Sharepoint Server
by Microsoft
CVEs (672)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-55033 | Hig | 0.00 | 7.8 | 0.01 | Jul 14, 2026 | Integer overflow or wraparound in Microsoft Office Word allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-55032 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-55030 | Med | 0.00 | 4.6 | 0.01 | Jul 14, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | ||
| CVE-2026-55028 | Med | 0.00 | 5.5 | 0.00 | Jul 14, 2026 | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-55027 | Med | 0.00 | 5.5 | 0.01 | Jul 14, 2026 | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-55026 | Med | 0.00 | 6.2 | 0.00 | Jul 14, 2026 | Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-55023 | Med | 0.00 | 5.5 | 0.01 | Jul 14, 2026 | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-55021 | Hig | 0.00 | 7.3 | 0.01 | Jul 14, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | ||
| CVE-2026-55020 | Med | 0.00 | 4.6 | 0.00 | Jul 14, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | ||
| CVE-2026-55019 | Med | 0.00 | 4.6 | 0.01 | Jul 14, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | ||
| CVE-2026-55016 | Med | 0.00 | 4.6 | 0.00 | Jul 14, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | ||
| CVE-2026-54108 | Med | 0.00 | 6.5 | 0.01 | Jul 14, 2026 | External control of file name or path in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. |
- risk 0.00cvss 7.8epss 0.01
Integer overflow or wraparound in Microsoft Office Word allows an unauthorized attacker to execute code locally.
- risk 0.00cvss 7.8epss 0.00
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
- risk 0.00cvss 4.6epss 0.01
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
- risk 0.00cvss 5.5epss 0.00
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
- risk 0.00cvss 5.5epss 0.01
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
- risk 0.00cvss 6.2epss 0.00
Integer overflow or wraparound in Microsoft Office allows an unauthorized attacker to disclose information locally.
- risk 0.00cvss 5.5epss 0.01
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
- risk 0.00cvss 7.3epss 0.01
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
- risk 0.00cvss 4.6epss 0.00
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
- risk 0.00cvss 4.6epss 0.01
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
- risk 0.00cvss 4.6epss 0.00
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
- risk 0.00cvss 6.5epss 0.01
External control of file name or path in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Page 34 of 34