cbcvebase.

Microsoft Sharepoint Foundation vulnerabilities

226 known vulnerabilities affecting microsoft/sharepoint_foundation.

Total CVEs
226
CISA KEV
1
actively exploited
Public exploits
12
Exploited in wild
8
Severity breakdown
CRITICAL11HIGH89MEDIUM116LOW10

Vulnerabilities

Page 7 of 12
CVE-2021-24071P3MEDIUMCVSS 6.5v2010v20132021-02-25
CVE-2021-24071 [MEDIUM] CVE-2021-24071: Microsoft SharePoint Information Disclosure Vulnerability Microsoft SharePoint Information Disclosure Vulnerability
nvd
CVE-2021-31173P3MEDIUMCVSS 6.5v20132021-05-11
CVE-2021-31173 [MEDIUM] CWE-200 CVE-2021-31173: Microsoft SharePoint Server Information Disclosure Vulnerability Microsoft SharePoint Server Information Disclosure Vulnerability
nvd
CVE-2020-1103P4MEDIUMCVSS 6.5v20132020-05-21
CVE-2020-1103 [MEDIUM] CWE-352 CVE-2020-1103: An information disclosure vulnerability exists where certain modes of the search function in Microso An information disclosure vulnerability exists where certain modes of the search function in Microsoft SharePoint Server are vulnerable to cross-site search attacks (a variant of cross-site request forgery, CSRF).When users are simultaneously logged in to Microsoft SharePoint Server and visit a malicious web page, the attacker can, through standard br
nvd
CVE-2021-26418P4HIGHCVSS 7.1v20132021-05-11
CVE-2021-26418 [HIGH] CWE-290 CVE-2021-26418: Microsoft SharePoint Server Spoofing Vulnerability Microsoft SharePoint Server Spoofing Vulnerability
nvd
CVE-2020-17015P4MEDIUMCVSS 6.5v20132020-11-11
CVE-2020-17015 [MEDIUM] CVE-2020-17015: Microsoft SharePoint Server Spoofing Vulnerability Microsoft SharePoint Server Spoofing Vulnerability
nvd
CVE-2015-6117P4MEDIUMCVSS 6.1v20132016-01-13
CVE-2015-6117 [MEDIUM] CWE-79 CVE-2015-6117: Microsoft SharePoint Server 2013 SP1 and SharePoint Foundation 2013 SP1 allow remote authenticated u Microsoft SharePoint Server 2013 SP1 and SharePoint Foundation 2013 SP1 allow remote authenticated users to bypass intended Access Control Policy restrictions and conduct cross-site scripting (XSS) attacks by modifying a webpart, aka "Microsoft SharePoint Security Feature Bypass," a different vulnerability than CVE-2016-0011.
nvd
CVE-2016-0039P4MEDIUMCVSS 6.1v20132016-02-10
CVE-2016-0039 [MEDIUM] CWE-79 CVE-2016-0039: Cross-site scripting (XSS) vulnerability in SharePoint Server in Microsoft SharePoint Foundation 201 Cross-site scripting (XSS) vulnerability in SharePoint Server in Microsoft SharePoint Foundation 2013 SP1 allows remote attackers to inject arbitrary web script or HTML via a crafted request, aka "Microsoft SharePoint XSS Vulnerability."
nvd
CVE-2020-1499P4MEDIUMCVSS 5.4v2010v20132020-08-17
CVE-2020-1499 [MEDIUM] CVE-2020-1499: A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specia A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially crafted request to an affected SharePoint server. The attacker who successfully exploited the vulnerability could then per
nvd
CVE-2020-1501P4MEDIUMCVSS 5.4v20132020-08-17
CVE-2020-1501 [MEDIUM] CVE-2020-1501: A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specia A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially crafted request to an affected SharePoint server. The attacker who successfully exploited the vulnerability could then per
nvd
CVE-2017-0107P4MEDIUMCVSS 6.1v20132017-03-17
