cbcvebase.

Microsoft Sharepoint Enterprise Server vulnerabilities

256 known vulnerabilities affecting microsoft/sharepoint_enterprise_server.

Total CVEs
256
CISA KEV
5
actively exploited
Public exploits
9
Exploited in wild
8
Severity breakdown
CRITICAL3HIGH120MEDIUM129LOW4

Vulnerabilities

Page 3 of 13
CVE-2020-0920P2HIGHCVSS 8.8v20162020-04-15
CVE-2020-0920 [HIGH] CWE-434 CVE-2020-0920: A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to chec A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0929, CVE-2020-0931, CVE-2020-0932, CVE-2020-0971, CVE-2020-0974.
nvd
CVE-2020-1023P3HIGHCVSS 8.8v20162020-05-21
CVE-2020-1023 [HIGH] CWE-434 CVE-2020-1023: A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to chec A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1024, CVE-2020-1102.
nvd
CVE-2020-1024P3HIGHCVSS 8.8v20162020-05-21
CVE-2020-1024 [HIGH] CVE-2020-1024: A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to chec A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1023, CVE-2020-1102.
nvd
CVE-2020-1460P3HIGHCVSS 8.8v2013v20162020-09-11
CVE-2020-1460 [HIGH] CVE-2020-1460: <p>A remote code execution vulnerability exists in Microsoft SharePoint Server when it fails to prop A remote code execution vulnerability exists in Microsoft SharePoint Server when it fails to properly identify and filter unsafe ASP.Net web controls. An authenticated attacker who successfully exploited the vulnerability could use a specially crafted page to perform actions in the security context of the SharePoint application pool process. To exploit the vuln
nvd
CVE-2021-1707P3HIGHCVSS 8.8v20162021-01-12
CVE-2021-1707 [HIGH] CVE-2021-1707: Microsoft SharePoint Server Remote Code Execution Vulnerability Microsoft SharePoint Server Remote Code Execution Vulnerability
nvd
CVE-2021-26420P3HIGHCVSS 8.8v20162021-06-08
CVE-2021-26420 [HIGH] CVE-2021-26420: Microsoft SharePoint Server Remote Code Execution Vulnerability Microsoft SharePoint Server Remote Code Execution Vulnerability
nvd
CVE-2019-1295P3HIGHCVSS 8.8v20162019-09-11
CVE-2019-1295 [HIGH] CVE-2019-1295: A remote code execution vulnerability exists in Microsoft SharePoint where APIs aren't properly prot A remote code execution vulnerability exists in Microsoft SharePoint where APIs aren't properly protected from unsafe data input, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1257, CVE-2019-1296.
nvd
CVE-2019-1296P3HIGHCVSS 8.8v20162019-09-11
CVE-2019-1296 [HIGH] CVE-2019-1296: A remote code execution vulnerability exists in Microsoft SharePoint where APIs aren't properly prot A remote code execution vulnerability exists in Microsoft SharePoint where APIs aren't properly protected from unsafe data input, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1257, CVE-2019-1295.
nvd
CVE-2020-1595P3HIGHCVSS 8.8v2013v20162020-09-11
CVE-2020-1595 [HIGH] CWE-494 CVE-2020-1595: <p>A remote code execution vulnerability exists in Microsoft SharePoint where APIs aren't properly p A remote code execution vulnerability exists in Microsoft SharePoint where APIs aren't properly protected from unsafe data input. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the SharePoint application pool and the SharePoint server farm account. Exploitation of this vulnerability requires that a us
nvd
CVE-2022-44693P3HIGHCVSS 8.8v2013v20162022-12-13
CVE-2022-44693 [HIGH] CVE-2022-44693: Microsoft SharePoint Server Remote Code Execution Vulnerability Microsoft SharePoint Server Remote Code Execution Vulnerability
nvd
CVE-2018-8635P3HIGHCVSS 8.8v2013-sp1v20162018-12-12
CVE-2018-8635 [HIGH] CWE-20 CVE-2018-8635: An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sa An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted authentication request to an affected SharePoint server, aka "Microsoft SharePoint Server Elevation of Privilege Vulnerability." This affects Microsoft SharePoint Server, Microsoft SharePoint.
nvd
CVE-2021-42309P3HIGHCVSS 8.8v20162021-12-15
CVE-2021-42309 [HIGH] CWE-94 CVE-2021-42309: Microsoft SharePoint Server Remote Code Execution Vulnerability Microsoft SharePoint Server Remote Code Execution Vulnerability
nvd
CVE-2021-24072P3HIGHCVSS 8.8v20162021-02-25
CVE-2021-24072 [HIGH] CVE-2021-24072: Microsoft SharePoint Server Remote Code Execution Vulnerability Microsoft SharePoint Server Remote Code Execution Vulnerability
nvd
CVE-2022-38009P3HIGHCVSS 8.8v2013v20162022-09-13
CVE-2022-38009 [HIGH] CVE-2022-38009: Microsoft SharePoint Server Remote Code Execution Vulnerability Microsoft SharePoint Server Remote Code Execution Vulnerability
nvd
CVE-2020-1446P3HIGHCVSS 8.8v2013v20162020-07-14
CVE-2020-1446 [HIGH] CVE-2020-1446: A remote code execution vulnerability exists in Microsoft Word software when it fails to properly ha A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1447, CVE-2020-1448.
nvd
CVE-2017-0003P3HIGHCVSS 7.8v20162017-01-10
CVE-2017-0003 [HIGH] CWE-119 CVE-2017-0003: Microsoft Word 2016 and SharePoint Enterprise Server 2016 allow remote attackers to execute arbitrar Microsoft Word 2016 and SharePoint Enterprise Server 2016 allow remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability."
nvd
CVE-2022-38008P3HIGHCVSS 8.8v2013v20162022-09-13
CVE-2022-38008 [HIGH] CVE-2022-38008: Microsoft SharePoint Server Remote Code Execution Vulnerability Microsoft SharePoint Server Remote Code Execution Vulnerability
nvd
CVE-2022-41062P3HIGHCVSS 8.8v2013v20162022-11-09
CVE-2022-41062 [HIGH] CVE-2022-41062: Microsoft SharePoint Server Remote Code Execution Vulnerability Microsoft SharePoint Server Remote Code Execution Vulnerability
nvd
CVE-2020-1447P3HIGHCVSS 8.8v2013v20162020-07-14
CVE-2020-1447 [HIGH] CVE-2020-1447: A remote code execution vulnerability exists in Microsoft Word software when it fails to properly ha A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1446, CVE-2020-1448.
nvd
CVE-2020-1448P3HIGHCVSS 8.8v20162020-07-14
CVE-2020-1448 [HIGH] CVE-2020-1448: A remote code execution vulnerability exists in Microsoft Word software when it fails to properly ha A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1446, CVE-2020-1447.
nvd
Microsoft Sharepoint Enterprise Server vulnerabilities | cvebase