VendorsMicrosoftsharepoint_server2013
Vulnerabilities

Microsoft Sharepoint Server 2013

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

85CVEs
CVE-2022-30158
Microsoft SharePoint Server Remote Code Execution Vulnerability
Published 2022-06-15 · Modified
8.8EPSS 0.034
CVE-2022-21840
Microsoft Office Remote Code Execution Vulnerability
Published 2022-01-11 · Modified
8.8EPSS 0.031
CVE-2022-41038
Microsoft SharePoint Server Remote Code Execution Vulnerability
Published 2022-10-11 · Modified
8.8EPSS 0.029
CVE-2023-21744
Microsoft SharePoint Server Remote Code Execution Vulnerability
Published 2023-01-10 · Modified
8.8EPSS 0.028
CVE-2021-31963
Microsoft SharePoint Server Remote Code Execution Vulnerability
Published 2021-06-08 · Modified
8.8EPSS 0.021
CVE-2022-41037
Microsoft SharePoint Server Remote Code Execution Vulnerability
Published 2022-10-11 · Modified
8.8EPSS 0.017
CVE-2022-41036
Microsoft SharePoint Server Remote Code Execution Vulnerability
Published 2022-10-11 · Modified
8.8EPSS 0.017
CVE-2023-28288
Microsoft SharePoint Server Spoofing Vulnerability
Published 2023-04-11 · Modified
8.11 PoCEPSS 0.062
CVE-2021-28453
Microsoft Word Remote Code Execution Vulnerability
Published 2021-04-13 · Modified
7.8EPSS 0.041
CVE-2021-31966
Microsoft SharePoint Server Remote Code Execution Vulnerability
Published 2021-06-08 · Modified
7.2EPSS 0.046
CVE-2013-3895
Microsoft SharePoint Server 2007 SP3 and 2010 SP1 and SP2 allows remote attackers to conduct clickjacking attacks via a crafted web page, aka "Parameter Injection Vulnerability."
Published 2013-10-09 · Modified
6.8EPSS 0.296
CVE-2013-5059
Microsoft SharePoint Server 2010 SP1 and SP2 and 2013, and Office Web Apps 2013, allows remote attackers to execute arbitrary code via crafted page content, aka "SharePoint Page Content Vulnerabilities."
Published 2013-12-11 · Modified
6.8EPSS 0.107
CVE-2016-7233
Microsoft Word 2007, Office 2010 SP2, Word 2010 SP2, Word for Mac 2011, Excel for Mac 2011, Word Viewer, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2013 SP1, and Office Web Apps 2010 SP2 allow remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read) via a crafted Office document, aka "Microsoft Office Information Disclosure Vulnerability."
Published 2016-11-10 · Modified
6.5EPSS 0.224
CVE-2021-28450
Microsoft SharePoint Denial of Service Vulnerability
Published 2021-04-13 · Modified
6.5EPSS 0.024
CVE-2015-6117
Microsoft SharePoint Server 2013 SP1 and SharePoint Foundation 2013 SP1 allow remote authenticated users to bypass intended Access Control Policy restrictions and conduct cross-site scripting (XSS) attacks by modifying a webpart, aka "Microsoft SharePoint Security Feature Bypass," a different vulnerability than CVE-2016-0011.
Published 2016-01-13 · Modified
6.1EPSS 0.069
CVE-2020-1323
An open redirect vulnerability exists in Microsoft SharePoint that could lead to spoofing.To exploit the vulnerability, an attacker could send a link that has a specially crafted URL and convince the user to click the link, aka 'SharePoint Open Redirect Vulnerability'.
Published 2020-06-09 · Modified
6.1EPSS 0.021
CVE-2015-1700
Microsoft SharePoint Server 2007 SP3, SharePoint Foundation 2010 SP2, SharePoint Server 2010 SP2, and SharePoint Foundation 2013 SP1 allow remote authenticated users to execute arbitrary code via crafted page content, aka "Microsoft SharePoint Page Content Vulnerabilities."
Published 2015-05-13 · Modified
6.0EPSS 0.121
CVE-2016-3234
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Office Compatibility Pack SP3, Word Viewer, Word Automation Services on SharePoint Server 2010 SP2, Word Automation Services on SharePoint Server 2013 SP1, Office Web Apps 2010 SP2, and Office Web Apps Server 2013 SP1 allow remote attackers to obtain sensitive information from process memory via a crafted Office document, aka "Microsoft Office Information Disclosure Vulnerability."
Published 2016-06-16 · Modified
5.5EPSS 0.241
CVE-2018-8378
An information disclosure vulnerability exists when Microsoft Office software reads out of bound memory due to an uninitialized variable, which could disclose the contents of memory, aka "Microsoft Office Information Disclosure Vulnerability." This affects Word, Microsoft SharePoint Server, Microsoft Office Word Viewer, Microsoft Excel Viewer, Microsoft SharePoint, Microsoft Office.
Published 2018-08-15 · Modified
5.5EPSS 0.082
CVE-2022-22716
Microsoft Excel Information Disclosure Vulnerability
Published 2022-02-09 · Modified
5.5EPSS 0.046
CVE-2022-30172
Microsoft Office Information Disclosure Vulnerability
Published 2022-06-15 · Modified
5.5EPSS 0.027
CVE-2022-30159
Microsoft Office Information Disclosure Vulnerability
Published 2022-06-15 · Modified
5.5EPSS 0.027
CVE-2022-30171
Microsoft Office Information Disclosure Vulnerability
Published 2022-06-15 · Modified
5.5EPSS 0.026
CVE-2016-0011
