Vulnerabilities > Microsoft > Sharepoint Foundation

DATE CVE VULNERABILITY TITLE RISK
2019-06-12 CVE-2019-1036 Cross-site Scripting vulnerability in Microsoft products
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'.
network
low complexity
microsoft CWE-79
5.4
2019-06-12 CVE-2019-1033 Cross-site Scripting vulnerability in Microsoft products
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'.
network
low complexity
microsoft CWE-79
5.4
2019-06-12 CVE-2019-1031 Cross-site Scripting vulnerability in Microsoft products
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'.
network
low complexity
microsoft CWE-79
5.4
2019-05-16 CVE-2019-0963 Cross-site Scripting vulnerability in Microsoft Sharepoint Foundation 2013
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'.
network
low complexity
microsoft CWE-79
5.4
2019-05-16 CVE-2019-0958 Cross-site Scripting vulnerability in Microsoft Sharepoint Foundation and Sharepoint Server
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Elevation of Privilege Vulnerability'.
network
low complexity
microsoft CWE-79
8.8
2019-05-16 CVE-2019-0956 Improper Encoding or Escaping of Output vulnerability in Microsoft products
An information disclosure vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Server Information Disclosure Vulnerability'.
network
low complexity
microsoft CWE-116
6.5
2019-05-16 CVE-2019-0952 Unspecified vulnerability in Microsoft products
A remote code execution vulnerability exists in Microsoft SharePoint Server when it fails to properly identify and filter unsafe ASP.Net web controls, aka 'Microsoft SharePoint Server Remote Code Execution Vulnerability'.
network
low complexity
microsoft
8.8
2019-05-16 CVE-2019-0951 Cross-site Scripting vulnerability in Microsoft Sharepoint Foundation 2010/2013
A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Spoofing Vulnerability'.
network
low complexity
microsoft CWE-79
5.4
2019-05-16 CVE-2019-0950 Cross-site Scripting vulnerability in Microsoft Sharepoint Foundation and Sharepoint Server
A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Spoofing Vulnerability'.
network
low complexity
microsoft CWE-79
5.7
2019-05-16 CVE-2019-0949 Cross-site Scripting vulnerability in Microsoft Sharepoint Foundation and Sharepoint Server
A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Spoofing Vulnerability'.
network
low complexity
microsoft CWE-79
5.7