cbcvebase.

Microsoft Sharepoint Foundation vulnerabilities

226 known vulnerabilities affecting microsoft/sharepoint_foundation.

Total CVEs
226
CISA KEV
1
actively exploited
Public exploits
12
Exploited in wild
8
Severity breakdown
CRITICAL11HIGH89MEDIUM116LOW10

Vulnerabilities

Page 5 of 12
CVE-2014-2816P3CRITICALCVSS 9.3v20132014-08-12
CVE-2014-2816 [CRITICAL] CWE-264 CVE-2014-2816: Microsoft SharePoint Server 2013 Gold and SP1 and SharePoint Foundation 2013 Gold and SP1 allow remo Microsoft SharePoint Server 2013 Gold and SP1 and SharePoint Foundation 2013 Gold and SP1 allow remote authenticated users to gain privileges via a Trojan horse app that executes a custom action in the context of the SharePoint extensibility model, aka "SharePoint Page Content Vulnerability."
nvd
CVE-2019-0958P3HIGHCVSS 8.8v20132019-05-16
CVE-2019-0958 [HIGH] CVE-2019-0958: An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sa An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0957.
nvd
CVE-2019-1006P3HIGHCVSS 7.5v2010v20132019-07-15
CVE-2019-1006 [HIGH] CWE-295 CVE-2019-1006: An authentication bypass vulnerability exists in Windows Communication Foundation (WCF) and Windows An authentication bypass vulnerability exists in Windows Communication Foundation (WCF) and Windows Identity Foundation (WIF), allowing signing of SAML tokens with arbitrary symmetric keys, aka 'WCF/WIF SAML Token Authentication Bypass Vulnerability'.
nvd
CVE-2013-3179P4MEDIUMCVSS 4.3PoCv20102013-09-11
CVE-2013-3179 [MEDIUM] CWE-79 CVE-2013-3179: Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2007 SP3, 2010 SP1 and SP2, Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2007 SP3, 2010 SP1 and SP2, and 2013 allows remote attackers to inject arbitrary web script or HTML via a crafted request, aka "SharePoint XSS Vulnerability."
nvd
CVE-2023-21717P3HIGHCVSS 8.8v20132023-02-14
CVE-2023-21717 [HIGH] CWE-284 CVE-2023-21717: Microsoft SharePoint Server Elevation of Privilege Vulnerability Microsoft SharePoint Server Elevation of Privilege Vulnerability
nvd
CVE-2017-0281P3HIGHCVSS 7.8v20132017-05-12
CVE-2017-0281 [HIGH] CVE-2017-0281: Microsoft Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office 2016, Office Online Server 2016, Microsoft Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office 2016, Office Online Server 2016, Office Web Apps 2010 SP2,Office Web Apps 2013 SP1, Project Server 2013 SP1, SharePoint Enterprise Server 2013 SP1, SharePoint Enterprise Server 2016, SharePoint Foundation 2013 SP1, Sharepoint Server 2010 SP2, Word 2016, and Skype for Business 2016 allow a remot
nvd
CVE-2013-0080P3HIGHCVSS 7.5v20102013-03-13
CVE-2013-0080 [HIGH] CWE-264 CVE-2013-0080: Microsoft SharePoint Server 2010 SP1 and SharePoint Foundation 2010 SP1 allow remote attackers to by Microsoft SharePoint Server 2010 SP1 and SharePoint Foundation 2010 SP1 allow remote attackers to bypass intended read restrictions for content, and hijack user accounts, via a crafted URL, aka "Callback Function Vulnerability."
nvd
CVE-2010-3324P4MEDIUMCVSS 4.3PoCv20102010-09-17
