Microsoft Sharepoint Enterprise Server vulnerabilities
256 known vulnerabilities affecting microsoft/sharepoint_enterprise_server.
Total CVEs
256
CISA KEV
5
actively exploited
Public exploits
9
Exploited in wild
8
Severity breakdown
CRITICAL3HIGH120MEDIUM129LOW4
Vulnerabilities
Page 13 of 13
CVE-2020-1177P4MEDIUMCVSS 5.4v20162020-06-09
CVE-2020-1177 [MEDIUM] CWE-79 CVE-2020-1177: A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE-2020-1183, CVE-2020-1297, CVE-2020-1298, CVE-2020-1318, CVE-2020-1320.
nvd
CVE-2020-1297P4MEDIUMCVSS 5.4v20162020-06-09
CVE-2020-1297 [MEDIUM] CVE-2020-1297: A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE-2020-1177, CVE-2020-1183, CVE-2020-1298, CVE-2020-1318, CVE-2020-1320.
nvd
CVE-2020-0893P4MEDIUMCVSS 5.4v2013v20162020-03-12
CVE-2020-0893 [MEDIUM] CWE-79 CVE-2020-0893: A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE-2020-0894.
nvd
CVE-2020-0894P4MEDIUMCVSS 5.4v20162020-03-12
CVE-2020-0894 [MEDIUM] CVE-2020-0894: A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE-2020-0893.
nvd
CVE-2020-16941P4MEDIUMCVSS 5.5v20162020-10-16
CVE-2020-16941 [MEDIUM] CVE-2020-16941: <p>An information disclosure vulnerability exists when Microsoft SharePoint Server improperly disclo
An information disclosure vulnerability exists when Microsoft SharePoint Server improperly discloses its folder structure when rendering specific web pages. An attacker who took advantage of this information disclosure could view the folder path of scripts loaded on the page.
To take advantage of the vulnerability, an attacker would require access to the sp
nvd
CVE-2022-21968P4MEDIUMCVSS 4.3v20162022-02-09
CVE-2022-21968 [MEDIUM] CVE-2022-21968: Microsoft SharePoint Server Security Feature Bypass Vulnerability
Microsoft SharePoint Server Security Feature Bypass Vulnerability
nvd
CVE-2018-8578P4MEDIUMCVSS 4.3v2013-sp12018-11-14
CVE-2018-8578 [MEDIUM] CVE-2018-8578: An information disclosure vulnerability exists when Microsoft SharePoint Server improperly discloses
An information disclosure vulnerability exists when Microsoft SharePoint Server improperly discloses its folder structure when rendering specific web pages, aka "Microsoft SharePoint Information Disclosure Vulnerability." This affects Microsoft SharePoint.
nvd
CVE-2021-36940P4MEDIUMCVSS 4.3v2013v20162021-08-12
CVE-2021-36940 [MEDIUM] CVE-2021-36940: Microsoft SharePoint Server Spoofing Vulnerability
Microsoft SharePoint Server Spoofing Vulnerability
nvd
CVE-2022-41103P4MEDIUMCVSS 5.5v2013v20162022-11-09
CVE-2022-41103 [MEDIUM] CVE-2022-41103: Microsoft Word Information Disclosure Vulnerability
Microsoft Word Information Disclosure Vulnerability
nvd
CVE-2022-41060P4MEDIUMCVSS 5.5v2013v20162022-11-09
CVE-2022-41060 [MEDIUM] CVE-2022-41060: Microsoft Word Information Disclosure Vulnerability
Microsoft Word Information Disclosure Vulnerability
nvd
CVE-2018-0919P4LOWCVSS 3.3v2013v20162018-03-14
CVE-2018-0919 [LOW] CWE-125 CVE-2018-0919: Microsoft Office 2010 SP2, 2013 SP1, and 2016, Microsoft Office 2016 Click-to-Run Microsoft Office 2
Microsoft Office 2010 SP2, 2013 SP1, and 2016, Microsoft Office 2016 Click-to-Run Microsoft Office 2016 for Mac, Microsoft Office Web Apps 2010 SP2, Microsoft Office Web Apps 2013 SP1, Microsoft SharePoint Enterprise Server 2013 SP1, Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2010 SP2, Microsoft Word 2010 SP2, Word 2013 SP1
nvd
CVE-2019-1202P4MEDIUMCVSS 4.4v20162019-08-14
CVE-2019-1202 [MEDIUM] CWE-200 CVE-2019-1202: An information disclosure vulnerability exists in the way Microsoft SharePoint handles session objec
An information disclosure vulnerability exists in the way Microsoft SharePoint handles session objects. An authenticated attacker who successfully exploited the vulnerability could hijack the session of another user.
To exploit this vulnerability, the attacker could run a specially crafted application.
The security update corrects how SharePoint handl
nvd
CVE-2020-16942P4MEDIUMCVSS 4.4v20162020-10-16
CVE-2020-16942 [MEDIUM] CVE-2020-16942: <p>An information disclosure vulnerability exists when Microsoft SharePoint Server improperly disclo
An information disclosure vulnerability exists when Microsoft SharePoint Server improperly discloses its folder structure when rendering specific web pages. An attacker who took advantage of this information disclosure could view the folder path of scripts loaded on the page.
To take advantage of the vulnerability, an attacker would require access to the sp
nvd
CVE-2021-40484P4LOWCVSS 3.5v20162021-10-13
CVE-2021-40484 [LOW] CVE-2021-40484: Microsoft SharePoint Server Spoofing Vulnerability
Microsoft SharePoint Server Spoofing Vulnerability
nvd
CVE-2021-38652P4LOWCVSS 3.5v20162021-09-15
CVE-2021-38652 [LOW] CVE-2021-38652: Microsoft SharePoint Server Spoofing Vulnerability
Microsoft SharePoint Server Spoofing Vulnerability
nvd
CVE-2021-38651P4LOWCVSS 3.5v20162021-09-15
CVE-2021-38651 [LOW] CVE-2021-38651: Microsoft SharePoint Server Spoofing Vulnerability
Microsoft SharePoint Server Spoofing Vulnerability
nvd
← Previous13 / 13