threat
engine
.sh
Back
·
··:··
Home
/
Product
/
microsoft sharepoint foundation
Product
microsoft sharepoint foundation
226 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
Sort
Newest first
Oldest first
Highest CVSS
Lowest CVSS
Min CVSS
Any
4.0+
7.0+ (High)
9.0+ (Critical)
Published since
Reset
CVE-2023-28288
all versions
Microsoft SharePoint Server Spoofing Vulnerability
8.1
HIGH
CVE-2023-23395
all versions
Microsoft SharePoint Server Spoofing Vulnerability
3.1
LOW
CVE-2023-21717
all versions
Microsoft SharePoint Server Elevation of Privilege Vulnerability
8.8
HIGH
CVE-2023-21716
all versions
Microsoft Word Remote Code Execution Vulnerability
9.8
CRITICAL
CVE-2023-21744
all versions
Microsoft SharePoint Server Remote Code Execution Vulnerability
8.8
HIGH
CVE-2023-21742
all versions
Microsoft SharePoint Server Remote Code Execution Vulnerability
8.8
HIGH
CVE-2022-44693
all versions
Microsoft SharePoint Server Remote Code Execution Vulnerability
8.8
HIGH
CVE-2022-44690
all versions
Microsoft SharePoint Server Remote Code Execution Vulnerability
8.8
HIGH
CVE-2022-41122
all versions
Microsoft SharePoint Server Spoofing Vulnerability
6.5
MEDIUM
CVE-2022-41062
all versions
Microsoft SharePoint Server Remote Code Execution Vulnerability
8.8
HIGH
CVE-2022-41038
all versions
Microsoft SharePoint Server Remote Code Execution Vulnerability
8.8
HIGH
CVE-2022-41037
all versions
Microsoft SharePoint Server Remote Code Execution Vulnerability
8.8
HIGH
CVE-2022-41036
all versions
Microsoft SharePoint Server Remote Code Execution Vulnerability
8.8
HIGH
CVE-2022-38053
all versions
Microsoft SharePoint Server Remote Code Execution Vulnerability
8.8
HIGH
CVE-2022-38009
all versions
Microsoft SharePoint Server Remote Code Execution Vulnerability
8.8
HIGH
CVE-2022-38008
all versions
Microsoft SharePoint Server Remote Code Execution Vulnerability
8.8
HIGH
CVE-2022-37961
all versions
Microsoft SharePoint Server Remote Code Execution Vulnerability
8.8
HIGH
CVE-2022-35823
all versions
Microsoft SharePoint Remote Code Execution Vulnerability
8.8
HIGH
CVE-2022-30158
all versions
Microsoft SharePoint Server Remote Code Execution Vulnerability
8.8
HIGH
CVE-2022-29108
all versions
Microsoft SharePoint Server Remote Code Execution Vulnerability
8.8
HIGH
CVE-2022-24472
all versions
Microsoft SharePoint Server Spoofing Vulnerability
8.0
HIGH
CVE-2022-22005
all versions
Microsoft SharePoint Server Remote Code Execution Vulnerability
8.8
HIGH
CVE-2022-21987
all versions
Microsoft SharePoint Server Spoofing Vulnerability
8.0
HIGH
CVE-2022-21968
all versions
Microsoft SharePoint Server Security Feature Bypass Vulnerability
4.3
MEDIUM
CVE-2022-21837
all versions
Microsoft SharePoint Server Remote Code Execution Vulnerability
8.3
HIGH
CVE-2021-43242
all versions
Microsoft SharePoint Server Spoofing Vulnerability
7.6
HIGH
CVE-2021-42309
all versions
Microsoft SharePoint Server Remote Code Execution Vulnerability
8.8
HIGH
CVE-2021-42294
all versions
Microsoft SharePoint Server Remote Code Execution Vulnerability
7.2
HIGH
CVE-2021-41344
all versions
Microsoft SharePoint Server Remote Code Execution Vulnerability
8.1
HIGH
CVE-2021-40487
all versions
Microsoft SharePoint Server Remote Code Execution Vulnerability
8.1
HIGH
CVE-2021-40484
all versions
Microsoft SharePoint Server Spoofing Vulnerability
7.6
HIGH
CVE-2021-38652
all versions
Microsoft SharePoint Server Spoofing Vulnerability
7.6
HIGH
CVE-2021-38651
all versions
Microsoft SharePoint Server Spoofing Vulnerability
7.6
HIGH
CVE-2021-34467
all versions
Microsoft SharePoint Server Remote Code Execution Vulnerability
7.1
HIGH
CVE-2021-34520
all versions
Microsoft SharePoint Server Remote Code Execution Vulnerability
8.1
HIGH
CVE-2021-34519
all versions
Microsoft SharePoint Server Information Disclosure Vulnerability
5.3
MEDIUM
CVE-2021-34517
all versions
Microsoft SharePoint Server Spoofing Vulnerability
