Office SharePoint
by Microsoft
CVEs (233)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-30044 | Hig | 0.54 | 7.2 | 0.84 | May 14, 2024 | Microsoft SharePoint Server Remote Code Execution Vulnerability | ||
| CVE-2022-21837 | Hig | 0.54 | 8.3 | 0.03 | Jan 11, 2022 | Microsoft SharePoint Server Remote Code Execution Vulnerability | ||
| CVE-2026-63520 | Hig | 0.53 | 8.1 | 0.03 | Aug 11, 2026 | Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-26105 | Hig | 0.53 | 8.1 | 0.01 | Mar 10, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2025-53771 | Med | 0.53 | 6.5 | 1.00 | Jul 20, 2025 | Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2024-49068 | Hig | 0.53 | 8.2 | 0.02 | Dec 12, 2024 | Microsoft SharePoint Elevation of Privilege Vulnerability | ||
| CVE-2020-17118 | Hig | 0.53 | 8.1 | 0.04 | Dec 10, 2020 | Microsoft SharePoint Remote Code Execution Vulnerability | ||
| CVE-2026-57105 | Hig | 0.52 | 8.0 | 0.01 | Aug 11, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | ||
| CVE-2026-47298 | Hig | 0.52 | 8.0 | 0.01 | Jun 9, 2026 | Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | ||
| CVE-2026-47294 | Hig | 0.52 | 8.0 | 0.01 | Jun 1, 2026 | Improper neutralization of special elements used in an os command ('os command injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | ||
| CVE-2026-40368 | Hig | 0.52 | 8.0 | 0.02 | May 12, 2026 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | ||
| CVE-2025-62204 | Hig | 0.52 | 8.0 | 0.02 | Nov 11, 2025 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | ||
| CVE-2023-36892 | Hig | 0.52 | 8.0 | 0.02 | Aug 8, 2023 | Microsoft SharePoint Server Spoofing Vulnerability | ||
| CVE-2023-36891 | Hig | 0.52 | 8.0 | 0.02 | Aug 8, 2023 | Microsoft SharePoint Server Spoofing Vulnerability | ||
| CVE-2022-24472 | Hig | 0.52 | 8.0 | 0.02 | Apr 15, 2022 | Microsoft SharePoint Server Spoofing Vulnerability | ||
| CVE-2022-21987 | Hig | 0.52 | 8.0 | 0.02 | Feb 9, 2022 | Microsoft SharePoint Server Spoofing Vulnerability | ||
| CVE-2020-17115 | Hig | 0.52 | 8.0 | 0.02 | Dec 10, 2020 | Microsoft SharePoint Server Spoofing Vulnerability | ||
| CVE-2018-8628 | Hig | 0.52 | 7.8 | 0.15 | Dec 12, 2018 | A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fails to properly handle objects in memory, aka "Microsoft PowerPoint Remote Code Execution Vulnerability." This affects Microsoft Office, Office 365 ProPlus, Microsoft PowerPoint,… | ||
| CVE-2018-8161 | Hig | 0.52 | 7.8 | 0.20 | May 9, 2018 | A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory, aka "Microsoft Office Remote Code Execution Vulnerability." This affects Microsoft Word, Word, Microsoft Office, Microsoft SharePoint. This CVE… | ||
| CVE-2026-20951 | Hig | 0.51 | 7.8 | 0.01 | Jan 13, 2026 | Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally. |
- risk 0.54cvss 7.2epss 0.84
Microsoft SharePoint Server Remote Code Execution Vulnerability
- risk 0.54cvss 8.3epss 0.03
Microsoft SharePoint Server Remote Code Execution Vulnerability
- risk 0.53cvss 8.1epss 0.03
Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
- risk 0.53cvss 8.1epss 0.01
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
- risk 0.53cvss 6.5epss 1.00
Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
- risk 0.53cvss 8.2epss 0.02
Microsoft SharePoint Elevation of Privilege Vulnerability
- risk 0.53cvss 8.1epss 0.04
Microsoft SharePoint Remote Code Execution Vulnerability
- risk 0.52cvss 8.0epss 0.01
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
- risk 0.52cvss 8.0epss 0.01
Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- risk 0.52cvss 8.0epss 0.01
Improper neutralization of special elements used in an os command ('os command injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- risk 0.52cvss 8.0epss 0.02
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- risk 0.52cvss 8.0epss 0.02
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- risk 0.52cvss 8.0epss 0.02
Microsoft SharePoint Server Spoofing Vulnerability
- risk 0.52cvss 8.0epss 0.02
Microsoft SharePoint Server Spoofing Vulnerability
- risk 0.52cvss 8.0epss 0.02
Microsoft SharePoint Server Spoofing Vulnerability
- risk 0.52cvss 8.0epss 0.02
Microsoft SharePoint Server Spoofing Vulnerability
- risk 0.52cvss 8.0epss 0.02
Microsoft SharePoint Server Spoofing Vulnerability
- risk 0.52cvss 7.8epss 0.15
A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fails to properly handle objects in memory, aka "Microsoft PowerPoint Remote Code Execution Vulnerability." This affects Microsoft Office, Office 365 ProPlus, Microsoft PowerPoint,…
- risk 0.52cvss 7.8epss 0.20
A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory, aka "Microsoft Office Remote Code Execution Vulnerability." This affects Microsoft Word, Word, Microsoft Office, Microsoft SharePoint. This CVE…
- risk 0.51cvss 7.8epss 0.01
Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally.
Page 5 of 12