Vulnerability index

Browse CVEs

356 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-site Scripting (XSS)CWE-79 × clear
Project Server MEDIUM 6.1
CVE-2017-8551

An elevation of privilege vulnerability exists when Microsoft SharePoint software fails to properly sanitize a specially crafted requests, aka "Micro…

Patch available
Fix from $1,600 2017-06-15
Office MEDIUM 5.4
CVE-2017-8550EPSS 22%

A remote code execution vulnerability exists in Skype for Business when the software fails to sanitize specially crafted content, aka "Skype for Busi…

Patch available
Fix from $1,600 2017-06-15
Sharepoint Enterprise Server MEDIUM 5.4
CVE-2017-8514

An information disclosure vulnerability exists when Microsoft SharePoint software fails to properly sanitize a specially crafted requests, aka "Micro…

Patch available
Fix from $1,600 2017-06-15
Sharepoint Foundation MEDIUM 5.4
CVE-2017-0255

Microsoft SharePoint Foundation 2013 SP1 allows an elevation of privilege vulnerability when it does not properly sanitize a specially crafted web re…

Patch available
Fix from $1,600 2017-05-12
Excel Web App MEDIUM 5.4
CVE-2017-0195

Microsoft Excel Services on Microsoft SharePoint Server 2010 SP1 and SP2, Microsoft Excel Web Apps 2010 SP2, Microsoft Office Web Apps 2010 SP2, Micr…

Patch available
Fix from $1,600 2017-04-12
Sharepoint Foundation MEDIUM 6.1
CVE-2017-0107EPSS 7%

Microsoft SharePoint Server fails to sanitize crafted web requests, allowing remote attackers to run cross-script in local security context, aka "Mic…

Patch available
Fix from $1,600 2017-03-17
Exchange Server MEDIUM 6.1
CVE-2017-0110EPSS 7%

Cross-site scripting (XSS) vulnerability in Microsoft Exchange Outlook Web Access (OWA) allows remote attackers to inject arbitrary web script or HTM…

Patch available
Fix from $1,600 2017-03-17
Windows 10 MEDIUM 6.1
CVE-2017-0055EPSS 16%

Microsoft Internet Information Server (IIS) in Windows Vista SP2; Windows Server 2008 SP2 and R2; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gol…

Patch available
Fix from $1,600 2017-03-17
Edge MEDIUM 6.1
CVE-2017-0017EPSS 42%

The RegEx class in the XSS filter in Microsoft Edge allows remote attackers to conduct cross-site scripting (XSS) attacks and obtain sensitive inform…

Patch available
Fix from $1,600 2017-03-17
Edge MEDIUM 6.1
CVE-2016-7280EPSS 9%

Cross-site scripting (XSS) vulnerability in Microsoft Edge allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, ak…

Mitigation only
Fix from $1,600 2016-12-20
Edge MEDIUM 6.1
CVE-2016-7282EPSS 10%

Cross-site scripting (XSS) vulnerability in Microsoft Internet Explorer 9 through 11 and Microsoft Edge allows remote attackers to inject arbitrary w…

Mitigation only
Fix from $1,600 2016-12-20
Edge MEDIUM 6.1
CVE-2016-7206EPSS 12%

Cross-site scripting (XSS) vulnerability in Microsoft Edge allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, ak…

Mitigation only
Fix from $1,600 2016-12-20
Sql Server MEDIUM 6.1
CVE-2016-7251EPSS 8%

Cross-site scripting (XSS) vulnerability in the MDS API in Microsoft SQL Server 2016 allows remote attackers to inject arbitrary web script or HTML v…

Mitigation only
Fix from $1,600 2016-11-10
Exchange Server MEDIUM 6.1
CVE-2016-3379EPSS 8%

Cross-site scripting (XSS) vulnerability in Microsoft Exchange Server 2016 Cumulative Update 1 and 2 allows remote attackers to inject arbitrary web …

Mitigation only
Fix from $1,600 2016-09-14
Sharepoint Foundation MEDIUM 6.1
CVE-2016-0039EPSS 7%

Cross-site scripting (XSS) vulnerability in SharePoint Server in Microsoft SharePoint Foundation 2013 SP1 allows remote attackers to inject arbitrary…

Mitigation only
Fix from $1,600 2016-02-10
Exchange Server MEDIUM 6.1
CVE-2016-0032EPSS 8%

Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) in Microsoft Exchange Server 2013 PS1, 2013 Cumulative Update 10, 2013 Cumulativ…

Patch available
Fix from $1,600 2016-01-13
Exchange Server MEDIUM 6.1
CVE-2016-0031EPSS 8%

Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) in Microsoft Exchange Server 2016 allows remote attackers to inject arbitrary we…

Patch available
Fix from $1,600 2016-01-13
Exchange Server MEDIUM 6.1
CVE-2016-0030EPSS 8%

Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) in Microsoft Exchange Server 2013 PS1, 2013 Cumulative Update 10, and 2016 allow…

Patch available
Fix from $1,600 2016-01-13
Exchange Server MEDIUM 6.1
CVE-2016-0029EPSS 8%

Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) in Microsoft Exchange Server 2016 allows remote attackers to inject arbitrary we…

Patch available
Fix from $1,600 2016-01-13
Sharepoint Server MEDIUM 5.4
CVE-2016-0011EPSS 5%

Microsoft SharePoint Server 2013 SP1 and SharePoint Foundation 2013 SP1 allow remote authenticated users to bypass intended Access Control Policy res…

Mitigation only
Fix from $1,600 2016-01-13
Sharepoint Foundation MEDIUM 6.1
CVE-2015-6117EPSS 7%

Microsoft SharePoint Server 2013 SP1 and SharePoint Foundation 2013 SP1 allow remote authenticated users to bypass intended Access Control Policy res…

Mitigation only
Fix from $1,600 2016-01-13
Windows 2003 Server MEDIUM 6.1
CVE-2011-0096EPSS 47%

The MHTML protocol handler in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2…

No fix yet
Fix from $1,600 2011-01-31
Internet Explorer HIGH 9.3
CVE-2008-0454EPSS 25%

Cross-zone scripting vulnerability in the Internet Explorer web control in Skype 3.6.0.244, and earlier 3.5.x and 3.6.x versions, on Windows allows u…

Fix: after 3.6.0.244
Fix from $1,950 2008-01-25
Outlook HIGH 8.8
CVE-2007-4040EPSS 13%

Argument injection vulnerability involving Microsoft Outlook and Outlook Express, when certain URIs are registered, allows remote attackers to conduc…

Mitigation only
Fix from $1,950 2007-07-27
Exchange Server MEDIUM 6.8
CVE-2007-0220EPSS 33%

Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) in Microsoft Exchange Server 2000 SP3, and 2003 SP1 and SP2 allows remote attack…

Patch available
Fix from $1,600 2007-05-08
Ie MEDIUM 6.0
CVE-2006-3643EPSS 20%

Cross-site scripting (XSS) vulnerability in Internet Explorer 5.01 and 6 in Microsoft Windows 2000 SP4 permits access to local "HTML-embedded resourc…

Patch available
Fix from $1,600 2006-08-09