5.3
MEDIUM
CVE-2021-34468
all versions
Microsoft SharePoint Server Remote Code Execution Vulnerability
7.1
HIGH
CVE-2021-31966
all versions
Microsoft SharePoint Server Remote Code Execution Vulnerability
7.2
HIGH
CVE-2021-31965
all versions
Microsoft SharePoint Server Information Disclosure Vulnerability
5.7
MEDIUM
CVE-2021-31964
all versions
Microsoft SharePoint Server Spoofing Vulnerability
7.6
HIGH
CVE-2021-31963
all versions
Microsoft SharePoint Server Remote Code Execution Vulnerability
7.1
HIGH
CVE-2021-31950
all versions
Microsoft SharePoint Server Spoofing Vulnerability
7.6
HIGH
CVE-2021-31948
all versions
Microsoft SharePoint Server Spoofing Vulnerability
7.6
HIGH
CVE-2021-26420
all versions
Microsoft SharePoint Server Remote Code Execution Vulnerability
7.1
HIGH
CVE-2021-31181
all versions
Microsoft SharePoint Remote Code Execution Vulnerability
8.8
HIGH
CVE-2021-31173
all versions
Microsoft SharePoint Server Information Disclosure Vulnerability
5.3
MEDIUM
CVE-2021-31172
all versions
Microsoft SharePoint Server Spoofing Vulnerability
7.1
HIGH
CVE-2021-31171
all versions
Microsoft SharePoint Information Disclosure Vulnerability
4.1
MEDIUM
CVE-2021-28478
all versions
Microsoft SharePoint Server Spoofing Vulnerability
7.6
HIGH
CVE-2021-28474
all versions
Microsoft SharePoint Server Remote Code Execution Vulnerability
8.8
HIGH
CVE-2021-26418
all versions
Microsoft SharePoint Server Spoofing Vulnerability
4.6
MEDIUM
CVE-2021-28450
all versions
Microsoft SharePoint Denial of Service Vulnerability
5.0
MEDIUM
CVE-2021-27076
all versions
Microsoft SharePoint Server Remote Code Execution Vulnerability
8.8
HIGH
CVE-2021-24104
all versions
Microsoft SharePoint Server Spoofing Vulnerability
4.6
MEDIUM
CVE-2021-24072
all versions
Microsoft SharePoint Server Remote Code Execution Vulnerability
8.8
HIGH
CVE-2021-24071
all versions
Microsoft SharePoint Information Disclosure Vulnerability
5.3
MEDIUM
CVE-2021-24066
all versions
Microsoft SharePoint Remote Code Execution Vulnerability
8.8
HIGH
CVE-2021-1726
all versions
Microsoft SharePoint Server Spoofing Vulnerability
8.0
HIGH
CVE-2021-1718
all versions
Microsoft SharePoint Server Tampering Vulnerability
8.0
HIGH
CVE-2021-1717
all versions
Microsoft SharePoint Server Spoofing Vulnerability
4.6
MEDIUM
CVE-2021-1712
all versions
Microsoft SharePoint Elevation of Privilege Vulnerability
8.0
HIGH
CVE-2021-1707
all versions
Microsoft SharePoint Server Remote Code Execution Vulnerability
8.8
HIGH
CVE-2021-1641
all versions
Microsoft SharePoint Server Spoofing Vulnerability
4.6
MEDIUM
CVE-2020-17121
all versions
Microsoft SharePoint Remote Code Execution Vulnerability
8.8
HIGH
CVE-2020-17120
all versions
Microsoft SharePoint Information Disclosure Vulnerability
5.3
MEDIUM
CVE-2020-17118
all versions
Microsoft SharePoint Remote Code Execution Vulnerability
8.1
HIGH
CVE-2020-17115
all versions
Microsoft SharePoint Server Spoofing Vulnerability
8.0
HIGH
CVE-2020-17089
all versions
Microsoft SharePoint Elevation of Privilege Vulnerability
7.1
HIGH
CVE-2020-17061
all versions
Microsoft SharePoint Remote Code Execution Vulnerability
8.8
HIGH
CVE-2020-17017
all versions
Microsoft SharePoint Information Disclosure Vulnerability
5.3
MEDIUM
CVE-2020-17016
all versions
Microsoft SharePoint Server Spoofing Vulnerability
8.0
HIGH
CVE-2020-17015
all versions
Microsoft SharePoint Server Spoofing Vulnerability
4.3
MEDIUM
CVE-2020-16979
all versions
Microsoft SharePoint Information Disclosure Vulnerability
5.3
MEDIUM
CVE-2020-16953
all versions
<p>An information disclosure vulnerability exists when Microsoft SharePoint Server fails to properly handle objects in memory. An
6.5
MEDIUM
CVE-2020-16952
all versions
<p>A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an a
8.6
HIGH
CVE-2020-16951
all versions
<p>A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an a
