cbcvebase.

Microsoft Sharepoint Foundation vulnerabilities

226 known vulnerabilities affecting microsoft/sharepoint_foundation.

Total CVEs
226
CISA KEV
1
actively exploited
Public exploits
12
Exploited in wild
8
Severity breakdown
CRITICAL11HIGH89MEDIUM116LOW10

Vulnerabilities

Page 2 of 12
CVE-2020-0932P2HIGHCVSS 8.8v20132020-04-15
CVE-2020-0932 [HIGH] CVE-2020-0932: A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to chec A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0920, CVE-2020-0929, CVE-2020-0931, CVE-2020-0971, CVE-2020-0974.
nvd
CVE-2020-1439P2HIGHCVSS 8.8v20132020-07-14
CVE-2020-1439 [HIGH] CWE-502 CVE-2020-1439: A remote code execution vulnerability exists in PerformancePoint Services for SharePoint Server when A remote code execution vulnerability exists in PerformancePoint Services for SharePoint Server when the software fails to check the source markup of XML file input, aka 'PerformancePoint Services Remote Code Execution Vulnerability'.
nvd
CVE-2018-8284P2HIGHCVSS 8.1v2010-sp2v2013-sp12018-07-11
CVE-2018-8284 [HIGH] CWE-94 CVE-2018-8284: A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate inp A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka ".NET Framework Remote Code Injection Vulnerability." This affects Microsoft .NET Framework 2.0, Microsoft .NET Framework 3.0, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.5.2, Microsoft .NET Framework 4.6, Mi
nvd
CVE-2013-1330P2CRITICALCVSS 10.0v20102013-09-11
CVE-2013-1330 [CRITICAL] CWE-20 CVE-2013-1330: The default configuration of Microsoft SharePoint Portal Server 2003 SP3, SharePoint Server 2007 SP3 The default configuration of Microsoft SharePoint Portal Server 2003 SP3, SharePoint Server 2007 SP3 and 2010 SP1 and SP2, and Office Web Apps 2010 does not set the EnableViewStateMac attribute, which allows remote attackers to execute arbitrary code by leveraging an unassigned workflow, aka "MAC Disabled Vulnerability."
nvd
CVE-2011-1892P3MEDIUMCVSS 4.0PoCv20102011-09-15
CVE-2011-1892 [MEDIUM] CWE-200 CVE-2011-1892: Microsoft Office Groove 2007 SP2, SharePoint Workspace 2010 Gold and SP1, Office Forms Server 2007 S Microsoft Office Groove 2007 SP2, SharePoint Workspace 2010 Gold and SP1, Office Forms Server 2007 SP2, Office SharePoint Server 2007 SP2, Office SharePoint Server 2010 Gold and SP1, Office Groove Data Bridge Server 2007 SP2, Office Groove Management Server 2007 SP2, Groove Server 2010 Gold and SP1, Windows SharePoint Services 3.0 SP2, SharePoint Foun
nvd
CVE-2022-29108P2HIGHCVSS 8.8v20132022-05-10
CVE-2022-29108 [HIGH] CVE-2022-29108: Microsoft SharePoint Server Remote Code Execution Vulnerability Microsoft SharePoint Server Remote Code Execution Vulnerability
nvd
CVE-2020-1025P2CRITICALCVSS 9.8v20132020-07-14
CVE-2020-1025 [CRITICAL] CWE-20 CVE-2020-1025: An elevation of privilege vulnerability exists when Microsoft SharePoint Server and Skype for Busine An elevation of privilege vulnerability exists when Microsoft SharePoint Server and Skype for Business Server improperly handle OAuth token validation. An attacker who successfully exploited the vulnerability could bypass authentication and achieve improper access. To exploit this vulnerability, an attacker would need to modify the token. The update
nvd
CVE-2015-1682P2CRITICALCVSS 9.3v2010v20132015-05-13
CVE-2015-1682 [CRITICAL] CWE-119 CVE-2015-1682: Microsoft Office 2010 SP2, Excel 2010 SP2, PowerPoint 2010 SP2, Word 2010 SP2, Office 2013 SP1, Exce Microsoft Office 2010 SP2, Excel 2010 SP2, PowerPoint 2010 SP2, Word 2010 SP2, Office 2013 SP1, Excel 2013 SP1, PowerPoint 2013 SP1, Word 2013 SP1, Office 2013 RT SP1, Excel 2013 RT SP1, PowerPoint 2013 RT SP1, Word 2013 RT SP1, Office for Mac 2011, Excel for Mac 2011, PowerPoint for Mac 2011, Word for Mac 2011, PowerPoint Viewer, Word Automation Se
