VendorsMicrosoftsharepoint_foundation2013
Vulnerabilities

Microsoft SharePoint Foundation 2013

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

191CVEs
CVE-2020-17118
Microsoft SharePoint Remote Code Execution Vulnerability
Published 2020-12-09 · Modified
10.0EPSS 0.038
CVE-2020-1595
Microsoft SharePoint Remote Code Execution Vulnerability
Published 2020-09-11 · Modified
9.9EPSS 0.020
CVE-2020-1210
Microsoft SharePoint Remote Code Execution Vulnerability
Published 2020-09-11 · Modified
9.9EPSS 0.019
CVE-2019-0604
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0594.
Published 2019-03-06 · Analyzed
9.8KEV1 PoCEPSS 0.999
CVE-2023-21716
Microsoft Word Remote Code Execution Vulnerability
Published 2023-02-14 · Modified
9.8EPSS 0.823
CVE-2020-1025
Microsoft Office Elevation of Privilege Vulnerability
Published 2020-07-14 · Modified
9.8EPSS 0.059
CVE-2016-3357
Microsoft Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office 2013 RT SP1, Office 2016, Word for Mac 2011, Word 2016 for Mac, Word Viewer, Word Automation Services on SharePoint Server 2010 SP2, SharePoint Server 2013 SP1, Excel Automation Services on SharePoint Server 2013 SP1, Word Automation Services on SharePoint Server 2013 SP1, Office Web Apps 2010 SP2, and Office Web Apps Server 2013 SP1 allow remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability."
Published 2016-09-14 · Modified
9.31 PoCEPSS 0.548
CVE-2018-8284
A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka ".NET Framework Remote Code Injection Vulnerability." This affects Microsoft .NET Framework 2.0, Microsoft .NET Framework 3.0, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.5.2, Microsoft .NET Framework 4.6, Microsoft .NET Framework 4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.7.1/4.7.2, Microsoft .NET Framework 3.5, Microsoft .NET Framework 3.5.1, Microsoft .NET Framework 4.6/4.6.1/4.6.2, Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2, Microsoft .NET Framework 4.7.2.
Published 2018-07-11 · Modified
9.3EPSS 0.415
CVE-2015-0085
Use-after-free vulnerability in Microsoft Office 2007 SP3, Excel 2007 SP3, PowerPoint 2007 SP3, Word 2007 SP3, Office 2010 SP2, Excel 2010 SP2, PowerPoint 2010 SP2, Word 2010 SP2, Office 2013 Gold and SP1, Word 2013 Gold and SP1, Office 2013 RT Gold and SP1, Word 2013 RT Gold and SP1, Excel Viewer, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2010 SP2, Excel Services on SharePoint Server 2013 Gold and SP1, Word Automation Services on SharePoint Server 2013 Gold and SP1, Web Applications 2010 SP2, Office Web Apps Server 2010 SP2, Web Apps Server 2013 Gold and SP1, SharePoint Server 2007 SP3, Windows SharePoint Services 3.0 SP3, SharePoint Foundation 2010 SP2, SharePoint Server 2010 SP2, SharePoint Foundation 2013 Gold and SP1, and SharePoint Server 2013 Gold and SP1 allows remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Component Use After Free Vulnerability."
Published 2015-03-11 · Modified
9.3EPSS 0.187
CVE-2015-1682
Microsoft Office 2010 SP2, Excel 2010 SP2, PowerPoint 2010 SP2, Word 2010 SP2, Office 2013 SP1, Excel 2013 SP1, PowerPoint 2013 SP1, Word 2013 SP1, Office 2013 RT SP1, Excel 2013 RT SP1, PowerPoint 2013 RT SP1, Word 2013 RT SP1, Office for Mac 2011, Excel for Mac 2011, PowerPoint for Mac 2011, Word for Mac 2011, PowerPoint Viewer, Word Automation Services on SharePoint Server 2010 SP2 and 2013 SP1, Excel Services on SharePoint Server 2010 SP2 and 2013 SP1, Office Web Apps 2010 SP2, Excel Web App 2010 SP2, Office Web Apps Server 2013 SP1, SharePoint Foundation 2010 SP2, and SharePoint Server 2013 SP1 allow remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability."
Published 2015-05-13 · Modified
9.3EPSS 0.187
CVE-2014-2816
Microsoft SharePoint Server 2013 Gold and SP1 and SharePoint Foundation 2013 Gold and SP1 allow remote authenticated users to gain privileges via a Trojan horse app that executes a custom action in the context of the SharePoint extensibility model, aka "SharePoint Page Content Vulnerability."
Published 2014-08-12 · Modified
9.3EPSS 0.162
CVE-2017-0281
Microsoft Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office 2016, Office Online Server 2016, Office Web Apps 2010 SP2,Office Web Apps 2013 SP1, Project Server 2013 SP1, SharePoint Enterprise Server 2013 SP1, SharePoint Enterprise Server 2016, SharePoint Foundation 2013 SP1, Sharepoint Server 2010 SP2, Word 2016, and Skype for Business 2016 allow a remote code execution vulnerability when the software fails to properly handle objects in memory, aka "Office Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-0261 and CVE-2017-0262.
Published 2017-05-12 · Modified
9.3EPSS 0.158
CVE-2020-0892
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0850, CVE-2020-0851, CVE-2020-0852, CVE-2020-0855.
Published 2020-03-12 · Modified
9.3EPSS 0.118
CVE-2014-0251
