Sharepoint Server
by Microsoft
CVEs (672)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-17089 | Hig | 0.46 | 7.1 | 0.03 | Dec 10, 2020 | Microsoft SharePoint Elevation of Privilege Vulnerability | ||
| CVE-2025-53736 | Med | 0.44 | 6.8 | 0.01 | Aug 12, 2025 | Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | ||
| CVE-2024-26251 | Med | 0.44 | 6.8 | 0.01 | Apr 9, 2024 | Microsoft SharePoint Server Spoofing Vulnerability | ||
| CVE-2016-7233 | Med | 0.44 | 6.5 | 0.22 | Nov 10, 2016 | Microsoft Word 2007, Office 2010 SP2, Word 2010 SP2, Word for Mac 2011, Excel for Mac 2011, Word Viewer, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2013 SP1, and Office Web Apps 2010 SP2 allow remote attackers to obtain sensitive information… | ||
| CVE-2024-49062 | Med | 0.43 | 6.5 | 0.03 | Dec 12, 2024 | Microsoft SharePoint Information Disclosure Vulnerability | ||
| CVE-2024-43466 | Med | 0.43 | 6.5 | 0.04 | Sep 10, 2024 | Microsoft SharePoint Server Denial of Service Vulnerability | ||
| CVE-2020-16953 | Med | 0.43 | 6.5 | 0.04 | Oct 16, 2020 | An information disclosure vulnerability exists when Microsoft SharePoint Server fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system. To exploit the… | ||
| CVE-2020-16948 | Med | 0.43 | 6.5 | 0.04 | Oct 16, 2020 | An information disclosure vulnerability exists when Microsoft SharePoint Server fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system. To exploit the… | ||
| CVE-2019-1443 | Med | 0.43 | 6.5 | 0.05 | Nov 12, 2019 | An information disclosure vulnerability exists in Microsoft SharePoint when an attacker uploads a specially crafted file to the SharePoint Server.An authenticated attacker who successfully exploited this vulnerability could potentially leverage SharePoint functionality to obtain… | ||
| CVE-2019-0956 | Med | 0.43 | 6.5 | 0.05 | May 16, 2019 | An information disclosure vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Server Information Disclosure Vulnerability'. | ||
| CVE-2018-8160 | Med | 0.43 | 6.5 | 0.09 | May 9, 2018 | An information disclosure vulnerability exists in Outlook when a message is opened, aka "Microsoft Outlook Information Disclosure Vulnerability." This affects Word, Microsoft Office. | ||
| CVE-2026-65660 | Med | 0.42 | 6.5 | 0.01 | Aug 11, 2026 | Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | ||
| CVE-2026-63516 | Med | 0.42 | 6.5 | 0.01 | Aug 11, 2026 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | ||
| CVE-2026-63512 | Med | 0.42 | 6.5 | 0.01 | Aug 11, 2026 | Incorrect authorization in Microsoft Office SharePoint allows an authorized attacker to perform tampering over a network. | ||
| CVE-2026-62839 | Med | 0.42 | 6.5 | 0.01 | Aug 11, 2026 | Insufficiently protected credentials in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | ||
| CVE-2026-62837 | Med | 0.42 | 6.5 | 0.01 | Aug 11, 2026 | Relative path traversal in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network. | ||
| CVE-2026-58639 | Med | 0.42 | 6.5 | 0.01 | Aug 11, 2026 | Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | ||
| CVE-2026-45454 | Med | 0.42 | 6.5 | 0.02 | Jun 9, 2026 | Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | ||
| CVE-2024-49064 | Med | 0.42 | 6.5 | 0.03 | Dec 12, 2024 | Microsoft SharePoint Information Disclosure Vulnerability | ||
| CVE-2023-36894 | Med | 0.42 | 6.5 | 0.02 | Aug 8, 2023 | Microsoft SharePoint Server Information Disclosure Vulnerability |
- risk 0.46cvss 7.1epss 0.03
Microsoft SharePoint Elevation of Privilege Vulnerability
- risk 0.44cvss 6.8epss 0.01
Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
- risk 0.44cvss 6.8epss 0.01
Microsoft SharePoint Server Spoofing Vulnerability
- risk 0.44cvss 6.5epss 0.22
Microsoft Word 2007, Office 2010 SP2, Word 2010 SP2, Word for Mac 2011, Excel for Mac 2011, Word Viewer, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2013 SP1, and Office Web Apps 2010 SP2 allow remote attackers to obtain sensitive information…
- risk 0.43cvss 6.5epss 0.03
Microsoft SharePoint Information Disclosure Vulnerability
- risk 0.43cvss 6.5epss 0.04
Microsoft SharePoint Server Denial of Service Vulnerability
- risk 0.43cvss 6.5epss 0.04
An information disclosure vulnerability exists when Microsoft SharePoint Server fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system. To exploit the…
- risk 0.43cvss 6.5epss 0.04
An information disclosure vulnerability exists when Microsoft SharePoint Server fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system. To exploit the…
- risk 0.43cvss 6.5epss 0.05
An information disclosure vulnerability exists in Microsoft SharePoint when an attacker uploads a specially crafted file to the SharePoint Server.An authenticated attacker who successfully exploited this vulnerability could potentially leverage SharePoint functionality to obtain…
- risk 0.43cvss 6.5epss 0.05
An information disclosure vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Server Information Disclosure Vulnerability'.
- risk 0.43cvss 6.5epss 0.09
An information disclosure vulnerability exists in Outlook when a message is opened, aka "Microsoft Outlook Information Disclosure Vulnerability." This affects Word, Microsoft Office.
- risk 0.42cvss 6.5epss 0.01
Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
- risk 0.42cvss 6.5epss 0.01
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
- risk 0.42cvss 6.5epss 0.01
Incorrect authorization in Microsoft Office SharePoint allows an authorized attacker to perform tampering over a network.
- risk 0.42cvss 6.5epss 0.01
Insufficiently protected credentials in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
- risk 0.42cvss 6.5epss 0.01
Relative path traversal in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.
- risk 0.42cvss 6.5epss 0.01
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
- risk 0.42cvss 6.5epss 0.02
Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- risk 0.42cvss 6.5epss 0.03
Microsoft SharePoint Information Disclosure Vulnerability
- risk 0.42cvss 6.5epss 0.02
Microsoft SharePoint Server Information Disclosure Vulnerability
Page 17 of 34