threat
engine
.sh
Back
·
··:··
Home
/
Product
/
microsoft sharepoint enterprise server
Product
microsoft sharepoint enterprise server
256 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
Sort
Newest first
Oldest first
Highest CVSS
Lowest CVSS
Min CVSS
Any
4.0+
7.0+ (High)
9.0+ (Critical)
Published since
Reset
CVE-2025-54905
all versions
Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
7.1
HIGH
CVE-2025-53736
all versions
Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
6.8
MEDIUM
CVE-2025-53733
all versions
Incorrect conversion between numeric types in Microsoft Office Word allows an unauthorized attacker to execute code locally.
8.4
HIGH
CVE-2025-49706
all versions
Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
6.5
MEDIUM
CVE-2025-47994
all versions
Deserialization of untrusted data in Microsoft Office allows an unauthorized attacker to elevate privileges locally.
7.8
HIGH
CVE-2025-47172
all versions
Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an auth
8.8
HIGH
CVE-2025-47169
all versions
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
7.8
HIGH
CVE-2025-47168
all versions
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
7.8
HIGH
CVE-2025-47166
all versions
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
8.8
HIGH
CVE-2025-47163
all versions
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
8.8
HIGH
CVE-2025-29820
all versions
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
7.8
HIGH
CVE-2025-29794
all versions
Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
8.8
HIGH
CVE-2025-29793
all versions
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
7.2
HIGH
CVE-2025-27747
all versions
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
7.8
HIGH
CVE-2023-38177
all versions
Microsoft SharePoint Server Remote Code Execution Vulnerability
6.1
MEDIUM
CVE-2023-24955
all versions
Microsoft SharePoint Server Remote Code Execution Vulnerability
7.2
HIGH
CVE-2023-24954
all versions
Microsoft SharePoint Server Information Disclosure Vulnerability
6.5
MEDIUM
CVE-2023-24950
all versions
Microsoft SharePoint Server Spoofing Vulnerability
6.5
MEDIUM
CVE-2023-21717
all versions
Microsoft SharePoint Server Elevation of Privilege Vulnerability
8.8
HIGH
CVE-2023-21716
all versions
Microsoft Word Remote Code Execution Vulnerability
9.8
CRITICAL
CVE-2022-44693
all versions
Microsoft SharePoint Server Remote Code Execution Vulnerability
8.8
HIGH
CVE-2022-41122
all versions
Microsoft SharePoint Server Spoofing Vulnerability
6.5
MEDIUM
CVE-2022-41103
all versions
Microsoft Word Information Disclosure Vulnerability
5.5
MEDIUM
CVE-2022-41062
all versions
Microsoft SharePoint Server Remote Code Execution Vulnerability
8.8
HIGH
CVE-2022-41061
all versions
Microsoft Word Remote Code Execution Vulnerability
7.8
HIGH
CVE-2022-41060
all versions
Microsoft Word Information Disclosure Vulnerability
5.5
MEDIUM
CVE-2022-38053
all versions
Microsoft SharePoint Server Remote Code Execution Vulnerability
8.8
HIGH
CVE-2022-38009
all versions
Microsoft SharePoint Server Remote Code Execution Vulnerability
8.8
HIGH
CVE-2022-38008
all versions
Microsoft SharePoint Server Remote Code Execution Vulnerability
8.8
HIGH
CVE-2022-37961
all versions
Microsoft SharePoint Server Remote Code Execution Vulnerability
8.8
HIGH
CVE-2022-35823
all versions
Microsoft SharePoint Remote Code Execution Vulnerability
8.8
HIGH
CVE-2022-29108
all versions
Microsoft SharePoint Server Remote Code Execution Vulnerability
8.8
HIGH
CVE-2022-22005
all versions
Microsoft SharePoint Server Remote Code Execution Vulnerability
8.8
HIGH
CVE-2022-21987
all versions
Microsoft SharePoint Server Spoofing Vulnerability
8.0
HIGH
CVE-2022-21968
all versions
Microsoft SharePoint Server Security Feature Bypass Vulnerability
4.3
MEDIUM
CVE-2022-21842
all versions
Microsoft Word Remote Code Execution Vulnerability
7.8
HIGH
CVE-2022-21840
all versions
Microsoft Office Remote Code Execution Vulnerability
8.8
HIGH
CVE-2021-43876
all versions
Microsoft SharePoint Elevation of Privilege Vulnerability
8.8
HIGH
CVE-2021-43242
all versions
Microsoft SharePoint Server Spoofing Vulnerability
7.6
HIGH
CVE-2021-42320
all versions
Microsoft SharePoint Server Spoofing Vulnerability
