CVEs (226)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Microsoft 3Business Productivity Servers Sharepoint Enterprise ServerSharepoint FoundationFeb 28, 2025 Mar 12, 2020 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 This vulnerability is caused when SharePoint Server does not properly sanitize a specially crafted request to an affected SharePoint server.An authenticated attacker could exploit this vulnerability by sending a speciall...Show more |
1Microsoft 3Sharepoint Enterprise Server Sharepoint FoundationSharepoint ServerNov 21, 2024 Nov 12, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 An information disclosure vulnerability exists in Microsoft SharePoint when an attacker uploads a specially crafted file to the SharePoint Server.An authenticated attacker who successfully exploited this vulnerability co...Show more |
1Microsoft 2Sharepoint Enterprise Server Sharepoint FoundationNov 21, 2024 Oct 10, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 An elevation of privilege vulnerability exists in Microsoft SharePoint, aka 'Microsoft SharePoint Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1329. |
1Microsoft 2Sharepoint Enterprise Server Sharepoint FoundationNov 21, 2024 Oct 10, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Elevation of Privileg...Show more |
1Microsoft 2Sharepoint Enterprise Server Sharepoint FoundationNov 21, 2024 Oct 10, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Spoofing Vulnerability'. |
1Microsoft 3Sharepoint Enterprise Server Sharepoint FoundationSharepoint ServerNov 21, 2024 Sep 11, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A remote code execution vulnerability exists in Microsoft SharePoint where APIs aren't properly protected from unsafe data input, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from...Show more |
1Microsoft 3Sharepoint Enterprise Server Sharepoint FoundationSharepoint ServerNov 21, 2024 Sep 11, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A remote code execution vulnerability exists in Microsoft SharePoint where APIs aren't properly protected from unsafe data input, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from...Show more |
1Microsoft 1Sharepoint Foundation Nov 21, 2024 Sep 11, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnera...Show more |
1Microsoft 3Sharepoint Enterprise Server Sharepoint FoundationSharepoint ServerNov 21, 2024 Sep 11, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A spoofing vulnerability exists in Microsoft SharePoint when it improperly handles requests to authorize applications, resulting in cross-site request forgery (CSRF).To exploit this vulnerability, an attacker would need...Show more |
1Microsoft 3Sharepoint Enterprise Server Sharepoint FoundationSharepoint ServerNov 21, 2024 Sep 11, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 An elevation of privilege vulnerability exists in Microsoft SharePoint, aka 'Microsoft SharePoint Elevation of Privilege Vulnerability'. |
1Microsoft 1Sharepoint Foundation Nov 21, 2024 Sep 11, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A spoofing vulnerability exists in Microsoft SharePoint when it improperly handles requests to authorize applications, resulting in cross-site request forgery (CSRF).To exploit this vulnerability, an attacker would need...Show more |
1Microsoft 3Sharepoint Enterprise Server Sharepoint FoundationSharepoint ServerNov 21, 2024 Sep 11, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE...Show more |
1Microsoft 3Sharepoint Enterprise Server Sharepoint FoundationSharepoint ServerFeb 20, 2026 Aug 14, 2019 N/A· v4 4.4 MEDIUM· v3 3.6 LOW· v2 An information disclosure vulnerability exists in the way Microsoft SharePoint handles session objects. An authenticated attacker who successfully exploited the vulnerability could hijack the session of another user. To...Show more |
1Microsoft 13.net Framework IdentitymodelSharepoint Enterprise Server+10 moreNov 21, 2024 Jul 15, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An authentication bypass vulnerability exists in Windows Communication Foundation (WCF) and Windows Identity Foundation (WIF), allowing signing of SAML tokens with arbitrary symmetric keys, aka 'WCF/WIF SAML Token Authen...Show more |
1Microsoft 4Project Server Sharepoint Enterprise ServerSharepoint Foundation+1 moreMay 20, 2025 Jun 12, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the...Show more |
1Microsoft 4Project Server Sharepoint Enterprise ServerSharepoint Foundation+1 moreMay 20, 2025 Jun 12, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the...Show more |
1Microsoft 4Project Server Sharepoint Enterprise ServerSharepoint Foundation+1 moreMay 20, 2025 Jun 12, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the...Show more |
1Microsoft 1Sharepoint Foundation Feb 28, 2025 May 16, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnera...Show more |
1Microsoft 2Sharepoint Foundation Sharepoint ServerNov 21, 2024 May 16, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Elevation of Privileg...Show more |
1Microsoft 2Sharepoint Enterprise Server Sharepoint FoundationNov 21, 2024 May 16, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 An information disclosure vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Server Information Di...Show more |