Microsoft Sharepoint Server 2019 vulnerabilities
353 known vulnerabilities affecting microsoft/microsoft_sharepoint_server_2019.
Total CVEs
353
CISA KEV
13
actively exploited
Public exploits
19
Exploited in wild
22
Severity breakdown
CRITICAL13HIGH196MEDIUM137LOW7
Vulnerabilities
Page 1 of 18
CVE-2025-53770P1CRITICALCVSS 9.8KEVPoCRansomware≥ 16.0.0, < 16.0.10417.200372025-07-20
CVE-2025-53770 [CRITICAL] CWE-502 CVE-2025-53770: Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized
Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network.
Microsoft is aware that an exploit for CVE-2025-53770 exists in the wild.
Microsoft is preparing and fully testing a comprehensive update to address this vulnerability. In the meantime, please make sure that t
nvd
CVE-2023-29357P1CRITICALCVSS 9.8KEVPoCRansomware≥ 16.0.0, < 16.0.10399.200052023-06-14
CVE-2023-29357 [CRITICAL] CWE-303 CVE-2023-29357: Microsoft SharePoint Server Elevation of Privilege Vulnerability
Microsoft SharePoint Server Elevation of Privilege Vulnerability
nvd
CVE-2025-49704P1HIGHCVSS 8.8KEVPoCRansomware≥ 16.0.0, < 16.0.10417.200272025-07-08
CVE-2025-49704 [HIGH] CWE-94 CVE-2025-49704: Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an a
Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
nvd
CVE-2026-50522P1CRITICALCVSS 9.8KEVPoC≥ 16.0.0, < 16.0.10417.201752026-07-14
CVE-2026-50522 [CRITICAL] CWE-502 CVE-2026-50522: Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-45659P1HIGHCVSS 8.8KEVPoCRansomware≥ 16.0.0, < 16.0.10417.201282026-05-22
CVE-2026-45659 [HIGH] CWE-502 CVE-2026-45659: Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to ex
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
cvelistv5nvd
CVE-2025-49706P1MEDIUMCVSS 6.5KEVPoCRansomware≥ 16.0.0, < 16.0.10417.200272025-07-08
CVE-2025-49706 [MEDIUM] CWE-287 CVE-2025-49706: Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform sp
Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
nvd
CVE-2026-55040P1CRITICALCVSS 9.1KEVPoC≥ 16.0.0, < 16.0.10417.201752026-07-14
CVE-2026-55040 [CRITICAL] CWE-1390 CVE-2026-55040: Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a secur
Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.
nvd
CVE-2023-24955P1HIGHCVSS 7.2KEVPoCRansomware≥ 16.0.0, < 16.0.10398.200002023-05-09
CVE-2023-24955 [HIGH] CWE-94 CVE-2023-24955: Microsoft SharePoint Server Remote Code Execution Vulnerability
Microsoft SharePoint Server Remote Code Execution Vulnerability
nvd
CVE-2026-58644P1CRITICALCVSS 9.8KEVPoC≥ 16.0.0, < 16.0.10417.201532026-07-14
CVE-2026-58644 [CRITICAL] CWE-502 CVE-2026-58644: Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-32201P1MEDIUMCVSS 6.5KEVPoC≥ 16.0.0, < 16.0.10417.201142026-04-14
CVE-2026-32201 [MEDIUM] CWE-20 CVE-2026-32201: Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to perform
Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
nvd
CVE-2026-56164P1CRITICALCVSS 9.8KEV≥ 16.0.0, < 16.0.10417.201752026-07-14
CVE-2026-56164 [CRITICAL] CWE-306 CVE-2026-56164: Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized a
Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.
nvd
CVE-2026-20963P1CRITICALCVSS 9.8KEV≥ 16.0.0, < 16.0.10417.200832026-01-13
CVE-2026-20963 [CRITICAL] CWE-502 CVE-2026-20963: Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
nvd
CVE-2024-38094P1HIGHCVSS 7.2KEVRansomware≥ 16.0.0, < 16.0.10412.200012024-07-09
CVE-2024-38094 [HIGH] CWE-502 CVE-2024-38094: Microsoft SharePoint Remote Code Execution Vulnerability
Microsoft SharePoint Remote Code Execution Vulnerability
nvd
CVE-2023-21716P1CRITICALCVSS 9.8ExploitedPoC≥ 16.0.0, < 16.0.10395.200012023-02-14
CVE-2023-21716 [CRITICAL] CWE-190 CVE-2023-21716: Microsoft Word Remote Code Execution Vulnerability
Microsoft Word Remote Code Execution Vulnerability
nvd
CVE-2025-53771P1MEDIUMCVSS 6.5ExploitedPoCRansomware≥ 16.0.0, < 16.0.10417.200372025-07-20
CVE-2025-53771 [MEDIUM] CWE-287 CVE-2025-53771: Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform sp
Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
nvd
CVE-2023-21742P1HIGHCVSS 8.8ExploitedPoC≥ 16.0.0, < 16.0.10394.200212023-01-10
CVE-2023-21742 [HIGH] CWE-284 CVE-2023-21742: Microsoft SharePoint Server Remote Code Execution Vulnerability
Microsoft SharePoint Server Remote Code Execution Vulnerability
nvd
CVE-2026-63520P1HIGHCVSS 8.1ExploitedPoC≥ 16.0.0, < 16.0.10417.201982026-08-11
CVE-2026-63520 [HIGH] CWE-20 CVE-2026-63520: Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute
Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
nvd
CVE-2024-38023P2HIGHCVSS 7.2Exploited≥ 16.0.0, < 16.0.10412.200012024-07-09
CVE-2024-38023 [HIGH] CWE-502 CVE-2024-38023: Microsoft SharePoint Server Remote Code Execution Vulnerability
Microsoft SharePoint Server Remote Code Execution Vulnerability
nvd
CVE-2024-38024P2HIGHCVSS 7.2Exploited≥ 16.0.0, < 16.0.10412.200012024-07-09
CVE-2024-38024 [HIGH] CWE-502 CVE-2024-38024: Microsoft SharePoint Server Remote Code Execution Vulnerability
Microsoft SharePoint Server Remote Code Execution Vulnerability
nvd
CVE-2022-22005P1HIGHCVSS 8.8Exploited≥ 16.0.0, < 16.0.10383.200012022-02-09
CVE-2022-22005 [HIGH] CWE-502 CVE-2022-22005: Microsoft SharePoint Server Remote Code Execution Vulnerability
Microsoft SharePoint Server Remote Code Execution Vulnerability
nvd
1 / 18Next →