8.0
HIGH
CVE-2021-42309
all versions
Microsoft SharePoint Server Remote Code Execution Vulnerability
8.8
HIGH
CVE-2021-42294
all versions
Microsoft SharePoint Server Remote Code Execution Vulnerability
7.2
HIGH
CVE-2021-40442
all versions
Microsoft Excel Remote Code Execution Vulnerability
7.8
HIGH
CVE-2021-41344
all versions
Microsoft SharePoint Server Remote Code Execution Vulnerability
8.1
HIGH
CVE-2021-40487
all versions
Microsoft SharePoint Server Remote Code Execution Vulnerability
8.1
HIGH
CVE-2021-40486
all versions
Microsoft Word Remote Code Execution Vulnerability
7.8
HIGH
CVE-2021-40485
all versions
Microsoft Excel Remote Code Execution Vulnerability
7.8
HIGH
CVE-2021-40484
all versions
Microsoft SharePoint Server Spoofing Vulnerability
7.6
HIGH
CVE-2021-38652
all versions
Microsoft SharePoint Server Spoofing Vulnerability
7.6
HIGH
CVE-2021-38651
all versions
Microsoft SharePoint Server Spoofing Vulnerability
7.6
HIGH
CVE-2021-36940
all versions
Microsoft SharePoint Server Spoofing Vulnerability
7.6
HIGH
CVE-2021-31948
all versions
Microsoft SharePoint Server Spoofing Vulnerability
7.6
HIGH
CVE-2021-26420
all versions
Microsoft SharePoint Server Remote Code Execution Vulnerability
7.1
HIGH
CVE-2021-31181
all versions
Microsoft SharePoint Remote Code Execution Vulnerability
8.8
HIGH
CVE-2021-27052
all versions
Microsoft SharePoint Server Information Disclosure Vulnerability
5.3
MEDIUM
CVE-2021-24104
all versions
Microsoft SharePoint Server Spoofing Vulnerability
4.6
MEDIUM
CVE-2021-24072
all versions
Microsoft SharePoint Server Remote Code Execution Vulnerability
8.8
HIGH
CVE-2021-24071
all versions
Microsoft SharePoint Information Disclosure Vulnerability
5.3
MEDIUM
CVE-2021-24066
all versions
Microsoft SharePoint Remote Code Execution Vulnerability
8.8
HIGH
CVE-2021-1726
all versions
Microsoft SharePoint Server Spoofing Vulnerability
8.0
HIGH
CVE-2021-1719
all versions
Microsoft SharePoint Elevation of Privilege Vulnerability
8.0
HIGH
CVE-2021-1717
all versions
Microsoft SharePoint Server Spoofing Vulnerability
4.6
MEDIUM
CVE-2021-1716
all versions
Microsoft Word Remote Code Execution Vulnerability
7.8
HIGH
CVE-2021-1715
all versions
Microsoft Word Remote Code Execution Vulnerability
7.8
HIGH
CVE-2021-1714
all versions
Microsoft Excel Remote Code Execution Vulnerability
7.8
HIGH
CVE-2021-1712
all versions
Microsoft SharePoint Elevation of Privilege Vulnerability
8.0
HIGH
CVE-2021-1707
all versions
Microsoft SharePoint Server Remote Code Execution Vulnerability
8.8
HIGH
CVE-2021-1641
all versions
Microsoft SharePoint Server Spoofing Vulnerability
4.6
MEDIUM
CVE-2020-17060
all versions
Microsoft SharePoint Server Spoofing Vulnerability
5.4
MEDIUM
CVE-2020-17017
all versions
Microsoft SharePoint Information Disclosure Vulnerability
5.3
MEDIUM
CVE-2020-17016
all versions
Microsoft SharePoint Server Spoofing Vulnerability
8.0
HIGH
CVE-2020-17015
all versions
Microsoft SharePoint Server Spoofing Vulnerability
4.3
MEDIUM
CVE-2020-16979
all versions
Microsoft SharePoint Information Disclosure Vulnerability
5.3
MEDIUM
CVE-2020-16953
all versions
<p>An information disclosure vulnerability exists when Microsoft SharePoint Server fails to properly handle objects in memory. An
6.5
MEDIUM
CVE-2020-16952
all versions
<p>A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an a
8.6
HIGH
CVE-2020-16951
all versions
<p>A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an a
8.6
HIGH
CVE-2020-16948
all versions
<p>An information disclosure vulnerability exists when Microsoft SharePoint Server fails to properly handle objects in memory. An
6.5
MEDIUM
CVE-2020-16946
all versions
<p>A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially craft
8.7
HIGH
CVE-2020-16945
all versions
<p>A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially craft
8.7
HIGH
CVE-2020-16944
all versions
<p>This vulnerability is caused when SharePoint Server does not properly sanitize a specially crafted request to an affected Share
8.7
HIGH
CVE-2020-16942
all versions
<p>An information disclosure vulnerability exists when Microsoft SharePoint Server improperly discloses its folder structure when
4.1
MEDIUM
CVE-2020-16941
all versions