8.6
HIGH
CVE-2020-16948
all versions
<p>An information disclosure vulnerability exists when Microsoft SharePoint Server fails to properly handle objects in memory. An
6.5
MEDIUM
CVE-2020-16946
all versions
<p>A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially craft
8.7
HIGH
CVE-2020-16945
all versions
<p>A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially craft
8.7
HIGH
CVE-2020-16944
all versions
<p>This vulnerability is caused when SharePoint Server does not properly sanitize a specially crafted request to an affected Share
8.7
HIGH
CVE-2020-16942
all versions
<p>An information disclosure vulnerability exists when Microsoft SharePoint Server improperly discloses its folder structure when
4.1
MEDIUM
CVE-2020-16941
all versions
<p>An information disclosure vulnerability exists when Microsoft SharePoint Server improperly discloses its folder structure when
4.1
MEDIUM
CVE-2020-1595
all versions
<p>A remote code execution vulnerability exists in Microsoft SharePoint where APIs aren't properly protected from unsafe data inpu
9.9
CRITICAL
CVE-2020-1576
all versions
<p>A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an a
8.5
HIGH
CVE-2020-1575
all versions
<p>A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially craft
5.4
MEDIUM
CVE-2020-1514
all versions
<p>A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially craft
5.4
MEDIUM
CVE-2020-1482
all versions
<p>A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially craft
6.3
MEDIUM
CVE-2020-1460
all versions
<p>A remote code execution vulnerability exists in Microsoft SharePoint Server when it fails to properly identify and filter unsaf
8.6
HIGH
CVE-2020-1453
all versions
<p>A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an a
8.6
HIGH
CVE-2020-1452
all versions
<p>A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an a
8.6
HIGH
CVE-2020-1345
all versions
<p>A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially craft
7.4
HIGH
CVE-2020-1227
all versions
<p>A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially craft
5.4
MEDIUM
CVE-2020-1210
all versions
<p>A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an a
9.9
CRITICAL
CVE-2020-1205
all versions
<p>A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to
4.6
MEDIUM
CVE-2020-1200
all versions
<p>A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an a
8.6
HIGH
CVE-2020-1198
all versions
<p>A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially craft
7.4
HIGH
CVE-2020-1580
all versions
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted
5.4
MEDIUM
CVE-2020-1573
all versions
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted
5.5
MEDIUM
CVE-2020-1505
all versions
An information disclosure vulnerability exists when Microsoft SharePoint Server fails to properly handle objects in memory. An att
5.5
MEDIUM
CVE-2020-1501
all versions
A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an
5.4
MEDIUM
CVE-2020-1499
all versions
A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an
5.4
MEDIUM
CVE-2020-1444
all versions
A remote code execution vulnerability exists in the way Microsoft SharePoint software parses specially crafted email messages, aka
4.3
MEDIUM
CVE-2020-1443
all versions
A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an
5.4
MEDIUM
CVE-2020-1439
all versions
A remote code execution vulnerability exists in PerformancePoint Services for SharePoint Server when the software fails to check t
8.8
HIGH
CVE-2020-1025
all versions
An elevation of privilege vulnerability exists when Microsoft SharePoint Server and Skype for Business Server improperly handle OA
9.8
CRITICAL
CVE-2020-1320
all versions
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted
5.4
MEDIUM
CVE-2020-1318
all versions
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted
5.4
MEDIUM
CVE-2020-1298
all versions
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted
5.4
MEDIUM
CVE-2020-1297
all versions
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted
5.4
MEDIUM
CVE-2020-1289
all versions
A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an
5.4
MEDIUM
CVE-2020-1183
all versions
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted
5.4
MEDIUM
CVE-2020-1181
all versions
A remote code execution vulnerability exists in Microsoft SharePoint Server when it fails to properly identify and filter unsafe A
8.8
HIGH
CVE-2020-1177
all versions
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted
5.4
MEDIUM
CVE-2020-1107
all versions
A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an
5.4
MEDIUM
CVE-2020-1106
all versions
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted
6.1
MEDIUM
CVE-2020-1104
all versions
A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an
5.4
MEDIUM
CVE-2020-1103
all versions
An information disclosure vulnerability exists where certain modes of the search function in Microsoft SharePoint Server are vulne
6.5
MEDIUM
CVE-2020-1101
all versions
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted
5.4
MEDIUM
CVE-2020-1100
all versions
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted
5.4
MEDIUM
CVE-2020-1069
all versions
A remote code execution vulnerability exists in Microsoft SharePoint Server when it fails to properly identify and filter unsafe A
8.8
HIGH
CVE-2020-1024
all versions
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an appl
8.8
HIGH
CVE-2020-1023
all versions
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an appl
8.8
HIGH
CVE-2020-0978
all versions
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted
5.4
MEDIUM
CVE-2020-0976
all versions
A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an
5.4
MEDIUM
CVE-2020-0975
all versions
A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an
5.4
MEDIUM
CVE-2020-0972
all versions
A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an
5.4
MEDIUM
CVE-2020-0971
all versions
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an appl
8.8
HIGH
CVE-2020-0933
all versions
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted
5.4
MEDIUM
CVE-2020-0932
all versions
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an appl
8.8
HIGH
CVE-2020-0931
all versions
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an appl
8.8
HIGH
CVE-2020-0929
all versions
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an appl
8.8
HIGH
CVE-2020-0925
all versions
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted
5.4
MEDIUM
CVE-2020-0924
all versions
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted
5.4
MEDIUM
CVE-2020-0923
all versions
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted
5.4
MEDIUM
CVE-2020-0920
all versions
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an appl
8.8
HIGH
CVE-2020-0894
all versions
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted
5.4
MEDIUM
CVE-2020-0892
all versions
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'M
7.8
HIGH
CVE-2020-0891
all versions
This vulnerability is caused when SharePoint Server does not properly sanitize a specially crafted request to an affected SharePoi
5.4
MEDIUM
CVE-2020-0850
all versions
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'M
8.8
HIGH
CVE-2020-0795
all versions
This vulnerability is caused when SharePoint Server does not properly sanitize a specially crafted request to an affected SharePoi
5.4
MEDIUM
CVE-2019-1443
all versions
An information disclosure vulnerability exists in Microsoft SharePoint when an attacker uploads a specially crafted file to the Sh
6.5
MEDIUM
CVE-2019-1330
all versions
An elevation of privilege vulnerability exists in Microsoft SharePoint, aka 'Microsoft SharePoint Elevation of Privilege Vulnerabi
6.5
MEDIUM
CVE-2019-1329
all versions
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web
5.4
