsoft SharePoint Information Disclosure Vulnerability
Published 2020-10-16 · Modified
5.5EPSS 0.009
CVE-2016-0011
Microsoft SharePoint Server 2013 SP1 and SharePoint Foundation 2013 SP1 allow remote authenticated users to bypass intended Access Control Policy restrictions and conduct cross-site scripting (XSS) attacks by modifying a webpart, aka "Microsoft SharePoint Security Feature Bypass," a different vulnerability than CVE-2015-6117.
Published 2016-01-13 · Modified
5.4EPSS 0.053
CVE-2019-1262
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'.
Published 2019-09-11 · Modified
5.41 PoCEPSS 0.030
CVE-2018-8155
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft SharePoint. This CVE ID is unique from CVE-2018-8149, CVE-2018-8156, CVE-2018-8168.
Published 2018-05-09 · Modified
5.4EPSS 0.029
CVE-2018-8252
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft SharePoint. This CVE ID is unique from CVE-2018-8254.
Published 2018-06-14 · Modified
5.4EPSS 0.028
CVE-2018-8254
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft Project Server, Microsoft SharePoint. This CVE ID is unique from CVE-2018-8252.
Published 2018-06-14 · Modified
5.4EPSS 0.028
CVE-2018-8299
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft SharePoint. This CVE ID is unique from CVE-2018-8323.
Published 2018-07-11 · Modified
5.4EPSS 0.025
CVE-2018-8568
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft SharePoint Server, Microsoft SharePoint. This CVE ID is unique from CVE-2018-8572.
Published 2018-11-14 · Modified
5.4EPSS 0.023
CVE-2020-0976
A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Spoofing Vulnerability'. This CVE ID is unique from CVE-2020-0972, CVE-2020-0975, CVE-2020-0977.
Published 2020-04-15 · Modified
5.4EPSS 0.022
CVE-2020-0924
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE-2020-0923, CVE-2020-0925, CVE-2020-0926, CVE-2020-0927, CVE-2020-0930, CVE-2020-0933, CVE-2020-0954, CVE-2020-0973, CVE-2020-0978.
Published 2020-04-15 · Modified
5.4EPSS 0.018
CVE-2017-8745
An elevation of privilege vulnerability exists in Microsoft SharePoint Foundation 2013 Service Pack 1 when it does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Cross Site Scripting Vulnerability".
Published 2017-09-13 · Modified
5.4EPSS 0.018
CVE-2020-1100
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE-2020-1099, CVE-2020-1101, CVE-2020-1106.
Published 2020-05-21 · Modified
5.4EPSS 0.017
CVE-2020-1101
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE-2020-1099, CVE-2020-1100, CVE-2020-1106.
Published 2020-05-21 · Modified
5.4EPSS 0.017
CVE-2017-0255
Microsoft SharePoint Foundation 2013 SP1 allows an elevation of privilege vulnerability when it does not properly sanitize a specially crafted web request, aka "Microsoft SharePoint XSS Vulnerability".
Published 2017-05-12 · Modified
5.4EPSS 0.017
CVE-2020-1104
A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Spoofing Vulnerability'. This CVE ID is unique from CVE-2020-1105, CVE-2020-1107.
Published 2020-05-21 · Modified
5.4EPSS 0.017
CVE-2019-1031
Microsoft Office SharePoint XSS Vulnerability
Published 2019-06-12 · Modified
5.4EPSS 0.017
CVE-2019-1033
Microsoft Office SharePoint XSS Vulnerability
Published 2019-06-12 · Modified
5.4EPSS 0.017
CVE-2019-1036
Microsoft Office SharePoint XSS Vulnerability
Published 2019-06-12 · Modified
5.4EPSS 0.017
← Prev4 / 6Next →