<p>An information disclosure vulnerability exists when Microsoft SharePoint Server improperly discloses its folder structure when
4.1
MEDIUM
CVE-2020-16929
all versions
<p>A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in
7.8
HIGH
CVE-2020-1595
all versions
<p>A remote code execution vulnerability exists in Microsoft SharePoint where APIs aren't properly protected from unsafe data inpu
9.9
CRITICAL
CVE-2020-1576
all versions
<p>A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an a
8.5
HIGH
CVE-2020-1514
all versions
<p>A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially craft
5.4
MEDIUM
CVE-2020-1482
all versions
<p>A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially craft
6.3
MEDIUM
CVE-2020-1460
all versions
<p>A remote code execution vulnerability exists in Microsoft SharePoint Server when it fails to properly identify and filter unsaf
8.6
HIGH
CVE-2020-1453
all versions
<p>A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an a
8.6
HIGH
CVE-2020-1452
all versions
<p>A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an a
8.6
HIGH
CVE-2020-1440
all versions
<p>A tampering vulnerability exists when Microsoft SharePoint Server fails to properly handle profile data. An attacker who succes
6.3
MEDIUM
CVE-2020-1345
all versions
<p>A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially craft
7.4
HIGH
CVE-2020-1227
all versions
<p>A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially craft
5.4
MEDIUM
CVE-2020-1224
all versions
<p>An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory. An attacke
5.5
MEDIUM
CVE-2020-1218
all versions
<p>A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory. An
7.8
HIGH
CVE-2020-1210
all versions
<p>A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an a
9.9
CRITICAL
CVE-2020-1205
all versions
<p>A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to
4.6
MEDIUM
CVE-2020-1200
all versions
<p>A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an a
8.6
HIGH
CVE-2020-1198
all versions
<p>A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially craft
7.4
HIGH
CVE-2020-1583
all versions
An information disclosure vulnerability exists when Microsoft Word improperly discloses the contents of its memory. An attacker wh
8.8
HIGH
CVE-2020-1580
all versions
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted
5.4
MEDIUM
CVE-2020-1573
all versions
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted
5.5
MEDIUM
CVE-2020-1505
all versions
An information disclosure vulnerability exists when Microsoft SharePoint Server fails to properly handle objects in memory. An att
5.5
MEDIUM
CVE-2020-1503
all versions
An information disclosure vulnerability exists when Microsoft Word improperly discloses the contents of its memory. An attacker wh
5.5
MEDIUM
CVE-2020-1501
all versions
A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an
5.4
MEDIUM
CVE-2020-1500
all versions
A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an
5.4
MEDIUM
CVE-2020-1499
all versions
A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an
5.4
MEDIUM
CVE-2020-1495
all versions
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in mem
8.8
HIGH
CVE-2020-1456
all versions
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted
5.4
MEDIUM
CVE-2020-1454
all versions
This vulnerability is caused when SharePoint Server does not properly sanitize a specially crafted request to an affected SharePoi
5.4
MEDIUM
CVE-2020-1451
all versions
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted
5.4
MEDIUM
CVE-2020-1450
all versions
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted
5.4
MEDIUM
CVE-2020-1448
all versions
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'M
8.8
HIGH
CVE-2020-1447
all versions
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'M
8.8
HIGH
CVE-2020-1446
all versions
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'M
8.8
HIGH
CVE-2020-1445
all versions
An information disclosure vulnerability exists when Microsoft Office improperly discloses the contents of its memory, aka 'Microso
5.5
MEDIUM
CVE-2020-1444
all versions
A remote code execution vulnerability exists in the way Microsoft SharePoint software parses specially crafted email messages, aka
