
CVE-2024-49065 – Microsoft Office Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2024-49065
10 Dec 2024 — Microsoft Office Remote Code Execution Vulnerability • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49065 • CWE-125: Out-of-bounds Read •

CVE-2024-49062 – Microsoft SharePoint Information Disclosure Vulnerability
https://notcve.org/view.php?id=CVE-2024-49062
10 Dec 2024 — Microsoft SharePoint Information Disclosure Vulnerability • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49062 • CWE-23: Relative Path Traversal •

CVE-2024-49070 – Microsoft SharePoint Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2024-49070
10 Dec 2024 — Microsoft SharePoint Remote Code Execution Vulnerability • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49070 • CWE-502: Deserialization of Untrusted Data •

CVE-2024-49068 – Microsoft SharePoint Elevation of Privilege Vulnerability
https://notcve.org/view.php?id=CVE-2024-49068
10 Dec 2024 — Microsoft SharePoint Elevation of Privilege Vulnerability • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49068 • CWE-284: Improper Access Control •

CVE-2024-49064 – Microsoft SharePoint Information Disclosure Vulnerability
https://notcve.org/view.php?id=CVE-2024-49064
10 Dec 2024 — Microsoft SharePoint Information Disclosure Vulnerability • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49064 • CWE-611: Improper Restriction of XML External Entity Reference •

CVE-2024-43503 – Microsoft SharePoint Elevation of Privilege Vulnerability
https://notcve.org/view.php?id=CVE-2024-43503
08 Oct 2024 — Microsoft SharePoint Elevation of Privilege Vulnerability • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43503 • CWE-284: Improper Access Control •

CVE-2024-38228 – Microsoft SharePoint Server Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2024-38228
10 Sep 2024 — Microsoft SharePoint Server Remote Code Execution Vulnerability • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38228 • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') •

CVE-2024-38227 – Microsoft SharePoint Server Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2024-38227
10 Sep 2024 — Microsoft SharePoint Server Remote Code Execution Vulnerability • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38227 • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') •

CVE-2024-43464 – Microsoft SharePoint Server Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2024-43464
10 Sep 2024 — Microsoft SharePoint Server Remote Code Execution Vulnerability • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43464 • CWE-502: Deserialization of Untrusted Data •

CVE-2024-38018 – Microsoft SharePoint Server Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2024-38018
10 Sep 2024 — Microsoft SharePoint Server Remote Code Execution Vulnerability This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft SharePoint. Authentication is required to exploit this vulnerability. The specific flaw exists within the handling of serialized instances of the SPThemes class. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to ... • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38018 • CWE-502: Deserialization of Untrusted Data •