MEDIUM
CVE-2019-1328
all versions
A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an
5.4
MEDIUM
CVE-2019-1296
all versions
A remote code execution vulnerability exists in Microsoft SharePoint where APIs aren't properly protected from unsafe data input,
8.8
HIGH
CVE-2019-1295
all versions
A remote code execution vulnerability exists in Microsoft SharePoint where APIs aren't properly protected from unsafe data input,
8.8
HIGH
CVE-2019-1262
all versions
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted
5.4
MEDIUM
CVE-2019-1261
all versions
A spoofing vulnerability exists in Microsoft SharePoint when it improperly handles requests to authorize applications, resulting i
8.8
HIGH
CVE-2019-1260
all versions
An elevation of privilege vulnerability exists in Microsoft SharePoint, aka 'Microsoft SharePoint Elevation of Privilege Vulnerabi
6.5
MEDIUM
CVE-2019-1259
all versions
A spoofing vulnerability exists in Microsoft SharePoint when it improperly handles requests to authorize applications, resulting i
8.8
HIGH
CVE-2019-1257
all versions
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an appl
8.8
HIGH
CVE-2019-1202
all versions
An information disclosure vulnerability exists in the way Microsoft SharePoint handles session objects. An authenticated attacker
4.4
MEDIUM
CVE-2019-1006
all versions
An authentication bypass vulnerability exists in Windows Communication Foundation (WCF) and Windows Identity Foundation (WIF), all
7.5
HIGH
CVE-2019-1036
all versions
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted
5.4
MEDIUM
CVE-2019-1033
all versions
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted
5.4
MEDIUM
CVE-2019-1031
all versions
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted
5.4
MEDIUM
CVE-2019-0963
all versions
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted
5.4
MEDIUM
CVE-2019-0958
all versions
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web
8.8
HIGH
CVE-2019-0956
all versions
An information disclosure vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web
6.5
MEDIUM
CVE-2019-0952
all versions
A remote code execution vulnerability exists in Microsoft SharePoint Server when it fails to properly identify and filter unsafe A
8.8
HIGH
CVE-2019-0951
all versions
A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an
5.4
MEDIUM
CVE-2019-0950
all versions
A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an
5.7
MEDIUM
CVE-2019-0949
all versions
A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an
5.7
MEDIUM
CVE-2019-0831
all versions
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted
5.4
MEDIUM
CVE-2019-0830
all versions
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted
5.4
MEDIUM
CVE-2019-0778
all versions
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted
5.4
MEDIUM
CVE-2019-0670
all versions
A spoofing vulnerability exists in Microsoft SharePoint when the application does not properly parse HTTP content, aka 'Microsoft
6.1
MEDIUM
CVE-2019-0604
all versions
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an appl
9.8
CRITICAL
CVE-2019-0594
all versions
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an appl
8.8
HIGH
CVE-2018-8572
all versions
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web
5.4
MEDIUM
CVE-2018-8568
all versions
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web
5.4
MEDIUM
CVE-2018-8299
all versions
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web
5.4
MEDIUM
CVE-2018-8284
all versions
A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka ".NET Framewo
8.1
HIGH
CVE-2018-8254
all versions
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web
5.4
MEDIUM
CVE-2018-8252
all versions
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web
5.4
MEDIUM
CVE-2018-8155
all versions
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web
5.4
MEDIUM
CVE-2018-0790
all versions
