Vulnerabilities > Microsoft > Sharepoint Foundation

DATE CVE VULNERABILITY TITLE RISK
2020-10-16 CVE-2020-16944 Cross-site Scripting vulnerability in Microsoft products
<p>This vulnerability is caused when SharePoint Server does not properly sanitize a specially crafted request to an affected SharePoint server.</p> <p>An authenticated attacker could exploit this vulnerability by sending a specially crafted request to an affected SharePoint server.
network
low complexity
microsoft CWE-79
8.7
2020-10-16 CVE-2020-16942 Unspecified vulnerability in Microsoft products
<p>An information disclosure vulnerability exists when Microsoft SharePoint Server improperly discloses its folder structure when rendering specific web pages.
local
high complexity
microsoft
4.1
2020-10-16 CVE-2020-16941 Unspecified vulnerability in Microsoft products
<p>An information disclosure vulnerability exists when Microsoft SharePoint Server improperly discloses its folder structure when rendering specific web pages.
local
high complexity
microsoft
4.1
2020-09-11 CVE-2020-1595 Download of Code Without Integrity Check vulnerability in Microsoft products
<p>A remote code execution vulnerability exists in Microsoft SharePoint where APIs aren't properly protected from unsafe data input.
network
low complexity
microsoft CWE-494
critical
9.9
2020-09-11 CVE-2020-1576 Download of Code Without Integrity Check vulnerability in Microsoft products
<p>A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package.
network
high complexity
microsoft CWE-494
8.5
2020-09-11 CVE-2020-1575 Cross-site Scripting vulnerability in Microsoft Sharepoint Foundation 2013
<p>A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server.
network
low complexity
microsoft CWE-79
5.4
2020-09-11 CVE-2020-1514 Cross-site Scripting vulnerability in Microsoft products
<p>A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server.
network
low complexity
microsoft CWE-79
5.4
2020-09-11 CVE-2020-1482 Cross-site Scripting vulnerability in Microsoft products
<p>A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server.
network
low complexity
microsoft CWE-79
6.3
2020-09-11 CVE-2020-1460 Unspecified vulnerability in Microsoft products
<p>A remote code execution vulnerability exists in Microsoft SharePoint Server when it fails to properly identify and filter unsafe ASP.Net web controls.
network
low complexity
microsoft
8.6
2020-09-11 CVE-2020-1453 Download of Code Without Integrity Check vulnerability in Microsoft products
<p>A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package.
network
low complexity
microsoft CWE-494
8.6