4.3
MEDIUM
CVE-2020-1443
all versions
A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an
5.4
MEDIUM
CVE-2020-1439
all versions
A remote code execution vulnerability exists in PerformancePoint Services for SharePoint Server when the software fails to check t
8.8
HIGH
CVE-2020-1342
all versions
An information disclosure vulnerability exists when Microsoft Office software reads out of bound memory due to an uninitialized va
5.5
MEDIUM
CVE-2020-1147
all versions
A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to
7.8
HIGH
CVE-2020-1025
all versions
An elevation of privilege vulnerability exists when Microsoft SharePoint Server and Skype for Business Server improperly handle OA
9.8
CRITICAL
CVE-2020-1323
all versions
An open redirect vulnerability exists in Microsoft SharePoint that could lead to spoofing.To exploit the vulnerability, an attacke
6.1
MEDIUM
CVE-2020-1320
all versions
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted
5.4
MEDIUM
CVE-2020-1318
all versions
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted
5.4
MEDIUM
CVE-2020-1298
all versions
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted
5.4
MEDIUM
CVE-2020-1297
all versions
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted
5.4
MEDIUM
CVE-2020-1295
all versions
An elevation of privilege vulnerability exists in Microsoft SharePoint, aka 'Microsoft SharePoint Elevation of Privilege Vulnerabi
8.8
HIGH
CVE-2020-1183
all versions
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted
5.4
MEDIUM
CVE-2020-1181
all versions
A remote code execution vulnerability exists in Microsoft SharePoint Server when it fails to properly identify and filter unsafe A
8.8
HIGH
CVE-2020-1178
all versions
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted aut
8.8
HIGH
CVE-2020-1177
all versions
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted
5.4
MEDIUM
CVE-2020-1148
all versions
A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an
5.4
MEDIUM
CVE-2020-1107
all versions
A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an
5.4
MEDIUM
CVE-2020-1106
all versions
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted
6.1
MEDIUM
CVE-2020-1105
all versions
A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an
5.4
MEDIUM
CVE-2020-1104
all versions
A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an
5.4
MEDIUM
CVE-2020-1103
all versions
An information disclosure vulnerability exists where certain modes of the search function in Microsoft SharePoint Server are vulne
6.5
MEDIUM
CVE-2020-1102
all versions
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an appl
8.8
HIGH
CVE-2020-1101
all versions
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted
5.4
MEDIUM
CVE-2020-1100
all versions
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted
5.4
MEDIUM
CVE-2020-1099
all versions
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted
5.4
MEDIUM
CVE-2020-1069
all versions
A remote code execution vulnerability exists in Microsoft SharePoint Server when it fails to properly identify and filter unsafe A
8.8
HIGH
CVE-2020-1024
all versions
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an appl
8.8
HIGH
CVE-2020-1023
all versions
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an appl
8.8
HIGH
CVE-2020-0980
all versions
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'M
7.8
HIGH
CVE-2020-0978
all versions
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted
5.4
MEDIUM
CVE-2020-0977
all versions
A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an
5.4
MEDIUM
CVE-2020-0976
all versions
A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an
5.4
MEDIUM
CVE-2020-0975
all versions
A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an
5.4
MEDIUM
CVE-2020-0974
all versions
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an appl
8.8
HIGH
CVE-2020-0973
all versions
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted
5.4
MEDIUM
CVE-2020-0972
all versions
A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an
5.4
MEDIUM
CVE-2020-0971
all versions
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an appl
8.8
HIGH
CVE-2020-0954
all versions
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted
