CVEs (226)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Microsoft 1Sharepoint Foundation May 13, 2026 May 12, 2017 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Microsoft SharePoint Foundation 2013 SP1 allows an elevation of privilege vulnerability when it does not properly sanitize a specially crafted web request, aka "Microsoft SharePoint XSS Vulnerability". |
1Microsoft 1Sharepoint Foundation May 13, 2026 Mar 17, 2017 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Microsoft SharePoint Server fails to sanitize crafted web requests, allowing remote attackers to run cross-script in local security context, aka "Microsoft SharePoint XSS Vulnerability." |
1Microsoft 6Office Office Web AppsOffice Web Apps Server+3 moreMay 6, 2026 Sep 14, 2016 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 Microsoft Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office 2013 RT SP1, Office 2016, Word for Mac 2011, Word 2016 for Mac, Word Viewer, Word Automation Services on SharePoint Server 2010 SP2, SharePoint Server 2...Show more |
1Microsoft 4Excel Office Compatibility PackSharepoint Designer+1 moreMay 6, 2026 Apr 12, 2016 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 Microsoft Excel 2007 SP3, Excel 2010 SP2, Office Compatibility Pack SP3, Excel Services on SharePoint Server 2007 SP3, and Excel Services on SharePoint Server 2010 SP2 allow remote attackers to execute arbitrary code via...Show more |
1Microsoft 8Excel Excel For MacExcel Viewer+5 moreMay 6, 2026 Feb 10, 2016 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Excel for Mac 2011, Excel 2016 for Mac, Office Compatibility Pack SP3, Excel Viewer, Excel Services on SharePoint Server 2007 SP3,...Show more |
1Microsoft 1Sharepoint Foundation May 6, 2026 Feb 10, 2016 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in SharePoint Server in Microsoft SharePoint Foundation 2013 SP1 allows remote attackers to inject arbitrary web script or HTML via a crafted request, aka "Microsoft SharePoint XS...Show more |
1Microsoft 2Sharepoint Foundation Sharepoint ServerMay 6, 2026 Jan 13, 2016 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Microsoft SharePoint Server 2013 SP1 and SharePoint Foundation 2013 SP1 allow remote authenticated users to bypass intended Access Control Policy restrictions and conduct cross-site scripting (XSS) attacks by modifying a...Show more |
1Microsoft 2Sharepoint Foundation Sharepoint ServerMay 6, 2026 Jan 13, 2016 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Microsoft SharePoint Server 2013 SP1 and SharePoint Foundation 2013 SP1 allow remote authenticated users to bypass intended Access Control Policy restrictions and conduct cross-site scripting (XSS) attacks by modifying a...Show more |
1Microsoft 2Sharepoint Foundation Sharepoint ServerMay 6, 2026 Oct 14, 2015 N/A· v4 N/A· v3 3.5 LOW· v2 Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2013 SP1 and SharePoint Foundation 2013 SP1 allows remote authenticated users to inject arbitrary web script or HTML via crafted content in an Offic...Show more |
1Microsoft 4Excel Web App Office Web AppsSharepoint Foundation+1 moreMay 6, 2026 Oct 14, 2015 N/A· v4 N/A· v3 3.5 LOW· v2 Cross-site scripting (XSS) vulnerability in Microsoft Excel Services on SharePoint Server 2010 SP2 and 2013 SP1, Office Web Apps 2010 SP2, Excel Web App 2010 SP2, Office Web Apps Server 2013 SP1, and SharePoint Foundatio...Show more |
Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Foundation 2013 SP1 allows remote authenticated users to inject arbitrary web script or HTML via crafted content, aka "Microsoft SharePoint XSS Spoofing Vu...Show more |
1Microsoft 2Sharepoint Foundation Sharepoint ServerMay 6, 2026 May 13, 2015 N/A· v4 N/A· v3 6.0 MEDIUM· v2 Microsoft SharePoint Server 2007 SP3, SharePoint Foundation 2010 SP2, SharePoint Server 2010 SP2, and SharePoint Foundation 2013 SP1 allow remote authenticated users to execute arbitrary code via crafted page content, ak...Show more |
1Microsoft 9Excel Excel Web AppOffice+6 moreMay 6, 2026 May 13, 2015 N/A· v4 N/A· v3 9.3 HIGH· v2 Microsoft Office 2010 SP2, Excel 2010 SP2, PowerPoint 2010 SP2, Word 2010 SP2, Office 2013 SP1, Excel 2013 SP1, PowerPoint 2013 SP1, Word 2013 SP1, Office 2013 RT SP1, Excel 2013 RT SP1, PowerPoint 2013 RT SP1, Word 2013...Show more |
1Microsoft 2Sharepoint Foundation Sharepoint ServerMay 6, 2026 Apr 14, 2015 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Foundation 2013 SP1 and SharePoint Server 2013 SP1 allows remote attackers to inject arbitrary web script or HTML via a crafted request, aka "Microsoft Sha...Show more |
1Microsoft 2Sharepoint Foundation Sharepoint ServerMay 6, 2026 Mar 11, 2015 N/A· v4 N/A· v3 3.5 LOW· v2 Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Foundation 2013 Gold and SP1 and SharePoint Server 2013 Gold and SP1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted...Show more |
1Microsoft 2Sharepoint Foundation Sharepoint ServerMay 6, 2026 Mar 11, 2015 N/A· v4 N/A· v3 3.5 LOW· v2 Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Foundation 2010 SP2, SharePoint Server 2010 SP2, SharePoint Foundation 2013 Gold and SP1, and SharePoint Server 2013 Gold and SP1 allows remote authenticat...Show more |
1Microsoft 11Excel Excel ViewerOffice+8 moreMay 6, 2026 Mar 11, 2015 N/A· v4 N/A· v3 9.3 HIGH· v2 Use-after-free vulnerability in Microsoft Office 2007 SP3, Excel 2007 SP3, PowerPoint 2007 SP3, Word 2007 SP3, Office 2010 SP2, Excel 2010 SP2, PowerPoint 2010 SP2, Word 2010 SP2, Office 2013 Gold and SP1, Word 2013 Gold...Show more |
Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Foundation 2010 SP2 allows remote authenticated users to inject arbitrary web script or HTML via a modified list, aka "SharePoint Elevation of Privilege Vu...Show more |
1Microsoft 2Sharepoint Foundation Sharepoint ServerMay 6, 2026 Aug 12, 2014 N/A· v4 N/A· v3 9.3 HIGH· v2 Microsoft SharePoint Server 2013 Gold and SP1 and SharePoint Foundation 2013 Gold and SP1 allow remote authenticated users to gain privileges via a Trojan horse app that executes a custom action in the context of the Sha...Show more |
1Microsoft 4Office Web Apps Server Sharepoint FoundationSharepoint Server+1 moreMay 6, 2026 May 14, 2014 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2013 Gold and SP1, SharePoint Foundation 2013 Gold and SP1, Office Web Apps Server 2013 Gold and SP1, and SharePoint Server 2013 Client Components S...Show more |