nvd
CVE-2015-0085P2CRITICALCVSS 9.3v2010v20132015-03-11
CVE-2015-0085 [CRITICAL] CVE-2015-0085: Use-after-free vulnerability in Microsoft Office 2007 SP3, Excel 2007 SP3, PowerPoint 2007 SP3, Word Use-after-free vulnerability in Microsoft Office 2007 SP3, Excel 2007 SP3, PowerPoint 2007 SP3, Word 2007 SP3, Office 2010 SP2, Excel 2010 SP2, PowerPoint 2010 SP2, Word 2010 SP2, Office 2013 Gold and SP1, Word 2013 Gold and SP1, Office 2013 RT Gold and SP1, Word 2013 RT Gold and SP1, Excel Viewer, Office Compatibility Pack SP3, Word Automation Services on
nvd
CVE-2020-17118P2CRITICALCVSS 9.8v2010v20132020-12-10
CVE-2020-17118 [CRITICAL] CVE-2020-17118: Microsoft SharePoint Remote Code Execution Vulnerability Microsoft SharePoint Remote Code Execution Vulnerability
nvd
CVE-2020-1069P2HIGHCVSS 8.8v20132020-05-21
CVE-2020-1069 [HIGH] CWE-476 CVE-2020-1069: A remote code execution vulnerability exists in Microsoft SharePoint Server when it fails to properl A remote code execution vulnerability exists in Microsoft SharePoint Server when it fails to properly identify and filter unsafe ASP.Net web controls, aka 'Microsoft SharePoint Server Remote Code Execution Vulnerability'.
nvd
CVE-2019-0952P2HIGHCVSS 8.8v20132019-05-16
CVE-2019-0952 [HIGH] CVE-2019-0952: A remote code execution vulnerability exists in Microsoft SharePoint Server when it fails to properl A remote code execution vulnerability exists in Microsoft SharePoint Server when it fails to properly identify and filter unsafe ASP.Net web controls, aka 'Microsoft SharePoint Server Remote Code Execution Vulnerability'.
nvd
CVE-2020-0971P2HIGHCVSS 8.8v2010v20132020-04-15
CVE-2020-0971 [HIGH] CVE-2020-0971: A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to chec A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0920, CVE-2020-0929, CVE-2020-0931, CVE-2020-0932, CVE-2020-0974.
nvd
CVE-2013-1315P3CRITICALCVSS 9.3v20102013-09-11
CVE-2013-1315 [CRITICAL] CWE-119 CVE-2013-1315: Microsoft SharePoint Server 2007 SP3, 2010 SP1 and SP2, and 2013; Office Web Apps 2010; Excel 2003 S Microsoft SharePoint Server 2007 SP3, 2010 SP1 and SP2, and 2013; Office Web Apps 2010; Excel 2003 SP3, 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT; Office for Mac 2011; Excel Viewer; and Office Compatibility Pack SP3 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, ak
nvd
CVE-2019-0594P2HIGHCVSS 8.8v20132019-03-05
CVE-2019-0594 [HIGH] CWE-20 CVE-2019-0594: A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to chec A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0604.
nvd
CVE-2021-41344P3HIGHCVSS 8.8v20132021-10-13
CVE-2021-41344 [HIGH] CVE-2021-41344: Microsoft SharePoint Server Remote Code Execution Vulnerability Microsoft SharePoint Server Remote Code Execution Vulnerability
nvd
CVE-2021-24066P2HIGHCVSS 8.8v2010v20132021-02-25
CVE-2021-24066 [HIGH] CWE-502 CVE-2021-24066: Microsoft SharePoint Remote Code Execution Vulnerability Microsoft SharePoint Remote Code Execution Vulnerability
nvd
CVE-2019-1257P3HIGHCVSS 8.8v2010v20132019-09-11
CVE-2019-1257 [HIGH] CWE-20 CVE-2019-1257: A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to chec A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1295, CVE-2019-1296.
nvd
CVE-2020-0929P2HIGHCVSS 8.8v2010v20132020-04-15
CVE-2020-0929 [HIGH] CVE-2020-0929: A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to chec A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0920, CVE-2020-0931, CVE-2020-0932, CVE-2020-0971, CVE-2020-0974.
nvd
CVE-2020-0931P2HIGHCVSS 8.8v20132020-04-15
CVE-2020-0931 [HIGH] CVE-2020-0931: A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to chec A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0920, CVE-2020-0929, CVE-2020-0932, CVE-2020-0971, CVE-2020-0974.
nvd
Microsoft Sharepoint Foundation vulnerabilities | cvebase