Microsoft SharePoint Foundation 2010, Microsoft SharePoint Server 2013 and Microsoft SharePoint Server 2016 allow an elevation of
8.8
HIGH
CVE-2017-8745
all versions
An elevation of privilege vulnerability exists in Microsoft SharePoint Foundation 2013 Service Pack 1 when it does not properly sa
5.4
MEDIUM
CVE-2017-0281
all versions
Microsoft Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office 2016, Office Online Server 2016, Office Web Apps 2010 SP2,Offi
7.8
HIGH
CVE-2017-0255
all versions
Microsoft SharePoint Foundation 2013 SP1 allows an elevation of privilege vulnerability when it does not properly sanitize a speci
5.4
MEDIUM
CVE-2017-0107
all versions
Microsoft SharePoint Server fails to sanitize crafted web requests, allowing remote attackers to run cross-script in local securit
6.1
MEDIUM
CVE-2016-3357
all versions
Microsoft Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office 2013 RT SP1, Office 2016, Word for Mac 2011, Word 2016 for Mac
7.8
HIGH
CVE-2016-0136
all versions
Microsoft Excel 2007 SP3, Excel 2010 SP2, Office Compatibility Pack SP3, Excel Services on SharePoint Server 2007 SP3, and Excel S
7.8
HIGH
CVE-2016-0054
all versions
Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Excel for Mac 2011, Excel 2016 for Mac, O
7.8
HIGH
CVE-2016-0039
all versions
Cross-site scripting (XSS) vulnerability in SharePoint Server in Microsoft SharePoint Foundation 2013 SP1 allows remote attackers
6.1
MEDIUM
CVE-2016-0011
all versions
Microsoft SharePoint Server 2013 SP1 and SharePoint Foundation 2013 SP1 allow remote authenticated users to bypass intended Access
5.4
MEDIUM
CVE-2015-6117
all versions
Microsoft SharePoint Server 2013 SP1 and SharePoint Foundation 2013 SP1 allow remote authenticated users to bypass intended Access
6.1
MEDIUM
CVE-2015-6039
all versions
Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2013 SP1 and SharePoint Foundation 2013 SP1 allows remote
CVE-2015-6037
all versions
Cross-site scripting (XSS) vulnerability in Microsoft Excel Services on SharePoint Server 2010 SP2 and 2013 SP1, Office Web Apps 2
CVE-2015-2522
all versions
Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Foundation 2013 SP1 allows remote authenticated users to inject a
CVE-2015-1700
all versions
Microsoft SharePoint Server 2007 SP3, SharePoint Foundation 2010 SP2, SharePoint Server 2010 SP2, and SharePoint Foundation 2013 S
CVE-2015-1682
all versions
Microsoft Office 2010 SP2, Excel 2010 SP2, PowerPoint 2010 SP2, Word 2010 SP2, Office 2013 SP1, Excel 2013 SP1, PowerPoint 2013 SP
CVE-2015-1653
all versions
Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Foundation 2013 SP1 and SharePoint Server 2013 SP1 allows remote
CVE-2015-1636
all versions
Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Foundation 2013 Gold and SP1 and SharePoint Server 2013 Gold and
CVE-2015-1633
all versions
Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Foundation 2010 SP2, SharePoint Server 2010 SP2, SharePoint Found
CVE-2015-0085
all versions
Use-after-free vulnerability in Microsoft Office 2007 SP3, Excel 2007 SP3, PowerPoint 2007 SP3, Word 2007 SP3, Office 2010 SP2, Ex
CVE-2014-4116
all versions
Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Foundation 2010 SP2 allows remote authenticated users to inject a
CVE-2014-2816
all versions
Microsoft SharePoint Server 2013 Gold and SP1 and SharePoint Foundation 2013 Gold and SP1 allow remote authenticated users to gain
CVE-2014-1754
all versions
Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2013 Gold and SP1, SharePoint Foundation 2013 Gold and SP1
CVE-2014-0251
all versions
Microsoft Windows SharePoint Services 3.0 SP3; SharePoint Server 2007 SP3, 2010 SP1 and SP2, and 2013 Gold and SP1; SharePoint Fou
CVE-2013-3847
all versions
Microsoft Word Automation Services in SharePoint Server 2010 SP1, Word Web App 2010 SP1 in Office Web Apps 2010, Word 2003 SP3, Wo