Microsoft Windows SharePoint Services 3.0 SP3; SharePoint Server 2007 SP3, 2010 SP1 and SP2, and 2013 Gold and SP1; SharePoint Foundation 2010 SP1 and SP2 and 2013 Gold and SP1; Project Server 2010 SP1 and SP2 and 2013 Gold and SP1; Web Applications 2010 SP1 and SP2; Office Web Apps Server 2013 Gold and SP1; SharePoint Server 2013 Client Components SDK; and SharePoint Designer 2007 SP3, 2010 SP1 and SP2, and 2013 Gold and SP1 allow remote authenticated users to execute arbitrary code via crafted page content, aka "SharePoint Page Content Vulnerability."
Published 2014-05-14 · Modified
9.0EPSS 0.142
CVE-2021-1707
Microsoft SharePoint Server Remote Code Execution Vulnerability
Published 2021-01-12 · Modified
9.0EPSS 0.036
CVE-2022-21837
Microsoft SharePoint Server Remote Code Execution Vulnerability
Published 2022-01-11 · Modified
9.0EPSS 0.030
CVE-2022-44690
Microsoft SharePoint Server Remote Code Execution Vulnerability
Published 2022-12-13 · Modified
8.8EPSS 0.821
CVE-2022-38053
Microsoft SharePoint Server Remote Code Execution Vulnerability
Published 2022-10-11 · Modified
8.8EPSS 0.764
CVE-2020-1181
A remote code execution vulnerability exists in Microsoft SharePoint Server when it fails to properly identify and filter unsafe ASP.Net web controls, aka 'Microsoft SharePoint Server Remote Code Execution Vulnerability'.
Published 2020-06-09 · Modified
8.8EPSS 0.693
CVE-2023-21742
Microsoft SharePoint Server Remote Code Execution Vulnerability
Published 2023-01-10 · Modified
8.8EPSS 0.558
CVE-2022-35823
Microsoft SharePoint Remote Code Execution Vulnerability
Published 2022-09-13 · Modified
8.8EPSS 0.536
CVE-2021-28474
Microsoft SharePoint Server Remote Code Execution Vulnerability
Published 2021-05-11 · Modified
8.8EPSS 0.508
CVE-2022-37961
Microsoft SharePoint Server Remote Code Execution Vulnerability
Published 2022-09-13 · Modified
8.8EPSS 0.507
CVE-2021-40487
Microsoft SharePoint Server Remote Code Execution Vulnerability
Published 2021-10-13 · Modified
8.8EPSS 0.482
CVE-2020-0932
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0920, CVE-2020-0929, CVE-2020-0931, CVE-2020-0971, CVE-2020-0974.
Published 2020-04-15 · Modified
8.8EPSS 0.312
CVE-2021-31181
Microsoft SharePoint Remote Code Execution Vulnerability
Published 2021-05-11 · Modified
8.8EPSS 0.300
CVE-2020-1439
A remote code execution vulnerability exists in PerformancePoint Services for SharePoint Server when the software fails to check the source markup of XML file input, aka 'PerformancePoint Services Remote Code Execution Vulnerability'.
Published 2020-07-14 · Modified
8.8EPSS 0.203
CVE-2022-22005
Microsoft SharePoint Server Remote Code Execution Vulnerability
Published 2022-02-09 · Modified
8.8EPSS 0.164
CVE-2021-27076
Microsoft SharePoint Server Remote Code Execution Vulnerability
Published 2021-03-11 · Modified
8.8EPSS 0.144
CVE-2020-0971
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0920, CVE-2020-0929, CVE-2020-0931, CVE-2020-0932, CVE-2020-0974.
Published 2020-04-15 · Modified
8.8EPSS 0.132
CVE-2019-0594
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0604.
Published 2019-03-06 · Modified
8.8EPSS 0.121
CVE-2022-29108
Microsoft SharePoint Server Remote Code Execution Vulnerability
Published 2022-05-10 · Modified
8.8EPSS 0.119
CVE-2019-1257
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1295, CVE-2019-1296.
Published 2019-09-11 · Modified
8.8EPSS 0.117
CVE-2020-0929
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0920, CVE-2020-0931, CVE-2020-0932, CVE-2020-0971, CVE-2020-0974.
Published 2020-04-15 · Modified
8.8EPSS 0.107
CVE-2020-0931
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0920, CVE-2020-0929, CVE-2020-0932, CVE-2020-0971, CVE-2020-0974.
Published 2020-04-15 · Modified
8.8EPSS 0.107
CVE-2020-0920
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0929, CVE-2020-0931, CVE-2020-0932, CVE-2020-0971, CVE-2020-0974.
Published 2020-04-15 · Modified
8.8EPSS 0.104
CVE-2019-0952
A remote code execution vulnerability exists in Microsoft SharePoint Server when it fails to properly identify and filter unsafe ASP.Net web controls, aka 'Microsoft SharePoint Server Remote Code Execution Vulnerability'.
Published 2019-05-16 · Modified
8.8EPSS 0.096
CVE-2020-0850
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0851, CVE-2020-0852, CVE-2020-0855, CVE-2020-0892.
Published 2020-03-12 · Modified
8.8EPSS 0.088
CVE-2019-1295
A remote code execution vulnerability exists in Microsoft SharePoint where APIs aren't properly protected from unsafe data input, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1257, CVE-2019-1296.
Published 2019-09-11 · Modified
8.8EPSS 0.083
CVE-2019-1296
A remote code execution vulnerability exists in Microsoft SharePoint where APIs aren't properly protected from unsafe data input, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1257, CVE-2019-1295.
Published 2019-09-11 · Modified
8.8EPSS 0.083
1 / 5Next →