Sharepoint Server
by Microsoft
CVEs (672)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-1025 | Cri | 0.64 | 9.8 | 0.06 | Jul 14, 2020 | An elevation of privilege vulnerability exists when Microsoft SharePoint Server and Skype for Business Server improperly handle OAuth token validation. An attacker who successfully exploited the vulnerability could bypass authentication and achieve improper access. To exploit… | ||
| CVE-2019-1205 | Cri | 0.64 | 9.8 | 0.04 | Aug 14, 2019 | A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could use a specially crafted file to perform actions in the security context of the current user.… | ||
| CVE-2022-38053 | Hig | 0.63 | 8.8 | 0.76 | Oct 11, 2022 | Microsoft SharePoint Server Remote Code Execution Vulnerability | ||
| CVE-2021-31181 | Hig | 0.63 | 8.8 | 0.30 | May 11, 2021 | Microsoft SharePoint Remote Code Execution Vulnerability | ||
| CVE-2020-1181 | Hig | 0.63 | 8.8 | 0.69 | Jun 9, 2020 | A remote code execution vulnerability exists in Microsoft SharePoint Server when it fails to properly identify and filter unsafe ASP.Net web controls, aka 'Microsoft SharePoint Server Remote Code Execution Vulnerability'. | ||
| CVE-2026-70332 | Cri | 0.62 | 9.6 | 0.00 | Aug 7, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2023-21742 | Hig | 0.62 | 8.8 | 0.56 | Jan 10, 2023 | Microsoft SharePoint Server Remote Code Execution Vulnerability | ||
| CVE-2025-47166 | Hig | 0.61 | 8.8 | 0.15 | Jun 10, 2025 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | ||
| CVE-2024-38018 | Hig | 0.61 | 8.8 | 0.51 | Sep 10, 2024 | Microsoft SharePoint Server Remote Code Execution Vulnerability | ||
| CVE-2023-33157 | Hig | 0.61 | 8.8 | 0.41 | Jul 11, 2023 | Microsoft SharePoint Remote Code Execution Vulnerability | ||
| CVE-2022-37961 | Hig | 0.61 | 8.8 | 0.50 | Sep 13, 2022 | Microsoft SharePoint Server Remote Code Execution Vulnerability | ||
| CVE-2022-35823 | Hig | 0.61 | 8.8 | 0.53 | Sep 13, 2022 | Microsoft SharePoint Remote Code Execution Vulnerability | ||
| CVE-2021-28474 | Hig | 0.61 | 8.8 | 0.51 | May 11, 2021 | Microsoft SharePoint Server Remote Code Execution Vulnerability | ||
| CVE-2026-70306 | Cri | 0.60 | 9.3 | 0.01 | Aug 11, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2024-21318 | Hig | 0.60 | 8.8 | 0.31 | Jan 9, 2024 | Microsoft SharePoint Server Remote Code Execution Vulnerability | ||
| CVE-2020-0932 | Hig | 0.60 | 8.8 | 0.31 | Apr 15, 2020 | A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0920, CVE-2020-0929,… | ||
| CVE-2026-55040 | Cri | 0.59 | 9.1 | 0.04 | Jul 14, 2026 | Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network. | ||
| CVE-2026-20947 | Hig | 0.59 | 8.8 | 0.19 | Jan 13, 2026 | Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | ||
| CVE-2025-54897 | Hig | 0.59 | 8.8 | 0.19 | Sep 9, 2025 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | ||
| CVE-2025-49712 | Hig | 0.59 | 8.8 | 0.18 | Aug 12, 2025 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. |
- risk 0.64cvss 9.8epss 0.06
An elevation of privilege vulnerability exists when Microsoft SharePoint Server and Skype for Business Server improperly handle OAuth token validation. An attacker who successfully exploited the vulnerability could bypass authentication and achieve improper access. To exploit…
- risk 0.64cvss 9.8epss 0.04
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could use a specially crafted file to perform actions in the security context of the current user.…
- risk 0.63cvss 8.8epss 0.76
Microsoft SharePoint Server Remote Code Execution Vulnerability
- risk 0.63cvss 8.8epss 0.30
Microsoft SharePoint Remote Code Execution Vulnerability
- risk 0.63cvss 8.8epss 0.69
A remote code execution vulnerability exists in Microsoft SharePoint Server when it fails to properly identify and filter unsafe ASP.Net web controls, aka 'Microsoft SharePoint Server Remote Code Execution Vulnerability'.
- risk 0.62cvss 9.6epss 0.00
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
- risk 0.62cvss 8.8epss 0.56
Microsoft SharePoint Server Remote Code Execution Vulnerability
- risk 0.61cvss 8.8epss 0.15
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- risk 0.61cvss 8.8epss 0.51
Microsoft SharePoint Server Remote Code Execution Vulnerability
- risk 0.61cvss 8.8epss 0.41
Microsoft SharePoint Remote Code Execution Vulnerability
- risk 0.61cvss 8.8epss 0.50
Microsoft SharePoint Server Remote Code Execution Vulnerability
- risk 0.61cvss 8.8epss 0.53
Microsoft SharePoint Remote Code Execution Vulnerability
- risk 0.61cvss 8.8epss 0.51
Microsoft SharePoint Server Remote Code Execution Vulnerability
- risk 0.60cvss 9.3epss 0.01
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
- risk 0.60cvss 8.8epss 0.31
Microsoft SharePoint Server Remote Code Execution Vulnerability
- risk 0.60cvss 8.8epss 0.31
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0920, CVE-2020-0929,…
- risk 0.59cvss 9.1epss 0.04
Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.
- risk 0.59cvss 8.8epss 0.19
Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- risk 0.59cvss 8.8epss 0.19
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- risk 0.59cvss 8.8epss 0.18
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Page 2 of 34