CVE-2017-0107 [MEDIUM] CWE-79 CVE-2017-0107: Microsoft SharePoint Server fails to sanitize crafted web requests, allowing remote attackers to run Microsoft SharePoint Server fails to sanitize crafted web requests, allowing remote attackers to run cross-script in local security context, aka "Microsoft SharePoint XSS Vulnerability."
nvd
CVE-2020-1443P4MEDIUMCVSS 5.4v20132020-07-14
CVE-2020-1443 [MEDIUM] CVE-2020-1443: A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specia A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Spoofing Vulnerability'.
nvd
CVE-2020-1444P4MEDIUMCVSS 4.3v20132020-07-14
CVE-2020-1444 [MEDIUM] CVE-2020-1444: A remote code execution vulnerability exists in the way Microsoft SharePoint software parses special A remote code execution vulnerability exists in the way Microsoft SharePoint software parses specially crafted email messages, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'.
nvd
CVE-2012-1859P4MEDIUMCVSS 4.3v20102012-07-10
CVE-2012-1859 [MEDIUM] CWE-79 CVE-2012-1859: Cross-site scripting (XSS) vulnerability in scriptresx.ashx in Microsoft SharePoint Server 2010 Gold Cross-site scripting (XSS) vulnerability in scriptresx.ashx in Microsoft SharePoint Server 2010 Gold and SP1, SharePoint Foundation 2010 Gold and SP1, and Office Web Apps 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via crafted JavaScript elements in a URL, aka "XSS scriptresx.ashx Vulnerability."
nvd
CVE-2016-0011P4MEDIUMCVSS 5.4v20132016-01-13
CVE-2016-0011 [MEDIUM] CVE-2016-0011: Microsoft SharePoint Server 2013 SP1 and SharePoint Foundation 2013 SP1 allow remote authenticated u Microsoft SharePoint Server 2013 SP1 and SharePoint Foundation 2013 SP1 allow remote authenticated users to bypass intended Access Control Policy restrictions and conduct cross-site scripting (XSS) attacks by modifying a webpart, aka "Microsoft SharePoint Security Feature Bypass," a different vulnerability than CVE-2015-6117.
nvd
CVE-2020-1345P4MEDIUMCVSS 6.1v2010v20132020-09-11
CVE-2020-1345 [MEDIUM] CWE-79 CVE-2020-1345: <p>A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not prope A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially crafted request to an affected SharePoint server. The attacker who successfully exploited the vul
nvd
CVE-2020-1198P4MEDIUMCVSS 6.1v2010v20132020-09-11
CVE-2020-1198 [MEDIUM] CWE-79 CVE-2020-1198: <p>A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not prope A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially crafted request to an affected SharePoint server. The attacker who successfully exploited the vul
nvd
CVE-2020-1482P4MEDIUMCVSS 6.1v2010v20132020-09-11
CVE-2020-1482 [MEDIUM] CWE-79 CVE-2020-1482: <p>A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not prope A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially crafted request to an affected SharePoint server. The attacker who successfully exploited the vul
nvd
CVE-2019-0950P4MEDIUMCVSS 5.7v20132019-05-16
CVE-2019-0950 [MEDIUM] CVE-2019-0950: A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specia A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-0949, CVE-2019-0951.
nvd
CVE-2019-0949P4MEDIUMCVSS 5.7v20132019-05-16
CVE-2019-0949 [MEDIUM] CWE-79 CVE-2019-0949: A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specia A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-0950, CVE-2019-0951.
nvd
CVE-2022-24472P4MEDIUMCVSS 5.7v20132022-04-15
CVE-2022-24472 [MEDIUM] CVE-2022-24472: Microsoft SharePoint Server Spoofing Vulnerability Microsoft SharePoint Server Spoofing Vulnerability
nvd
Microsoft Sharepoint Foundation vulnerabilities | cvebase