Microsoft SharePoint Server 2013 SP1 and SharePoint Foundation 2013 SP1 allow remote authenticated users to bypass intended Access Control Policy restrictions and conduct cross-site scripting (XSS) attacks by modifying a webpart, aka "Microsoft SharePoint Security Feature Bypass," a different vulnerability than CVE-2015-6117.
Published 2016-01-13 · Modified
5.4EPSS 0.053
CVE-2018-8149
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft SharePoint Server, Microsoft SharePoint. This CVE ID is unique from CVE-2018-8155, CVE-2018-8156, CVE-2018-8168.
Published 2018-05-09 · Modified
5.4EPSS 0.029
CVE-2018-0864
SharePoint Project Server 2013 and SharePoint Enterprise Server 2016 allow an information disclosure vulnerability due to how web requests are handled, aka "Microsoft SharePoint Information Disclosure Vulnerability".
Published 2018-02-15 · Modified
5.4EPSS 0.026
CVE-2018-8168
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft SharePoint Server, Microsoft SharePoint. This CVE ID is unique from CVE-2018-8149, CVE-2018-8155, CVE-2018-8156.
Published 2018-05-09 · Modified
5.4EPSS 0.024
CVE-2017-8629
Microsoft SharePoint Server 2013 Service Pack 1 allows an elevation of privilege vulnerability when it fails to properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint XSS Vulnerability".
Published 2017-09-13 · Modified
5.4EPSS 0.024
CVE-2019-0558
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft Office SharePoint XSS Vulnerability." This affects Microsoft SharePoint Server, Microsoft SharePoint, Microsoft Business Productivity Servers. This CVE ID is unique from CVE-2019-0556, CVE-2019-0557.
Published 2019-01-08 · Modified
5.4EPSS 0.020
CVE-2020-1105
A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Spoofing Vulnerability'. This CVE ID is unique from CVE-2020-1104, CVE-2020-1107.
Published 2020-05-21 · Modified
5.4EPSS 0.017
CVE-2019-0556
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft Office SharePoint XSS Vulnerability." This affects Microsoft SharePoint. This CVE ID is unique from CVE-2019-0557, CVE-2019-0558.
Published 2019-01-08 · Modified
5.4EPSS 0.016
CVE-2021-34519
Microsoft SharePoint Server Information Disclosure Vulnerability
Published 2021-07-14 · Modified
5.3EPSS 0.061
CVE-2021-34517
Microsoft SharePoint Server Spoofing Vulnerability
Published 2021-07-14 · Modified
5.3EPSS 0.020
CVE-2013-0081
Microsoft SharePoint Portal Server 2003 SP3 and SharePoint Server 2007 SP3, 2010 SP1 and SP2, and 2013 do not properly process unassigned workflows, which allows remote attackers to cause a denial of service (W3WP process hang) via a crafted URL, aka "SharePoint Denial of Service Vulnerability."
Published 2013-09-11 · Modified
5.0EPSS 0.767
CVE-2017-0027
Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 RT SP1, Excel 2016, Office Compatibility Pack SP3, and Excel Services on SharePoint Server 2013 SP1 allow remote attackers to obtain sensitive information from process memory via a crafted Office document, aka "Microsoft Office Information Disclosure Vulnerability."
Published 2017-03-17 · Modified
4.7EPSS 0.226
CVE-2015-2375
Microsoft Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel Viewer 2007 SP3, Excel Services on SharePoint Server 2010 SP2, and Excel Services on SharePoint Server 2013 SP1 allow remote attackers to bypass the ASLR protection mechanism via a crafted spreadsheet, aka "Microsoft Excel ASLR Bypass Vulnerability."
Published 2015-07-14 · Modified
4.3EPSS 0.140
CVE-2014-1754
Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2013 Gold and SP1, SharePoint Foundation 2013 Gold and SP1, Office Web Apps Server 2013 Gold and SP1, and SharePoint Server 2013 Client Components SDK allows remote attackers to inject arbitrary web script or HTML via a crafted request, aka "SharePoint XSS Vulnerability."
Published 2014-05-14 · Modified
4.3EPSS 0.111
CVE-2015-1653
Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Foundation 2013 SP1 and SharePoint Server 2013 SP1 allows remote attackers to inject arbitrary web script or HTML via a crafted request, aka "Microsoft SharePoint XSS Vulnerability."
Published 2015-04-14 · Modified
4.3EPSS 0.088
CVE-2018-8580
An information disclosure vulnerability exists where certain modes of the search function in Microsoft SharePoint Server are vulnerable to cross-site search attacks (a variant of cross-site request forgery, CSRF), aka "Microsoft SharePoint Information Disclosure Vulnerability." This affects Microsoft SharePoint.
Published 2018-12-12 · Modified
4.3EPSS 0.044
CVE-2013-1290
Microsoft SharePoint Server 2013, in certain configurations involving legacy My Sites, does not properly establish default access controls for a SharePoint list, which allows remote authenticated users to bypass intended restrictions on reading list items via a direct request for a list's location, aka "Incorrect Access Rights Information Disclosure Vulnerability."
Published 2013-04-09 · Modified
3.5EPSS 0.170
← Prev2 / 3Next →