5.4
MEDIUM
CVE-2020-0933
all versions
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted
5.4
MEDIUM
CVE-2020-0932
all versions
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an appl
8.8
HIGH
CVE-2020-0931
all versions
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an appl
8.8
HIGH
CVE-2020-0930
all versions
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted
5.4
MEDIUM
CVE-2020-0929
all versions
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an appl
8.8
HIGH
CVE-2020-0927
all versions
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted
5.4
MEDIUM
CVE-2020-0926
all versions
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted
5.4
MEDIUM
CVE-2020-0925
all versions
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted
5.4
MEDIUM
CVE-2020-0924
all versions
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted
5.4
MEDIUM
CVE-2020-0923
all versions
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted
5.4
MEDIUM
CVE-2020-0920
all versions
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an appl
8.8
HIGH
CVE-2020-0894
all versions
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted
5.4
MEDIUM
CVE-2020-0893
all versions
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted
5.4
MEDIUM
CVE-2020-0892
all versions
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'M
7.8
HIGH
CVE-2020-0891
all versions
This vulnerability is caused when SharePoint Server does not properly sanitize a specially crafted request to an affected SharePoi
5.4
MEDIUM
CVE-2020-0850
all versions
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'M
8.8
HIGH
CVE-2020-0795
all versions
This vulnerability is caused when SharePoint Server does not properly sanitize a specially crafted request to an affected SharePoi
5.4
MEDIUM
CVE-2020-0694
all versions
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted
5.4
MEDIUM
CVE-2020-0693
all versions
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted
5.4
MEDIUM
CVE-2019-1446
all versions
An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka 'Microsof
5.5
MEDIUM
CVE-2019-1443
all versions
An information disclosure vulnerability exists in Microsoft SharePoint when an attacker uploads a specially crafted file to the Sh
6.5
MEDIUM
CVE-2019-1330
all versions
An elevation of privilege vulnerability exists in Microsoft SharePoint, aka 'Microsoft SharePoint Elevation of Privilege Vulnerabi
6.5
MEDIUM
CVE-2019-1329
all versions
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web
5.4
MEDIUM
CVE-2019-1328
all versions
A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an
5.4
MEDIUM
CVE-2019-1070
all versions
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted
5.4
MEDIUM
CVE-2019-1296
all versions
A remote code execution vulnerability exists in Microsoft SharePoint where APIs aren't properly protected from unsafe data input,
8.8
HIGH
CVE-2019-1295
all versions
A remote code execution vulnerability exists in Microsoft SharePoint where APIs aren't properly protected from unsafe data input,
8.8
HIGH
CVE-2019-1261
all versions
A spoofing vulnerability exists in Microsoft SharePoint when it improperly handles requests to authorize applications, resulting i
8.8
HIGH
CVE-2019-1260
all versions
An elevation of privilege vulnerability exists in Microsoft SharePoint, aka 'Microsoft SharePoint Elevation of Privilege Vulnerabi
6.5
MEDIUM
CVE-2019-1257
all versions
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an appl
8.8
HIGH
CVE-2019-1203
all versions
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted
5.4
MEDIUM
CVE-2019-1202
all versions
An information disclosure vulnerability exists in the way Microsoft SharePoint handles session objects. An authenticated attacker
4.4
MEDIUM
CVE-2019-1201
all versions
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory. An att
7.8
HIGH
CVE-2019-1134
all versions
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted
5.4
MEDIUM
CVE-2019-1006
all versions
An authentication bypass vulnerability exists in Windows Communication Foundation (WCF) and Windows Identity Foundation (WIF), all
7.5
HIGH
CVE-2019-1036
all versions
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted
5.4
MEDIUM
CVE-2019-1034
