Vulnerabilities > Microsoft > Sharepoint Enterprise Server > 2013

DATE CVE VULNERABILITY TITLE RISK
2017-10-13 CVE-2017-11775 Cross-site Scripting vulnerability in Microsoft Sharepoint Enterprise Server 2013/2016
Microsoft SharePoint Enterprise Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an attacker to exploit a cross-site scripting (XSS) vulnerability by sending a specially crafted request to an affected SharePoint server, due to how SharePoint Server sanitizes web requests, aka "Microsoft Office SharePoint XSS Vulnerability".
network
microsoft CWE-79
3.5
2017-06-15 CVE-2017-8512 Remote Code Execution vulnerability in Microsoft Office
A remote code execution vulnerability exists in Microsoft Office when the software fails to properly handle objects in memory, aka "Office Remote Code Execution Vulnerability".
network
microsoft
critical
9.3