Sharepoint Server
by Microsoft
CVEs (672)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-1452 | Hig | 0.56 | 8.6 | 0.02 | Sep 11, 2020 | A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the SharePoint application… | ||
| CVE-2020-1200 | Hig | 0.56 | 8.6 | 0.02 | Sep 11, 2020 | A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the SharePoint application… | ||
| CVE-2018-8284 | Hig | 0.56 | 8.1 | 0.39 | Jul 11, 2018 | A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka ".NET Framework Remote Code Injection Vulnerability." This affects Microsoft .NET Framework 2.0, Microsoft .NET Framework 3.0, Microsoft .NET Framework… | ||
| CVE-2010-0258 | Hig | 0.56 | 7.8 | 0.61 | Mar 10, 2010 | Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Excel Viewer SP1 and SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 do not properly… | ||
| CVE-2026-45458 | Hig | 0.55 | 8.4 | 0.00 | Jun 9, 2026 | Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-45456 | Hig | 0.55 | 8.4 | 0.00 | Jun 9, 2026 | Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-40367 | Hig | 0.55 | 8.4 | 0.00 | May 12, 2026 | Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-26113 | Hig | 0.55 | 8.4 | 0.01 | Mar 10, 2026 | Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally. | ||
| CVE-2025-53733 | Hig | 0.55 | 8.4 | 0.01 | Aug 12, 2025 | Incorrect conversion between numeric types in Microsoft Office Word allows an unauthorized attacker to execute code locally. | ||
| CVE-2020-1576 | Hig | 0.55 | 8.5 | 0.02 | Sep 11, 2020 | A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the SharePoint application… | ||
| CVE-2025-21400 | Hig | 0.54 | 8.0 | 0.34 | Feb 11, 2025 | Microsoft SharePoint Server Remote Code Execution Vulnerability | ||
| CVE-2024-30044 | Hig | 0.54 | 7.2 | 0.84 | May 14, 2024 | Microsoft SharePoint Server Remote Code Execution Vulnerability | ||
| CVE-2022-21837 | Hig | 0.54 | 8.3 | 0.03 | Jan 11, 2022 | Microsoft SharePoint Server Remote Code Execution Vulnerability | ||
| CVE-2026-63520 | Hig | 0.53 | 8.1 | 0.01 | Aug 11, 2026 | Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-26105 | Hig | 0.53 | 8.1 | 0.01 | Mar 10, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2025-53771 | Med | 0.53 | 6.5 | 1.00 | Jul 20, 2025 | Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2024-49068 | Hig | 0.53 | 8.2 | 0.02 | Dec 12, 2024 | Microsoft SharePoint Elevation of Privilege Vulnerability | ||
| CVE-2021-41344 | Hig | 0.53 | 8.1 | 0.06 | Oct 13, 2021 | Microsoft SharePoint Server Remote Code Execution Vulnerability | ||
| CVE-2021-34520 | Hig | 0.53 | 8.1 | 0.04 | Jul 14, 2021 | Microsoft SharePoint Server Remote Code Execution Vulnerability | ||
| CVE-2021-31950 | Hig | 0.53 | 7.6 | 0.05 | Jun 8, 2021 | Microsoft SharePoint Server Spoofing Vulnerability |
- risk 0.56cvss 8.6epss 0.02
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the SharePoint application…
- risk 0.56cvss 8.6epss 0.02
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the SharePoint application…
- risk 0.56cvss 8.1epss 0.39
A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka ".NET Framework Remote Code Injection Vulnerability." This affects Microsoft .NET Framework 2.0, Microsoft .NET Framework 3.0, Microsoft .NET Framework…
- risk 0.56cvss 7.8epss 0.61
Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Excel Viewer SP1 and SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 do not properly…
- risk 0.55cvss 8.4epss 0.00
Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.
- risk 0.55cvss 8.4epss 0.00
Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.
- risk 0.55cvss 8.4epss 0.00
Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally.
- risk 0.55cvss 8.4epss 0.01
Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally.
- risk 0.55cvss 8.4epss 0.01
Incorrect conversion between numeric types in Microsoft Office Word allows an unauthorized attacker to execute code locally.
- risk 0.55cvss 8.5epss 0.02
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the SharePoint application…
- risk 0.54cvss 8.0epss 0.34
Microsoft SharePoint Server Remote Code Execution Vulnerability
- risk 0.54cvss 7.2epss 0.84
Microsoft SharePoint Server Remote Code Execution Vulnerability
- risk 0.54cvss 8.3epss 0.03
Microsoft SharePoint Server Remote Code Execution Vulnerability
- risk 0.53cvss 8.1epss 0.01
Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
- risk 0.53cvss 8.1epss 0.01
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
- risk 0.53cvss 6.5epss 1.00
Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
- risk 0.53cvss 8.2epss 0.02
Microsoft SharePoint Elevation of Privilege Vulnerability
- risk 0.53cvss 8.1epss 0.06
Microsoft SharePoint Server Remote Code Execution Vulnerability
- risk 0.53cvss 8.1epss 0.04
Microsoft SharePoint Server Remote Code Execution Vulnerability
- risk 0.53cvss 7.6epss 0.05
Microsoft SharePoint Server Spoofing Vulnerability
Page 9 of 34