all versions
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory. An att
7.8
HIGH
CVE-2019-1033
all versions
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted
5.4
MEDIUM
CVE-2019-1032
all versions
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted
5.4
MEDIUM
CVE-2019-1031
all versions
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted
5.4
MEDIUM
CVE-2019-0957
all versions
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web
8.8
HIGH
CVE-2019-0956
all versions
An information disclosure vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web
6.5
MEDIUM
CVE-2019-0952
all versions
A remote code execution vulnerability exists in Microsoft SharePoint Server when it fails to properly identify and filter unsafe A
8.8
HIGH
CVE-2019-0831
all versions
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted
5.4
MEDIUM
CVE-2019-0830
all versions
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted
5.4
MEDIUM
CVE-2019-0778
all versions
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted
5.4
MEDIUM
CVE-2019-0670
all versions
A spoofing vulnerability exists in Microsoft SharePoint when the application does not properly parse HTTP content, aka 'Microsoft
6.1
MEDIUM
CVE-2019-0668
all versions
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web
8.8
HIGH
CVE-2019-0604
all versions
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an appl
9.8
CRITICAL
CVE-2019-0594
all versions
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an appl
8.8
HIGH
CVE-2019-0562
all versions
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web
5.4
MEDIUM
CVE-2018-8650
all versions
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted
5.4
MEDIUM
CVE-2018-8635
all versions
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted aut
8.8
HIGH
CVE-2018-8628
all versions
A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fails to properly handle objects i
7.8
HIGH
CVE-2018-8578
all versions
An information disclosure vulnerability exists when Microsoft SharePoint Server improperly discloses its folder structure when ren
4.3
MEDIUM
CVE-2018-8572
all versions
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web
5.4
MEDIUM
CVE-2018-8568
all versions
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web
5.4
MEDIUM
CVE-2018-8518
all versions
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web
5.4
MEDIUM
CVE-2018-8498
all versions
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web
5.4
MEDIUM
CVE-2018-8488
all versions
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web
5.4
MEDIUM
CVE-2018-8431
all versions
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web
5.4
MEDIUM
CVE-2018-8428
all versions
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web
5.4
MEDIUM
CVE-2018-8323
all versions
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web
5.4
MEDIUM
CVE-2018-8300
all versions
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an appl
8.8
HIGH
CVE-2018-8299
all versions
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web
5.4
MEDIUM
CVE-2018-8284
all versions
A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka ".NET Framewo
8.1
HIGH
CVE-2018-1034
all versions
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web
5.4
MEDIUM
CVE-2018-1032
all versions
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web
5.4
MEDIUM
CVE-2018-1028
all versions
A remote code execution vulnerability exists when the Office graphics component improperly handles specially crafted embedded font
8.8
HIGH
CVE-2018-1014
all versions
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web
5.4
MEDIUM
CVE-2018-1005
all versions
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web
5.4
MEDIUM
CVE-2018-0947
all versions
Microsoft SharePoint Foundation 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation of privilege vulnerabi
8.8
HIGH
CVE-2018-0944
all versions
Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allows an elevation of privilege vulnerability t
8.8
HIGH
CVE-2018-0923
all versions
Microsoft SharePoint Enterprise Server 2016 allows an elevation of privilege vulnerability to due how specially crafted web reques
8.8
HIGH
CVE-2018-0922
all versions
