VYPR

Office SharePoint

by Microsoft

CVEs (233)

  • CVE-2026-70306CriAug 11, 2026
    risk 0.60cvss 9.3epss 0.01

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2024-21318HigJan 9, 2024
    risk 0.60cvss 8.8epss 0.31

    Microsoft SharePoint Server Remote Code Execution Vulnerability

  • CVE-2026-20947HigJan 13, 2026
    risk 0.59cvss 8.8epss 0.19

    Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

  • CVE-2025-54897HigSep 9, 2025
    risk 0.59cvss 8.8epss 0.19

    Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

  • CVE-2025-49712HigAug 12, 2025
    risk 0.59cvss 8.8epss 0.20

    Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

  • CVE-2022-22005HigFeb 9, 2022
    risk 0.59cvss 8.8epss 0.17

    Microsoft SharePoint Server Remote Code Execution Vulnerability

  • CVE-2019-0585HigJan 8, 2019
    risk 0.59cvss 8.8epss 0.20

    A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka "Microsoft Word Remote Code Execution Vulnerability." This affects Word, Microsoft Office, Microsoft Office Word Viewer, Office 365 ProPlus, Microsoft…

  • CVE-2018-1028HigApr 12, 2018
    risk 0.59cvss 8.8epss 0.17

    A remote code execution vulnerability exists when the Office graphics component improperly handles specially crafted embedded fonts, aka "Microsoft Office Graphics Remote Code Execution Vulnerability." This affects Word, Microsoft Office, Microsoft SharePoint, Excel, Microsoft…

  • CVE-2025-47163HigJun 10, 2025
    risk 0.58cvss 8.8epss 0.15

    Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

  • CVE-2025-29794HigApr 8, 2025
    risk 0.58cvss 8.8epss 0.05

    Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

  • CVE-2023-33160HigJul 11, 2023
    risk 0.58cvss 8.8epss 0.04

    Microsoft SharePoint Server Remote Code Execution Vulnerability

  • CVE-2022-30157HigJun 15, 2022
    risk 0.58cvss 8.8epss 0.08

    Microsoft SharePoint Server Remote Code Execution Vulnerability

  • CVE-2022-29108HigMay 10, 2022
    risk 0.58cvss 8.8epss 0.12

    Microsoft SharePoint Server Remote Code Execution Vulnerability

  • CVE-2018-8635HigDec 12, 2018
    risk 0.58cvss 8.8epss 0.05

    An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted authentication request to an affected SharePoint server, aka "Microsoft SharePoint Server Elevation of Privilege Vulnerability." This affects Microsoft…

  • CVE-2018-8300HigJul 11, 2018
    risk 0.58cvss 8.8epss 0.12

    A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka "Microsoft SharePoint Remote Code Execution Vulnerability." This affects Microsoft SharePoint.

  • CVE-2026-70326HigAug 11, 2026
    risk 0.57cvss 8.8epss 0.01

    Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-70324HigAug 11, 2026
    risk 0.57cvss 8.8epss 0.01

    Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-70321HigAug 11, 2026
    risk 0.57cvss 8.8epss 0.01

    Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

  • CVE-2026-66808HigAug 11, 2026
    risk 0.57cvss 8.8epss 0.01

    Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

  • CVE-2026-66805HigAug 11, 2026
    risk 0.57cvss 8.8epss 0.02

    Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Page 2 of 12