Microsoft Project Server vulnerabilities
24 known vulnerabilities affecting microsoft/project_server.
Total CVEs
24
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH12MEDIUM9
Vulnerabilities
Page 1 of 2
CVE-2020-0954MEDIUMCVSS 5.4v20132020-04-15
CVE-2020-0954 [MEDIUM] CVE-2020-0954: A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE-2020-0923, CVE-2020-0924, CVE-2020-0925, CVE-2020-0926, CVE-2020-0927, CVE-2020-0930, CVE-2020-0933,
nvd
CVE-2019-1033MEDIUMCVSS 5.4v20102019-06-12
CVE-2019-1033 [MEDIUM] CWE-79 CVE-2019-1033: A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially crafted request to an affected SharePoint server.
The attacker who successfully exploited the vul
nvd
CVE-2019-1036MEDIUMCVSS 5.4v20102019-06-12
CVE-2019-1036 [MEDIUM] CWE-79 CVE-2019-1036: A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially crafted request to an affected SharePoint server.
The attacker who successfully exploited the vul
nvd
CVE-2019-1031MEDIUMCVSS 5.4v20102019-06-12
CVE-2019-1031 [MEDIUM] CWE-79 CVE-2019-1031: A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially crafted request to an affected SharePoint server.
The attacker who successfully exploited the vul
nvd
CVE-2018-8284HIGHCVSS 8.1v2010v20132018-07-11
CVE-2018-8284 [HIGH] CWE-94 CVE-2018-8284: A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate inp
A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka ".NET Framework Remote Code Injection Vulnerability." This affects Microsoft .NET Framework 2.0, Microsoft .NET Framework 3.0, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.5.2, Microsoft .NET Framework 4.6, Mi
nvd
CVE-2018-8254MEDIUMCVSS 5.4v20102018-06-14
CVE-2018-8254 [MEDIUM] CVE-2018-8254: An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sa
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft Project Server, Microsoft SharePoint. This CVE ID is unique from CVE-2018-8252.
nvd
CVE-2018-8156MEDIUMCVSS 5.4v2010v20132018-05-09
CVE-2018-8156 [MEDIUM] CVE-2018-8156: An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sa
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft SharePoint, Microsoft Project Server. This CVE ID is unique from CVE-2018-8149, CVE-2018-8155, CVE-2
nvd
CVE-2018-0911HIGHCVSS 8.8v20132018-03-14
CVE-2018-0911 [HIGH] CVE-2018-0911: Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation
Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation of privilege vulnerability to due how specially crafted web requests are sanitized, aka "Microsoft SharePoint Elevation of Privilege Vulnerability". This CVE is unique from CVE-2018-0909, CVE-2018-0910, CVE-2018-0912, CVE-2018-0913, CVE-2018-0914, CVE-2018-0915,
nvd
CVE-2018-0914HIGHCVSS 8.8v20132018-03-14
CVE-2018-0914 [HIGH] CVE-2018-0914: Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation
Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation of privilege vulnerability to due how specially crafted web requests are sanitized, aka "Microsoft SharePoint Elevation of Privilege Vulnerability". This CVE is unique from CVE-2018-0909, CVE-2018-0910. CVE-2018-0911, CVE-2018-0912, CVE-2018-0913, CVE-2018-0915,
nvd
CVE-2018-0909HIGHCVSS 8.8v20132018-03-14
CVE-2018-0909 [HIGH] CWE-79 CVE-2018-0909: Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation
Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation of privilege vulnerability to due how specially crafted web requests are sanitized, aka "Microsoft SharePoint Elevation of Privilege Vulnerability". This CVE is unique from CVE-2018-0910, CVE-2018-0911, CVE-2018-0912, CVE-2018-0913, CVE-2018-0914, CVE-201
nvd
CVE-2018-0944HIGHCVSS 8.8v20132018-03-14
CVE-2018-0944 [HIGH] CVE-2018-0944: Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allows an elevatio
Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allows an elevation of privilege vulnerability to due how specially crafted web requests are sanitized, aka "Microsoft SharePoint Elevation of Privilege Vulnerability". This CVE is unique from CVE-2018-0909, CVE-2018-0910. CVE-2018-0911, CVE-2018-0912, CVE-2018-0913 CVE-2018-0914,
nvd
CVE-2018-0912HIGHCVSS 8.8v20132018-03-14
CVE-2018-0912 [HIGH] CVE-2018-0912: Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation
Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation of privilege vulnerability to due how specially crafted web requests are sanitized, aka "Microsoft SharePoint Elevation of Privilege Vulnerability". This CVE is unique from CVE-2018-0909, CVE-2018-0910. CVE-2018-0911, CVE-2018-0913, CVE-2018-0914, CVE-2018-0915,
nvd
CVE-2018-0910HIGHCVSS 8.8v20132018-03-14
CVE-2018-0910 [HIGH] CVE-2018-0910: Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation
Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation of privilege vulnerability to due how specially crafted web requests are sanitized, aka "Microsoft SharePoint Elevation of Privilege Vulnerability". This CVE is unique from CVE-2018-0909, CVE-2018-0911, CVE-2018-0912, CVE-2018-0913, CVE-2018-0914, CVE-2018-0915,
nvd
CVE-2018-0915HIGHCVSS 8.8v20132018-03-14
CVE-2018-0915 [HIGH] CVE-2018-0915: Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation
Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation of privilege vulnerability to due how specially crafted web requests are sanitized, aka "Microsoft SharePoint Elevation of Privilege Vulnerability". This CVE is unique from CVE-2018-0909, CVE-2018-0910. CVE-2018-0911, CVE-2018-0912, CVE-2018-0914, CVE-2018-0916,
nvd
CVE-2018-0913HIGHCVSS 8.8v20132018-03-14
CVE-2018-0913 [HIGH] CVE-2018-0913: Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation
Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation of privilege vulnerability to due how specially crafted web requests are sanitized, aka "Microsoft SharePoint Elevation of Privilege Vulnerability". This CVE is unique from CVE-2018-0909, CVE-2018-0910. CVE-2018-0911, CVE-2018-0913, CVE-2018-0914, CVE-2018-0915,
nvd
CVE-2018-0916HIGHCVSS 8.8v20132018-03-14
CVE-2018-0916 [HIGH] CVE-2018-0916: Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation
Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation of privilege vulnerability to due how specially crafted web requests are sanitized, aka "Microsoft SharePoint Elevation of Privilege Vulnerability". This CVE is unique from CVE-2018-0909, CVE-2018-0910. CVE-2018-0911, CVE-2018-0912, CVE-2018-0913 CVE-2018-0914,
nvd
CVE-2017-11876HIGHCVSS 8.8v20132017-11-15
CVE-2017-11876 [HIGH] CWE-352 CVE-2017-11876: Microsoft Project Server and Microsoft SharePoint Enterprise Server 2016 allow an attacker to use cr
Microsoft Project Server and Microsoft SharePoint Enterprise Server 2016 allow an attacker to use cross-site forgery to read content that they are not authorized to read, use the victim's identity to take actions on the web application on behalf of the victim, such as change permissions and delete content, and inject malicious content in the browser o
nvd
CVE-2017-8551MEDIUMCVSS 6.1v20132017-06-15
CVE-2017-8551 [MEDIUM] CWE-79 CVE-2017-8551: An elevation of privilege vulnerability exists when Microsoft SharePoint software fails to properly
An elevation of privilege vulnerability exists when Microsoft SharePoint software fails to properly sanitize a specially crafted requests, aka "Microsoft SharePoint XSS vulnerability".
nvd
CVE-2017-0281HIGHCVSS 7.8v20132017-05-12
CVE-2017-0281 [HIGH] CVE-2017-0281: Microsoft Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office 2016, Office Online Server 2016,
Microsoft Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office 2016, Office Online Server 2016, Office Web Apps 2010 SP2,Office Web Apps 2013 SP1, Project Server 2013 SP1, SharePoint Enterprise Server 2013 SP1, SharePoint Enterprise Server 2016, SharePoint Foundation 2013 SP1, Sharepoint Server 2010 SP2, Word 2016, and Skype for Business 2016 allow a remot
nvd
CVE-2015-2503CRITICALCVSS 9.3v2010v20132015-11-11
CVE-2015-2503 [CRITICAL] CWE-264 CVE-2015-2503: Microsoft Access 2007 SP3, Excel 2007 SP3, InfoPath 2007 SP3, OneNote 2007 SP3, PowerPoint 2007 SP3,
Microsoft Access 2007 SP3, Excel 2007 SP3, InfoPath 2007 SP3, OneNote 2007 SP3, PowerPoint 2007 SP3, Project 2007 SP3, Publisher 2007 SP3, Visio 2007 SP3, Word 2007 SP3, Office 2007 IME (Japanese) SP3, Access 2010 SP2, Excel 2010 SP2, InfoPath 2010 SP2, OneNote 2010 SP2, PowerPoint 2010 SP2, Project 2010 SP2, Publisher 2010 SP2, Visio 2010 SP2, Word
nvd
1 / 2Next →