Page 2 of 21 results (0.004 seconds)

CVSS: 7.8EPSS: 0%CPEs: 3EXPL: 0

10 Dec 2024 — Microsoft SharePoint Information Disclosure Vulnerability • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49064 • CWE-611: Improper Restriction of XML External Entity Reference •

CVSS: 7.8EPSS: 0%CPEs: 3EXPL: 0

08 Oct 2024 — Microsoft SharePoint Elevation of Privilege Vulnerability • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43503 • CWE-284: Improper Access Control •

CVSS: 8.3EPSS: 1%CPEs: 3EXPL: 0

10 Sep 2024 — Microsoft SharePoint Server Remote Code Execution Vulnerability • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38228 • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') •

CVSS: 8.3EPSS: 1%CPEs: 3EXPL: 0

10 Sep 2024 — Microsoft SharePoint Server Remote Code Execution Vulnerability • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38227 • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') •

CVSS: 8.3EPSS: 57%CPEs: 3EXPL: 0

10 Sep 2024 — Microsoft SharePoint Server Remote Code Execution Vulnerability • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43464 • CWE-502: Deserialization of Untrusted Data •

CVSS: 7.8EPSS: 11%CPEs: 3EXPL: 0

10 Sep 2024 — Microsoft SharePoint Server Denial of Service Vulnerability This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Microsoft SharePoint. Authentication is required to exploit this vulnerability. The specific flaw exists within the SPAutoSerializingObject class. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to create a denial... • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43466 • CWE-502: Deserialization of Untrusted Data •

CVSS: 9.0EPSS: 40%CPEs: 3EXPL: 0

10 Sep 2024 — Microsoft SharePoint Server Remote Code Execution Vulnerability This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft SharePoint. Authentication is required to exploit this vulnerability. The specific flaw exists within the handling of serialized instances of the SPThemes class. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to ... • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38018 • CWE-502: Deserialization of Untrusted Data •

CVSS: 8.3EPSS: 64%CPEs: 3EXPL: 0

14 May 2024 — Microsoft SharePoint Server Remote Code Execution Vulnerability Vulnerabilidad de ejecución remota de código de Microsoft SharePoint Server • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30044 • CWE-502: Deserialization of Untrusted Data •

CVSS: 7.1EPSS: 45%CPEs: 3EXPL: 1

14 May 2024 — Microsoft SharePoint Server Information Disclosure Vulnerability Vulnerabilidad de divulgación de información de Microsoft SharePoint Server This vulnerability allows remote attackers to disclose sensitive information on affected installations of Microsoft SharePoint. Authentication is required to exploit this vulnerability. The specific flaw exists within the BaseXmlDataSource class. Due to the improper restriction of XML External Entity (XXE) references, a crafted document specifying a URI causes the XML ... • https://github.com/W01fh4cker/CVE-2024-30043-XXE • CWE-611: Improper Restriction of XML External Entity Reference •

CVSS: 7.1EPSS: 0%CPEs: 3EXPL: 0

09 Apr 2024 — Microsoft SharePoint Server Spoofing Vulnerability Vulnerabilidad de suplantación de identidad de Microsoft SharePoint Server • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26251 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •