VulnSea

sharepoint_enterprise_server vulnerabilities

CVEs whose affected-version data names the sharepoint_enterprise_server package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

13 CVEsRSS

CVE-2025-49706Medium· 6.5CISA KEVPoC
1y ago

Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

Midnightmicrosoft · sharepoint_enterprise_serverEPSS 99%via NVD
CVE-2020-1107Medium· 5.4
6y ago

A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server

A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a speciall…

Sunlitmicrosoft · sharepoint_enterprise_serverEPSS 1.5%via NVD
CVE-2020-1106Medium· 6.1
6y ago

A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server

A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by …

Sunlitmicrosoft · sharepoint_enterprise_serverEPSS 4.0%via NVD
CVE-2020-1105Medium· 5.4
6y ago

A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server

A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a speciall…

Sunlitmicrosoft · sharepoint_enterprise_serverEPSS 1.7%via NVD
CVE-2020-1104Medium· 5.4
6y ago

A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server

A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a speciall…

Sunlitmicrosoft · sharepoint_enterprise_serverEPSS 1.7%via NVD
CVE-2020-1103Medium· 6.5
6y ago

An information disclosure vulnerability exists where certain modes of the search function in Microsoft SharePoint Server are vulnerable to cross-site search attacks (a variant of cross-site request forgery, CSRF). When users are simultan…

An information disclosure vulnerability exists where certain modes of the search function in Microsoft SharePoint Server are vulnerable to cross-site search attacks (a variant of cross-site request forgery, CSRF). When users are simultan…

Sunlitmicrosoft · sharepoint_enterprise_serverEPSS 2.4%via NVD
CVE-2020-1102High· 8.8PoC
6y ago

A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package

A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package. An attacker who successfully exploited the vulnerability could run arbitrary code in the c…

Midnightmicrosoft · sharepoint_enterprise_serverEPSS 5.2%via NVD
CVE-2020-1101Medium· 5.4
6y ago

A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server

A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by …

Sunlitmicrosoft · sharepoint_enterprise_serverEPSS 1.7%via NVD
CVE-2020-1100Medium· 5.4
6y ago

A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server

A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by …

Sunlitmicrosoft · sharepoint_enterprise_serverEPSS 1.7%via NVD
CVE-2020-1099Medium· 5.4
6y ago

A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server

A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by …

Sunlitmicrosoft · sharepoint_enterprise_serverEPSS 1.7%via NVD
CVE-2020-1069High· 8.8
6y ago

A remote code execution vulnerability exists in Microsoft SharePoint Server when it fails to properly identify and filter unsafe ASP.Net web controls

A remote code execution vulnerability exists in Microsoft SharePoint Server when it fails to properly identify and filter unsafe ASP.Net web controls. An authenticated attacker who successfully exploited the vulnerability could use a spe…

Twilightmicrosoft · sharepoint_enterprise_serverEPSS 4.0%via NVD
CVE-2020-1024High· 8.8
6y ago

A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package

A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package. An attacker who successfully exploited the vulnerability could run arbitrary code in the c…

Twilightmicrosoft · sharepoint_enterprise_serverEPSS 3.7%via NVD
CVE-2020-1023High· 8.8
6y ago

A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package

A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package. An attacker who successfully exploited the vulnerability could run arbitrary code in the c…

Twilightmicrosoft · sharepoint_enterprise_serverEPSS 3.7%via NVD
sharepoint_enterprise_server vulnerabilities (CVEs) · VulnSea