Vulnerabilities > Microsoft > Sharepoint Server > Medium

DATE CVE VULNERABILITY TITLE RISK
2018-06-14 CVE-2018-8252 Cross-site Scripting vulnerability in Microsoft Sharepoint Foundation and Sharepoint Server
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft SharePoint.
network
low complexity
microsoft CWE-79
5.4
2018-05-09 CVE-2018-8168 Cross-site Scripting vulnerability in Microsoft Sharepoint Server 2010/2013
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft SharePoint Server, Microsoft SharePoint.
network
low complexity
microsoft CWE-79
5.4
2018-05-09 CVE-2018-8160 Information Exposure vulnerability in Microsoft products
An information disclosure vulnerability exists in Outlook when a message is opened, aka "Microsoft Outlook Information Disclosure Vulnerability." This affects Word, Microsoft Office.
network
low complexity
microsoft CWE-200
6.5
2018-05-09 CVE-2018-8156 Cross-site Scripting vulnerability in Microsoft Project Server and Sharepoint Server
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft SharePoint, Microsoft Project Server.
network
low complexity
microsoft CWE-79
5.4
2018-05-09 CVE-2018-8155 Cross-site Scripting vulnerability in Microsoft Sharepoint Foundation and Sharepoint Server
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft SharePoint.
network
low complexity
microsoft CWE-79
5.4
2018-05-09 CVE-2018-8149 Cross-site Scripting vulnerability in Microsoft Sharepoint Server 2010/2013/2016
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft SharePoint Server, Microsoft SharePoint.
network
low complexity
microsoft CWE-79
5.4
2018-02-15 CVE-2018-0864 Cross-site Scripting vulnerability in Microsoft Sharepoint Server 2013/2016
SharePoint Project Server 2013 and SharePoint Enterprise Server 2016 allow an information disclosure vulnerability due to how web requests are handled, aka "Microsoft SharePoint Information Disclosure Vulnerability".
network
low complexity
microsoft CWE-79
5.4
2017-09-13 CVE-2017-8629 Cross-site Scripting vulnerability in Microsoft Sharepoint Server 2013
Microsoft SharePoint Server 2013 Service Pack 1 allows an elevation of privilege vulnerability when it fails to properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint XSS Vulnerability".
network
low complexity
microsoft CWE-79
5.4
2017-08-08 CVE-2017-8654 Cross-site Scripting vulnerability in Microsoft Sharepoint Server 2010
Microsoft SharePoint Server 2010 Service Pack 2 allows a cross-site scripting (XSS) vulnerability when it does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft Office SharePoint XSS Vulnerability".
network
low complexity
microsoft CWE-79
5.4
2017-04-12 CVE-2017-0195 Cross-site Scripting vulnerability in Microsoft products
Microsoft Excel Services on Microsoft SharePoint Server 2010 SP1 and SP2, Microsoft Excel Web Apps 2010 SP2, Microsoft Office Web Apps 2010 SP2, Microsoft Office Web Apps Server 2013 SP1 and Office Online Server allows remote attackers to perform cross-site scripting and run script with local user privileges via a crafted request, aka "Microsoft Office XSS Elevation of Privilege Vulnerability."
network
low complexity
microsoft CWE-79
5.4