Microsoft Sharepoint vulnerabilities

36 known vulnerabilities affecting microsoft/microsoft_sharepoint.

Total CVEs
36
CISA KEV
0
Public exploits
0
Exploited in wild
1
Severity breakdown
HIGH7MEDIUM29

Vulnerabilities

Page 2 of 2
CVE-2018-8300HIGHCVSS 8.8vEnterprise Server 2016vFoundation 2013 Service Pack 12018-07-11
CVE-2018-8300 [HIGH] CWE-20 CVE-2018-8300: A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to chec A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka "Microsoft SharePoint Remote Code Execution Vulnerability." This affects Microsoft SharePoint.
cvelistv5nvd
CVE-2018-8299MEDIUMCVSS 5.4vEnterprise Server 2013 Service Pack 1vEnterprise Server 20162018-07-11
CVE-2018-8299 [MEDIUM] CWE-79 CVE-2018-8299: An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sa An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft SharePoint. This CVE ID is unique from CVE-2018-8323.
cvelistv5nvd
CVE-2018-8323MEDIUMCVSS 5.4vEnterprise Server 2013 Service Pack 1vEnterprise Server 20162018-07-11
CVE-2018-8323 [MEDIUM] CVE-2018-8323: An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affec An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft SharePoint. This CVE ID is unique from CVE-2018-82
cvelistv5
CVE-2018-8254MEDIUMCVSS 5.4vEnterprise Server 2016vFoundation 2013 Service Pack 12018-06-14
CVE-2018-8254 [MEDIUM] CVE-2018-8254: An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affec An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft Project Server, Microsoft SharePoint. This CVE ID
cvelistv5
CVE-2018-8252MEDIUMCVSS 5.4vEnterprise Server 2016vFoundation 2013 Service Pack 12018-06-14
CVE-2018-8252 [MEDIUM] CWE-79 CVE-2018-8252: An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sa An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft SharePoint. This CVE ID is unique from CVE-2018-8254.
cvelistv5nvd
CVE-2018-8161HIGHCVSS 7.8vEnterprise Server 20162018-05-09
CVE-2018-8161 [HIGH] CVE-2018-8161: A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory, aka "Microsoft A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory, aka "Microsoft Office Remote Code Execution Vulnerability." This affects Microsoft Word, Word, Microsoft Office, Microsoft SharePoint. This CVE ID is unique from CVE-2018-8157,
cvelistv5
CVE-2018-8157HIGHCVSS 7.8vEnterprise Server 20162018-05-09
CVE-2018-8157 [HIGH] CVE-2018-8157: A remote code execution vulnerability exists in Microsoft Office software when the software fails to A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory, aka "Microsoft Office Remote Code Execution Vulnerability." This affects Microsoft Office. This CVE ID is unique from CVE-2018-8158, CVE-2018-8161.
nvd
CVE-2018-8149MEDIUMCVSS 5.4vEnterprise Server 2013 Service Pack 12018-05-09
CVE-2018-8149 [MEDIUM] CWE-79 CVE-2018-8149: An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sa An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft SharePoint Server, Microsoft SharePoint. This CVE ID is unique from CVE-2018-8155, CVE-2018-8
cvelistv5nvd
CVE-2018-8168MEDIUMCVSS 5.4vEnterprise Server 2013 Service Pack 12018-05-09
CVE-2018-8168 [MEDIUM] CVE-2018-8168: An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affec An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft SharePoint Server, Microsoft SharePoint. This CVE
cvelistv5
CVE-2018-8156MEDIUMCVSS 5.4vEnterprise Server 20162018-05-09
CVE-2018-8156 [MEDIUM] CVE-2018-8156: An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affec An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft SharePoint, Microsoft Project Server. This CVE ID
cvelistv5
CVE-2018-8155MEDIUMCVSS 5.4vEnterprise Server 2016vFoundation 2013 Service Pack 12018-05-09
CVE-2018-8155 [MEDIUM] CVE-2018-8155: An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affec An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft SharePoint. This CVE ID is unique from CVE-2018-81
cvelistv5
CVE-2018-1028HIGHCVSS 8.8vEnterprise Server 20162018-04-12
CVE-2018-1028 [HIGH] CWE-94 CVE-2018-1028: A remote code execution vulnerability exists when the Office graphics component improperly handles s A remote code execution vulnerability exists when the Office graphics component improperly handles specially crafted embedded fonts, aka "Microsoft Office Graphics Remote Code Execution Vulnerability." This affects Word, Microsoft Office, Microsoft SharePoint, Excel, Microsoft SharePoint Server.
cvelistv5nvd
CVE-2018-1014MEDIUMCVSS 5.4vEnterprise Server 2013 Service Pack 1vEnterprise Server 20162018-04-12
CVE-2018-1014 [MEDIUM] CVE-2018-1014: An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affec An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft SharePoint. This CVE ID is unique from CVE-2018-10
cvelistv5
CVE-2018-1032MEDIUMCVSS 5.4vEnterprise Server 2013 Service Pack 1vEnterprise Server 20162018-04-12
CVE-2018-1032 [MEDIUM] CVE-2018-1032: An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affec An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft SharePoint Server, Microsoft SharePoint. This CVE
cvelistv5
CVE-2018-1034MEDIUMCVSS 5.4vEnterprise Server 20162018-04-12
CVE-2018-1034 [MEDIUM] CVE-2018-1034: An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affec An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft SharePoint. This CVE ID is unique from CVE-2018-10
cvelistv5
CVE-2018-1005MEDIUMCVSS 5.4vEnterprise Server 20162018-04-12
CVE-2018-1005 [MEDIUM] CWE-79 CVE-2018-1005: An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sa An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft SharePoint. This CVE ID is unique from CVE-2018-1014, CVE-2018-1032, CVE-2018-1034.
cvelistv5nvd