Sharepoint Server
by Microsoft
CVEs (672)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-43242 | Hig | 0.49 | 7.6 | 0.01 | Dec 15, 2021 | Microsoft SharePoint Server Spoofing Vulnerability | ||
| CVE-2021-38652 | Hig | 0.49 | 7.6 | 0.01 | Sep 15, 2021 | Microsoft SharePoint Server Spoofing Vulnerability | ||
| CVE-2021-38651 | Hig | 0.49 | 7.6 | 0.01 | Sep 15, 2021 | Microsoft SharePoint Server Spoofing Vulnerability | ||
| CVE-2019-1006 | Hig | 0.49 | 7.5 | 0.06 | Jul 15, 2019 | An authentication bypass vulnerability exists in Windows Communication Foundation (WCF) and Windows Identity Foundation (WIF), allowing signing of SAML tokens with arbitrary symmetric keys, aka 'WCF/WIF SAML Token Authentication Bypass Vulnerability'. | ||
| CVE-2016-0025 | Hig | 0.49 | 7.3 | 0.15 | Jun 16, 2016 | Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Office 2016, Word 2016, Word for Mac 2011, Word 2016 for Mac, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2010 SP2, Word Automation Services on SharePoint… | ||
| CVE-2025-30384 | Hig | 0.48 | 7.4 | 0.01 | May 13, 2025 | Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally. | ||
| CVE-2025-29793 | Hig | 0.48 | 7.2 | 0.22 | Apr 8, 2025 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | ||
| CVE-2024-49070 | Hig | 0.48 | 7.4 | 0.02 | Dec 12, 2024 | Microsoft SharePoint Remote Code Execution Vulnerability | ||
| CVE-2023-36762 | Hig | 0.48 | 7.3 | 0.01 | Sep 12, 2023 | Microsoft Word Remote Code Execution Vulnerability | ||
| CVE-2023-33130 | Hig | 0.48 | 7.3 | 0.01 | Jun 14, 2023 | Microsoft SharePoint Server Spoofing Vulnerability | ||
| CVE-2023-24950 | Med | 0.48 | 6.5 | 0.67 | May 9, 2023 | Microsoft SharePoint Server Spoofing Vulnerability | ||
| CVE-2020-1345 | Hig | 0.48 | 7.4 | 0.03 | Sep 11, 2020 | A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially crafted request to… | ||
| CVE-2020-1198 | Hig | 0.48 | 7.4 | 0.03 | Sep 11, 2020 | A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially crafted request to… | ||
| CVE-2016-7291 | Hig | 0.48 | 7.1 | 0.23 | Dec 20, 2016 | Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Office Compatibility Pack SP3, Word for Mac 2011, Word Automation Services on SharePoint Server 2010 SP2, and Office Web Apps 2010 SP2 allow remote attackers to obtain sensitive information from process memory or cause a… | ||
| CVE-2016-7290 | Hig | 0.48 | 7.1 | 0.23 | Dec 20, 2016 | Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Office Compatibility Pack SP3, Word for Mac 2011, Word Automation Services on SharePoint Server 2010 SP2, and Office Web Apps 2010 SP2 allow remote attackers to obtain sensitive information from process memory or cause a… | ||
| CVE-2016-7268 | Hig | 0.48 | 7.1 | 0.23 | Dec 20, 2016 | Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Office Compatibility Pack SP3, Word Viewer, Word for Mac 2011, Word Automation Services on SharePoint Server 2010 SP2, and Office Web Apps 2010 SP2 allow remote attackers to obtain sensitive information from process memory… | ||
| CVE-2016-7265 | Hig | 0.48 | 7.1 | 0.23 | Dec 20, 2016 | Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Office Compatibility Pack SP3, Excel Viewer, Excel Services on SharePoint Server 2007 SP3, and Excel Services on SharePoint Server 2010 SP2 allow remote attackers to obtain sensitive… | ||
| CVE-2026-70355 | Hig | 0.47 | 7.3 | 0.00 | Aug 11, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-64900 | Hig | 0.47 | 7.3 | 0.00 | Aug 11, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | ||
| CVE-2026-47634 | Hig | 0.47 | 7.3 | 0.01 | Jun 9, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. |
- risk 0.49cvss 7.6epss 0.01
Microsoft SharePoint Server Spoofing Vulnerability
- risk 0.49cvss 7.6epss 0.01
Microsoft SharePoint Server Spoofing Vulnerability
- risk 0.49cvss 7.6epss 0.01
Microsoft SharePoint Server Spoofing Vulnerability
- risk 0.49cvss 7.5epss 0.06
An authentication bypass vulnerability exists in Windows Communication Foundation (WCF) and Windows Identity Foundation (WIF), allowing signing of SAML tokens with arbitrary symmetric keys, aka 'WCF/WIF SAML Token Authentication Bypass Vulnerability'.
- risk 0.49cvss 7.3epss 0.15
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Office 2016, Word 2016, Word for Mac 2011, Word 2016 for Mac, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2010 SP2, Word Automation Services on SharePoint…
- risk 0.48cvss 7.4epss 0.01
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally.
- risk 0.48cvss 7.2epss 0.22
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- risk 0.48cvss 7.4epss 0.02
Microsoft SharePoint Remote Code Execution Vulnerability
- risk 0.48cvss 7.3epss 0.01
Microsoft Word Remote Code Execution Vulnerability
- risk 0.48cvss 7.3epss 0.01
Microsoft SharePoint Server Spoofing Vulnerability
- risk 0.48cvss 6.5epss 0.67
Microsoft SharePoint Server Spoofing Vulnerability
- risk 0.48cvss 7.4epss 0.03
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially crafted request to…
- risk 0.48cvss 7.4epss 0.03
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially crafted request to…
- risk 0.48cvss 7.1epss 0.23
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Office Compatibility Pack SP3, Word for Mac 2011, Word Automation Services on SharePoint Server 2010 SP2, and Office Web Apps 2010 SP2 allow remote attackers to obtain sensitive information from process memory or cause a…
- risk 0.48cvss 7.1epss 0.23
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Office Compatibility Pack SP3, Word for Mac 2011, Word Automation Services on SharePoint Server 2010 SP2, and Office Web Apps 2010 SP2 allow remote attackers to obtain sensitive information from process memory or cause a…
- risk 0.48cvss 7.1epss 0.23
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Office Compatibility Pack SP3, Word Viewer, Word for Mac 2011, Word Automation Services on SharePoint Server 2010 SP2, and Office Web Apps 2010 SP2 allow remote attackers to obtain sensitive information from process memory…
- risk 0.48cvss 7.1epss 0.23
Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Office Compatibility Pack SP3, Excel Viewer, Excel Services on SharePoint Server 2007 SP3, and Excel Services on SharePoint Server 2010 SP2 allow remote attackers to obtain sensitive…
- risk 0.47cvss 7.3epss 0.00
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
- risk 0.47cvss 7.3epss 0.00
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
- risk 0.47cvss 7.3epss 0.01
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Page 15 of 34