Office SharePoint
by Microsoft
CVEs (233)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-43464 | Hig | 0.50 | 7.2 | 0.36 | Sep 10, 2024 | Microsoft SharePoint Server Remote Code Execution Vulnerability | ||
| CVE-2024-38024 | Hig | 0.50 | 7.2 | 0.45 | Jul 9, 2024 | Microsoft SharePoint Server Remote Code Execution Vulnerability | ||
| CVE-2026-21511 | Hig | 0.49 | 7.5 | 0.04 | Feb 10, 2026 | Deserialization of untrusted data in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2026-21260 | Hig | 0.49 | 7.5 | 0.01 | Feb 10, 2026 | Exposure of sensitive information to an unauthorized actor in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2024-32987 | Hig | 0.49 | 7.5 | 0.02 | Jul 9, 2024 | Microsoft SharePoint Server Information Disclosure Vulnerability | ||
| CVE-2025-30384 | Hig | 0.48 | 7.4 | 0.01 | May 13, 2025 | Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally. | ||
| CVE-2025-29793 | Hig | 0.48 | 7.2 | 0.22 | Apr 8, 2025 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | ||
| CVE-2024-49070 | Hig | 0.48 | 7.4 | 0.02 | Dec 12, 2024 | Microsoft SharePoint Remote Code Execution Vulnerability | ||
| CVE-2023-33130 | Hig | 0.48 | 7.3 | 0.01 | Jun 14, 2023 | Microsoft SharePoint Server Spoofing Vulnerability | ||
| CVE-2023-24950 | Med | 0.48 | 6.5 | 0.67 | May 9, 2023 | Microsoft SharePoint Server Spoofing Vulnerability | ||
| CVE-2026-70355 | Hig | 0.47 | 7.3 | 0.00 | Aug 11, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-64900 | Hig | 0.47 | 7.3 | 0.00 | Aug 11, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | ||
| CVE-2026-47634 | Hig | 0.47 | 7.3 | 0.01 | Jun 9, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | ||
| CVE-2026-45481 | Hig | 0.47 | 7.3 | 0.01 | Jun 9, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | ||
| CVE-2025-53760 | Hig | 0.47 | 7.1 | 0.12 | Aug 12, 2025 | Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2025-21348 | Hig | 0.47 | 7.2 | 0.02 | Jan 14, 2025 | Microsoft SharePoint Server Remote Code Execution Vulnerability | ||
| CVE-2024-38228 | Hig | 0.47 | 7.2 | 0.04 | Sep 10, 2024 | Microsoft SharePoint Server Remote Code Execution Vulnerability | ||
| CVE-2024-38227 | Hig | 0.47 | 7.2 | 0.08 | Sep 10, 2024 | Microsoft SharePoint Server Remote Code Execution Vulnerability | ||
| CVE-2024-30043 | Med | 0.47 | 6.5 | 0.55 | May 14, 2024 | Microsoft SharePoint Server Information Disclosure Vulnerability | ||
| CVE-2026-20943 | Hig | 0.46 | 7.0 | 0.01 | Jan 13, 2026 | Untrusted search path in Microsoft Office allows an unauthorized attacker to execute code locally. |
- risk 0.50cvss 7.2epss 0.36
Microsoft SharePoint Server Remote Code Execution Vulnerability
- risk 0.50cvss 7.2epss 0.45
Microsoft SharePoint Server Remote Code Execution Vulnerability
- risk 0.49cvss 7.5epss 0.04
Deserialization of untrusted data in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network.
- risk 0.49cvss 7.5epss 0.01
Exposure of sensitive information to an unauthorized actor in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network.
- risk 0.49cvss 7.5epss 0.02
Microsoft SharePoint Server Information Disclosure Vulnerability
- risk 0.48cvss 7.4epss 0.01
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally.
- risk 0.48cvss 7.2epss 0.22
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- risk 0.48cvss 7.4epss 0.02
Microsoft SharePoint Remote Code Execution Vulnerability
- risk 0.48cvss 7.3epss 0.01
Microsoft SharePoint Server Spoofing Vulnerability
- risk 0.48cvss 6.5epss 0.67
Microsoft SharePoint Server Spoofing Vulnerability
- risk 0.47cvss 7.3epss 0.00
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
- risk 0.47cvss 7.3epss 0.00
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
- risk 0.47cvss 7.3epss 0.01
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
- risk 0.47cvss 7.3epss 0.01
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
- risk 0.47cvss 7.1epss 0.12
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
- risk 0.47cvss 7.2epss 0.02
Microsoft SharePoint Server Remote Code Execution Vulnerability
- risk 0.47cvss 7.2epss 0.04
Microsoft SharePoint Server Remote Code Execution Vulnerability
- risk 0.47cvss 7.2epss 0.08
Microsoft SharePoint Server Remote Code Execution Vulnerability
- risk 0.47cvss 6.5epss 0.55
Microsoft SharePoint Server Information Disclosure Vulnerability
- risk 0.46cvss 7.0epss 0.01
Untrusted search path in Microsoft Office allows an unauthorized attacker to execute code locally.
Page 7 of 12