CVE-2010-3324 [MEDIUM] CVE-2010-3324: The toStaticHTML function in Microsoft Internet Explorer 8, and the SafeHTML function in Microsoft W The toStaticHTML function in Microsoft Internet Explorer 8, and the SafeHTML function in Microsoft Windows SharePoint Services 3.0 SP2, SharePoint Foundation 2010, Office SharePoint Server 2007 SP2, Groove Server 2010, and Office Web Apps, allows remote attackers to bypass the cross-site scripting (XSS) protection mechanism and conduct XSS attacks via a craft
nvd
CVE-2013-0081P3MEDIUMCVSS 5.0v2010v20132013-09-11
CVE-2013-0081 [MEDIUM] CWE-20 CVE-2013-0081: Microsoft SharePoint Portal Server 2003 SP3 and SharePoint Server 2007 SP3, 2010 SP1 and SP2, and 20 Microsoft SharePoint Portal Server 2003 SP3 and SharePoint Server 2007 SP3, 2010 SP1 and SP2, and 2013 do not properly process unassigned workflows, which allows remote attackers to cause a denial of service (W3WP process hang) via a crafted URL, aka "SharePoint Denial of Service Vulnerability."
nvd
CVE-2021-31966P3HIGHCVSS 7.2v20132021-06-08
CVE-2021-31966 [HIGH] CVE-2021-31966: Microsoft SharePoint Server Remote Code Execution Vulnerability Microsoft SharePoint Server Remote Code Execution Vulnerability
nvd
CVE-2020-0892P3HIGHCVSS 7.8v20132020-03-12
CVE-2020-0892 [HIGH] CVE-2020-0892: A remote code execution vulnerability exists in Microsoft Word software when it fails to properly ha A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0850, CVE-2020-0851, CVE-2020-0852, CVE-2020-0855.
nvd
CVE-2020-17016P3HIGHCVSS 8.8v20102020-11-11
CVE-2020-17016 [HIGH] CVE-2020-17016: Microsoft SharePoint Server Spoofing Vulnerability Microsoft SharePoint Server Spoofing Vulnerability
nvd
CVE-2021-42294P3HIGHCVSS 7.2v20132021-12-15
CVE-2021-42294 [HIGH] CVE-2021-42294: Microsoft SharePoint Server Remote Code Execution Vulnerability Microsoft SharePoint Server Remote Code Execution Vulnerability
nvd
CVE-2021-31964P3HIGHCVSS 8.1v20132021-06-08
CVE-2021-31964 [HIGH] CVE-2021-31964: Microsoft SharePoint Server Spoofing Vulnerability Microsoft SharePoint Server Spoofing Vulnerability
nvd
CVE-2021-31948P3HIGHCVSS 8.1v20132021-06-08
CVE-2021-31948 [HIGH] CVE-2021-31948: Microsoft SharePoint Server Spoofing Vulnerability Microsoft SharePoint Server Spoofing Vulnerability
nvd
CVE-2020-17115P3HIGHCVSS 8.0v2010v20132020-12-10
CVE-2020-17115 [HIGH] CVE-2020-17115: Microsoft SharePoint Server Spoofing Vulnerability Microsoft SharePoint Server Spoofing Vulnerability
nvd
CVE-2020-17089P3HIGHCVSS 8.0v2010v20132020-12-10
CVE-2020-17089 [HIGH] CVE-2020-17089: Microsoft SharePoint Elevation of Privilege Vulnerability Microsoft SharePoint Elevation of Privilege Vulnerability
nvd
CVE-2013-3180P4MEDIUMCVSS 4.3v20102013-09-11
CVE-2013-3180 [MEDIUM] CWE-79 CVE-2013-3180: Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2010 SP1 and SP2 and 2013 al Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2010 SP1 and SP2 and 2013 allows remote attackers to inject arbitrary web script or HTML via a crafted POST request, aka "POST XSS Vulnerability."
nvd
CVE-2021-1712P3HIGHCVSS 8.0v20132021-01-12
CVE-2021-1712 [HIGH] CWE-269 CVE-2021-1712: Microsoft SharePoint Elevation of Privilege Vulnerability Microsoft SharePoint Elevation of Privilege Vulnerability
nvd
CVE-2022-21987P3HIGHCVSS 8.0v20132022-02-09
CVE-2022-21987 [HIGH] CVE-2022-21987: Microsoft SharePoint Server Spoofing Vulnerability Microsoft SharePoint Server Spoofing Vulnerability
nvd
Microsoft Sharepoint Foundation vulnerabilities | cvebase