Microsoft Sharepoint Server 2019 vulnerabilities
315 known vulnerabilities affecting microsoft/microsoft_sharepoint_server_2019.
Total CVEs
315
CISA KEV
12
actively exploited
Public exploits
15
Exploited in wild
20
Severity breakdown
CRITICAL12HIGH179MEDIUM117LOW7
Vulnerabilities
Page 11 of 16
CVE-2023-36894P4MEDIUMCVSS 6.5≥ 16.0.0, < 16.0.10401.200252023-08-08
CVE-2023-36894 [MEDIUM] CWE-200 CVE-2023-36894: Microsoft SharePoint Server Information Disclosure Vulnerability
Microsoft SharePoint Server Information Disclosure Vulnerability
nvd
CVE-2023-24954P4MEDIUMCVSS 6.5≥ 16.0.0, < 16.0.10398.200002023-05-09
CVE-2023-24954 [MEDIUM] CWE-918 CVE-2023-24954: Microsoft SharePoint Server Information Disclosure Vulnerability
Microsoft SharePoint Server Information Disclosure Vulnerability
nvd
CVE-2026-20943P4HIGHCVSS 7.0≥ 16.0.0, < 16.0.10417.200832026-01-13
CVE-2026-20943 [HIGH] CWE-426 CVE-2026-20943: Untrusted search path in Microsoft Office allows an unauthorized attacker to execute code locally.
Untrusted search path in Microsoft Office allows an unauthorized attacker to execute code locally.
nvd
CVE-2023-36890P4MEDIUMCVSS 6.5≥ 16.0.0, < 16.0.10401.200252023-08-08
CVE-2023-36890 [MEDIUM] CWE-284 CVE-2023-36890: Microsoft SharePoint Server Information Disclosure Vulnerability
Microsoft SharePoint Server Information Disclosure Vulnerability
nvd
CVE-2022-41122P3MEDIUMCVSS 6.5≥ 16.0.0, < 16.0.10390.200002022-11-09
CVE-2022-41122 [MEDIUM] CVE-2022-41122: Microsoft SharePoint Server Spoofing Vulnerability
Microsoft SharePoint Server Spoofing Vulnerability
nvd
CVE-2021-28478P4HIGHCVSS 7.1≥ 16.0.0, < 16.0.10374.200002021-05-11
CVE-2021-28478 [HIGH] CWE-290 CVE-2021-28478: Microsoft SharePoint Server Spoofing Vulnerability
Microsoft SharePoint Server Spoofing Vulnerability
nvd
CVE-2026-20959P3MEDIUMCVSS 5.4≥ 16.0.0, < 16.0.10417.200832026-01-13
CVE-2026-20959 [MEDIUM] CWE-79 CVE-2026-20959: Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Of
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
nvd
CVE-2021-24071P3MEDIUMCVSS 6.5≥ 16.0.0, < publication2021-02-25
CVE-2021-24071 [MEDIUM] CVE-2021-24071: Microsoft SharePoint Information Disclosure Vulnerability
Microsoft SharePoint Information Disclosure Vulnerability
nvd
CVE-2021-27052P3MEDIUMCVSS 6.5≥ 16.0.0, < publication2021-03-11
CVE-2021-27052 [MEDIUM] CVE-2021-27052: Microsoft SharePoint Server Information Disclosure Vulnerability
Microsoft SharePoint Server Information Disclosure Vulnerability
nvd
CVE-2021-31173P3MEDIUMCVSS 6.5≥ 16.0.0, < 16.0.10374.200002021-05-11
CVE-2021-31173 [MEDIUM] CWE-200 CVE-2021-31173: Microsoft SharePoint Server Information Disclosure Vulnerability
Microsoft SharePoint Server Information Disclosure Vulnerability
nvd
CVE-2025-21393P4MEDIUMCVSS 6.3≥ 16.0.0, < 16.0.10416.200412025-01-14
CVE-2025-21393 [MEDIUM] CWE-79 CVE-2025-21393: Microsoft SharePoint Server Spoofing Vulnerability
Microsoft SharePoint Server Spoofing Vulnerability
nvd
CVE-2021-26418P4HIGHCVSS 7.1≥ 16.0.0, < 16.0.10374.200002021-05-11
CVE-2021-26418 [HIGH] CWE-290 CVE-2021-26418: Microsoft SharePoint Server Spoofing Vulnerability
Microsoft SharePoint Server Spoofing Vulnerability
nvd
CVE-2024-49064P4MEDIUMCVSS 6.5≥ 16.0.0, < 16.0.10416.200262024-12-12
CVE-2024-49064 [MEDIUM] CWE-611 CVE-2024-49064: Microsoft SharePoint Information Disclosure Vulnerability
Microsoft SharePoint Information Disclosure Vulnerability
nvd
CVE-2025-59235P4HIGHCVSS 7.1≥ 16.0.0, < 16.0.10417.200592025-10-14
CVE-2025-59235 [HIGH] CWE-125 CVE-2025-59235: Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
nvd
CVE-2020-17015P4MEDIUMCVSS 6.5≥ 16.0.0, < publication2020-11-11
CVE-2020-17015 [MEDIUM] CVE-2020-17015: Microsoft SharePoint Server Spoofing Vulnerability
Microsoft SharePoint Server Spoofing Vulnerability
nvd
CVE-2023-33132P4MEDIUMCVSS 6.3≥ 16.0.0, < 16.0.10399.200052023-06-14
CVE-2023-33132 [MEDIUM] CWE-79 CVE-2023-33132: Microsoft SharePoint Server Spoofing Vulnerability
Microsoft SharePoint Server Spoofing Vulnerability
nvd
CVE-2020-1500P4MEDIUMCVSS 5.4≥ 16.0.0, < publication2020-08-17
CVE-2020-1500 [MEDIUM] CVE-2020-1500: A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specia
A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially crafted request to an affected SharePoint server.
The attacker who successfully exploited the vulnerability could then per
nvd
CVE-2020-1499P4MEDIUMCVSS 5.4≥ 16.0.0, < publication2020-08-17
CVE-2020-1499 [MEDIUM] CVE-2020-1499: A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specia
A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially crafted request to an affected SharePoint server.
The attacker who successfully exploited the vulnerability could then per
nvd
CVE-2020-1501P4MEDIUMCVSS 5.4≥ 16.0.0, < publication2020-08-17
CVE-2020-1501 [MEDIUM] CVE-2020-1501: A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specia
A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially crafted request to an affected SharePoint server.
The attacker who successfully exploited the vulnerability could then per
nvd
CVE-2026-47634P4MEDIUMCVSS 5.4≥ 16.0.0, < 16.0.10417.201532026-06-09
CVE-2026-47634 [MEDIUM] CWE-74 CVE-2026-47634: Improper neutralization of special elements in output used by a downstream component ('injection') i
Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
nvd