CVE-2013-3180
all versions
Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2010 SP1 and SP2 and 2013 allows remote attackers to injec
CVE-2013-3179
all versions
Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2007 SP3, 2010 SP1 and SP2, and 2013 allows remote attacke
CVE-2013-1330
all versions
The default configuration of Microsoft SharePoint Portal Server 2003 SP3, SharePoint Server 2007 SP3 and 2010 SP1 and SP2, and Off
CVE-2013-1315
all versions
Microsoft SharePoint Server 2007 SP3, 2010 SP1 and SP2, and 2013; Office Web Apps 2010; Excel 2003 SP3, 2007 SP3, 2010 SP1 and SP2
CVE-2013-0081
all versions
Microsoft SharePoint Portal Server 2003 SP3 and SharePoint Server 2007 SP3, 2010 SP1 and SP2, and 2013 do not properly process una
CVE-2013-1289
all versions
Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2010 SP1, Groove Server 2010 SP1, SharePoint Foundation 20
CVE-2013-0086
all versions
Microsoft OneNote 2010 SP1 does not properly determine buffer sizes during memory allocation, which allows remote attackers to obt
CVE-2013-0085
all versions
Buffer overflow in Microsoft SharePoint Server 2010 SP1 and SharePoint Foundation 2010 SP1 allows remote attackers to cause a deni
CVE-2013-0084
all versions
Directory traversal vulnerability in Microsoft SharePoint Server 2010 SP1 and SharePoint Foundation 2010 SP1 allows remote attacke
CVE-2013-0083
all versions
Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2010 SP1 allows remote attackers to inject arbitrary web s
CVE-2013-0080
all versions
Microsoft SharePoint Server 2010 SP1 and SharePoint Foundation 2010 SP1 allow remote attackers to bypass intended read restriction
CVE-2012-2520
all versions
Cross-site scripting (XSS) vulnerability in Microsoft InfoPath 2007 SP2 and SP3 and 2010 SP1, Communicator 2007 R2, Lync 2010 and
CVE-2012-1863
all versions
Cross-site scripting (XSS) vulnerability in Microsoft Office SharePoint Server 2007 SP2 and SP3 Windows SharePoint Services 3.0 SP
CVE-2012-1861
all versions
Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2010 Gold and SP1, SharePoint Foundation 2010 Gold and SP1
CVE-2012-1859
all versions
Cross-site scripting (XSS) vulnerability in scriptresx.ashx in Microsoft SharePoint Server 2010 Gold and SP1, SharePoint Foundatio
CVE-2012-0145
all versions
Cross-site scripting (XSS) vulnerability in wizardlist.aspx in Microsoft Office SharePoint Server 2010 Gold and SP1 and SharePoint
CVE-2012-0144
all versions
Cross-site scripting (XSS) vulnerability in themeweb.aspx in Microsoft Office SharePoint Server 2010 Gold and SP1 and SharePoint F
CVE-2012-0017
all versions
Cross-site scripting (XSS) vulnerability in inplview.aspx in Microsoft SharePoint Foundation 2010 Gold and SP1 allows remote attac
CVE-2011-1893
all versions
Cross-site scripting (XSS) vulnerability in Microsoft Office SharePoint Server 2010, Windows SharePoint Services 2.0 and 3.0 SP2,
CVE-2011-1892
all versions
Microsoft Office Groove 2007 SP2, SharePoint Workspace 2010 Gold and SP1, Office Forms Server 2007 SP2, Office SharePoint Server 2
CVE-2011-1891
all versions
Cross-site scripting (XSS) vulnerability in Microsoft Windows SharePoint Services 3.0 SP2, and SharePoint Foundation 2010 Gold and
CVE-2011-1890
all versions
Cross-site scripting (XSS) vulnerability in EditForm.aspx in Microsoft Office SharePoint Server 2010 and SharePoint Foundation 201
CVE-2011-0653
all versions
Cross-site scripting (XSS) vulnerability in Microsoft Office SharePoint Server 2010 Gold and SP1, and SharePoint Foundation 2010,
CVE-2010-3324
all versions
The toStaticHTML function in Microsoft Internet Explorer 8, and the SafeHTML function in Microsoft Windows SharePoint Services 3.0
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh · Open-source threat intelligence platform · 100+ authoritative sources · Every fact traces to its origin