Sharepoint Server
by Microsoft
CVEs (672)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-17118 | Hig | 0.53 | 8.1 | 0.04 | Dec 10, 2020 | Microsoft SharePoint Remote Code Execution Vulnerability | ||
| CVE-2018-0797 | Hig | 0.53 | 7.8 | 0.25 | Jan 10, 2018 | Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow a remote code execution vulnerability due to the way RTF content is handled, aka "Microsoft Word Memory Corruption Vulnerability". | ||
| CVE-2017-8501 | Hig | 0.53 | 7.8 | 0.23 | Jul 11, 2017 | Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka "Microsoft Office Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8502. | ||
| CVE-2017-0030 | Hig | 0.53 | 7.8 | 0.26 | Mar 17, 2017 | Microsoft Office 2010 SP2, Office Compatibility Pack SP3, Office Web Apps Server 2010 SP2, Word 2007 SP3, Word 2010 SP2, and Word Automation Services on SharePoint Server 2010 SP2 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption)… | ||
| CVE-2017-0003 | Hig | 0.53 | 7.8 | 0.25 | Jan 10, 2017 | Microsoft Word 2016 and SharePoint Enterprise Server 2016 allow remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability." | ||
| CVE-2016-3282 | Hig | 0.53 | 7.8 | 0.26 | Jul 13, 2016 | Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, Word for Mac 2011, Word 2016 for Mac, Office Compatibility Pack SP3, Word Viewer, Word Automation Services on SharePoint Server 2010 SP2, Word Automation Services on SharePoint… | ||
| CVE-2026-57105 | Hig | 0.52 | 8.0 | 0.01 | Aug 11, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | ||
| CVE-2026-47298 | Hig | 0.52 | 8.0 | 0.01 | Jun 9, 2026 | Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | ||
| CVE-2026-47294 | Hig | 0.52 | 8.0 | 0.01 | Jun 1, 2026 | Improper neutralization of special elements used in an os command ('os command injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | ||
| CVE-2026-40368 | Hig | 0.52 | 8.0 | 0.02 | May 12, 2026 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | ||
| CVE-2025-62204 | Hig | 0.52 | 8.0 | 0.02 | Nov 11, 2025 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | ||
| CVE-2023-36892 | Hig | 0.52 | 8.0 | 0.02 | Aug 8, 2023 | Microsoft SharePoint Server Spoofing Vulnerability | ||
| CVE-2023-36891 | Hig | 0.52 | 8.0 | 0.02 | Aug 8, 2023 | Microsoft SharePoint Server Spoofing Vulnerability | ||
| CVE-2022-24472 | Hig | 0.52 | 8.0 | 0.02 | Apr 15, 2022 | Microsoft SharePoint Server Spoofing Vulnerability | ||
| CVE-2022-21987 | Hig | 0.52 | 8.0 | 0.02 | Feb 9, 2022 | Microsoft SharePoint Server Spoofing Vulnerability | ||
| CVE-2021-42320 | Hig | 0.52 | 8.0 | 0.02 | Dec 15, 2021 | Microsoft SharePoint Server Spoofing Vulnerability | ||
| CVE-2021-1726 | Hig | 0.52 | 8.0 | 0.02 | Feb 25, 2021 | Microsoft SharePoint Server Spoofing Vulnerability | ||
| CVE-2021-1719 | Hig | 0.52 | 8.0 | 0.02 | Jan 12, 2021 | Microsoft SharePoint Elevation of Privilege Vulnerability | ||
| CVE-2021-1718 | Hig | 0.52 | 8.0 | 0.03 | Jan 12, 2021 | Microsoft SharePoint Server Tampering Vulnerability | ||
| CVE-2021-1712 | Hig | 0.52 | 8.0 | 0.02 | Jan 12, 2021 | Microsoft SharePoint Elevation of Privilege Vulnerability |
- risk 0.53cvss 8.1epss 0.04
Microsoft SharePoint Remote Code Execution Vulnerability
- risk 0.53cvss 7.8epss 0.25
Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow a remote code execution vulnerability due to the way RTF content is handled, aka "Microsoft Word Memory Corruption Vulnerability".
- risk 0.53cvss 7.8epss 0.23
Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka "Microsoft Office Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-8502.
- risk 0.53cvss 7.8epss 0.26
Microsoft Office 2010 SP2, Office Compatibility Pack SP3, Office Web Apps Server 2010 SP2, Word 2007 SP3, Word 2010 SP2, and Word Automation Services on SharePoint Server 2010 SP2 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption)…
- risk 0.53cvss 7.8epss 0.25
Microsoft Word 2016 and SharePoint Enterprise Server 2016 allow remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability."
- risk 0.53cvss 7.8epss 0.26
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, Word for Mac 2011, Word 2016 for Mac, Office Compatibility Pack SP3, Word Viewer, Word Automation Services on SharePoint Server 2010 SP2, Word Automation Services on SharePoint…
- risk 0.52cvss 8.0epss 0.01
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
- risk 0.52cvss 8.0epss 0.01
Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- risk 0.52cvss 8.0epss 0.01
Improper neutralization of special elements used in an os command ('os command injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- risk 0.52cvss 8.0epss 0.02
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- risk 0.52cvss 8.0epss 0.02
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- risk 0.52cvss 8.0epss 0.02
Microsoft SharePoint Server Spoofing Vulnerability
- risk 0.52cvss 8.0epss 0.02
Microsoft SharePoint Server Spoofing Vulnerability
- risk 0.52cvss 8.0epss 0.02
Microsoft SharePoint Server Spoofing Vulnerability
- risk 0.52cvss 8.0epss 0.02
Microsoft SharePoint Server Spoofing Vulnerability
- risk 0.52cvss 8.0epss 0.02
Microsoft SharePoint Server Spoofing Vulnerability
- risk 0.52cvss 8.0epss 0.02
Microsoft SharePoint Server Spoofing Vulnerability
- risk 0.52cvss 8.0epss 0.02
Microsoft SharePoint Elevation of Privilege Vulnerability
- risk 0.52cvss 8.0epss 0.03
Microsoft SharePoint Server Tampering Vulnerability
- risk 0.52cvss 8.0epss 0.02
Microsoft SharePoint Elevation of Privilege Vulnerability
Page 10 of 34