Exposição de Microsoft SharePoint

CMS
15
score de exposição
2.158
sites usam
0
em exploração
0
críticos
Análise Vexday

O histórico de vulnerabilidades do Microsoft SharePoint no catálogo soma 52 CVEs, nenhuma das quais está atualmente confirmada em exploração ativa pelo CISA KEV, resultado abaixo da média geral do catálogo. Não há registros de severidade crítica nem de novas vulnerabilidades surgidas nos últimos 90 dias, o que indica um período recente de relativa estabilidade para a plataforma. O tipo de falha mais recorrente é CWE-79 (Cross-Site Scripting), padrão que, embora comum em aplicações web, exige atenção continuada em ambientes corporativos onde o SharePoint processa conteúdo de múltiplos usuários. A CVE com maior pontuação EPSS no conjunto é CVE-2019-0585, com valor de aproximadamente 0,22, sugerindo probabilidade moderada de tentativa de exploração — organizações que ainda mantêm versões antigas do produto devem verificar se essa vulnerabilidade foi devidamente remediada.

CVEs

52 resultados
CVE-2018-8431An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request tEPSS 2.3%CVE-2018-1034An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request tEPSS 2.2%CVE-2018-1005An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request tEPSS 2.2%CVE-2018-1014An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request tEPSS 2.2%CVE-2018-1032An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request tEPSS 2.2%CVE-2019-0557MEDIUMA cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web requesEPSS 2.1%CVE-2019-0558MEDIUMA cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web requesEPSS 2.0%CVE-2018-8428An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request tEPSS 1.7%CVE-2019-0562An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request tEPSS 1.7%CVE-2019-0556MEDIUMA cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web requesEPSS 1.6%CVE-2018-8572An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request tEPSS 1.6%CVE-2018-8650MEDIUMA cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web requesEPSS 1.6%