Microsoft Office 2010 SP2, 2013 SP1, and 2016, Microsoft Office 2016 Click-to-Run Microsoft Office 2016 for Mac, Microsoft Office
7.8
HIGH
CVE-2018-0921
all versions
Microsoft SharePoint Enterprise Server 2016 allows an elevation of privilege vulnerability to due how specially crafted web reques
8.8
HIGH
CVE-2018-0919
all versions
Microsoft Office 2010 SP2, 2013 SP1, and 2016, Microsoft Office 2016 Click-to-Run Microsoft Office 2016 for Mac, Microsoft Office
3.3
LOW
CVE-2018-0917
all versions
Microsoft SharePoint Enterprise Server 2016 allows an elevation of privilege vulnerability to due how specially crafted web reques
8.8
HIGH
CVE-2018-0916
all versions
Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation of privilege vulnerability to
8.8
HIGH
CVE-2018-0915
all versions
Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation of privilege vulnerability to
8.8
HIGH
CVE-2018-0914
all versions
Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation of privilege vulnerability to
8.8
HIGH
CVE-2018-0913
all versions
Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation of privilege vulnerability to
8.8
HIGH
CVE-2018-0912
all versions
Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation of privilege vulnerability to
8.8
HIGH
CVE-2018-0911
all versions
Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation of privilege vulnerability to
8.8
HIGH
CVE-2018-0910
all versions
Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation of privilege vulnerability to
8.8
HIGH
CVE-2018-0909
all versions
Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation of privilege vulnerability to
8.8
HIGH
CVE-2018-0869
all versions
SharePoint Server 2016 allows an elevation of privilege vulnerability due to how web requests are handled, aka "Microsoft SharePoi
5.4
MEDIUM
CVE-2018-0799
all versions
Microsoft Access in Microsoft SharePoint Enterprise Server 2013 and Microsoft SharePoint Enterprise Server 2016 allows a cross-sit
6.1
MEDIUM
CVE-2018-0797
all versions
Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow a remote code execution vulnerability due to the way
7.8
HIGH
CVE-2018-0790
all versions
Microsoft SharePoint Foundation 2010, Microsoft SharePoint Server 2013 and Microsoft SharePoint Server 2016 allow an elevation of
8.8
HIGH
CVE-2018-0789
all versions
Microsoft SharePoint Foundation 2010, Microsoft SharePoint Server 2013 and Microsoft SharePoint Server 2016 allow an elevation of
8.8
HIGH
CVE-2017-11936
all versions
Microsoft SharePoint Enterprise Server 2016 allows an elevation of privilege vulnerability due to the way web requests are handled
8.8
HIGH
CVE-2017-11876
all versions
Microsoft Project Server and Microsoft SharePoint Enterprise Server 2016 allow an attacker to use cross-site forgery to read conte
8.8
HIGH
CVE-2017-11826
all versions
Microsoft Office 2010, SharePoint Enterprise Server 2010, SharePoint Server 2010, Web Applications, Office Web Apps Server 2010 an
7.8
HIGH
CVE-2017-11820
all versions
Microsoft SharePoint Enterprise Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an attacker to exploit a cro
5.4
MEDIUM
CVE-2017-11777
all versions
Microsoft SharePoint Enterprise Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an attacker to exploit a cro
5.4
MEDIUM
CVE-2017-11775
all versions
Microsoft SharePoint Enterprise Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an attacker to exploit a cro
5.4
MEDIUM
CVE-2017-8742
all versions
A remote code execution vulnerability exists in Microsoft PowerPoint 2007 Service Pack 3, Microsoft PowerPoint 2010 Service Pack 2
7.8
HIGH
CVE-2017-8514
all versions
An information disclosure vulnerability exists when Microsoft SharePoint software fails to properly sanitize a specially crafted r
5.4
MEDIUM
CVE-2017-8512
all versions
A remote code execution vulnerability exists in Microsoft Office when the software fails to properly handle objects in memory, aka
8.8
HIGH
CVE-2017-0003
all versions
Microsoft Word 2016 and SharePoint Enterprise Server 2016 allow remote attackers to execute arbitrary code via a crafted document,
7.8
HIGH
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh · Open-source threat intelligence platform · 100+ authoritative sources · Every fact traces to its origin