Microsoft Sharepoint Server 2019 vulnerabilities
315 known vulnerabilities affecting microsoft/microsoft_sharepoint_server_2019.
Total CVEs
315
CISA KEV
12
actively exploited
Public exploits
15
Exploited in wild
20
Severity breakdown
CRITICAL12HIGH179MEDIUM117LOW7
Vulnerabilities
Page 13 of 16
CVE-2019-1032P4MEDIUMCVSS 5.4≥ 16.0.0, < publication2019-06-12
CVE-2019-1032 [MEDIUM] CWE-79 CVE-2019-1032: A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially crafted request to an affected SharePoint server.
The attacker who successfully exploited the vul
nvd
CVE-2019-1033P4MEDIUMCVSS 5.4≥ 16.0.0, < publication2019-06-12
CVE-2019-1033 [MEDIUM] CWE-79 CVE-2019-1033: A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially crafted request to an affected SharePoint server.
The attacker who successfully exploited the vul
nvd
CVE-2019-1036P4MEDIUMCVSS 5.4≥ 16.0.0, < publication2019-06-12
CVE-2019-1036 [MEDIUM] CWE-79 CVE-2019-1036: A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially crafted request to an affected SharePoint server.
The attacker who successfully exploited the vul
nvd
CVE-2019-1031P4MEDIUMCVSS 5.4≥ 16.0.0, < publication2019-06-12
CVE-2019-1031 [MEDIUM] CWE-79 CVE-2019-1031: A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially crafted request to an affected SharePoint server.
The attacker who successfully exploited the vul
nvd
CVE-2020-1514P4MEDIUMCVSS 5.4≥ 16.0.0, < publication2020-09-11
CVE-2020-1514 [MEDIUM] CWE-79 CVE-2020-1514: <p>A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not prope
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially crafted request to an affected SharePoint server.
The attacker who successfully exploited the vul
nvd
CVE-2020-1227P4MEDIUMCVSS 5.4≥ 16.0.0, < publication2020-09-11
CVE-2020-1227 [MEDIUM] CWE-79 CVE-2020-1227: <p>A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not prope
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially crafted request to an affected SharePoint server.
The attacker who successfully exploited the vul
nvd
CVE-2020-16944P4MEDIUMCVSS 5.4≥ 16.0.0, < publication2020-10-16
CVE-2020-16944 [MEDIUM] CWE-79 CVE-2020-16944: <p>This vulnerability is caused when SharePoint Server does not properly sanitize a specially crafte
This vulnerability is caused when SharePoint Server does not properly sanitize a specially crafted request to an affected SharePoint server.
An authenticated attacker could exploit this vulnerability by sending a specially crafted request to an affected SharePoint server. The attacker who successfully exploited this vulnerability could then perform c
nvd
CVE-2020-16946P4MEDIUMCVSS 5.4≥ 16.0.0, < publication2020-10-16
CVE-2020-16946 [MEDIUM] CWE-79 CVE-2020-16946: <p>A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not prope
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially crafted request to an affected SharePoint server.
The attacker who successfully exploited the v
nvd
CVE-2020-1580P4MEDIUMCVSS 5.4≥ 16.0.0, < publication2020-08-17
CVE-2020-1580 [MEDIUM] CWE-79 CVE-2020-1580: A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially crafted request to an affected SharePoint server.
The attacker who successfully exploited the vul
nvd
CVE-2026-45481P4MEDIUMCVSS 5.4≥ 16.0.0, < 16.0.10417.201532026-06-09
CVE-2026-45481 [MEDIUM] CWE-79 CVE-2026-45481: Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Of
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
nvd
CVE-2021-43242P4MEDIUMCVSS 5.7≥ 16.0.0, < 16.0.10381.200012021-12-15
CVE-2021-43242 [MEDIUM] CVE-2021-43242: Microsoft SharePoint Server Spoofing Vulnerability
Microsoft SharePoint Server Spoofing Vulnerability
nvd
CVE-2021-1717P4MEDIUMCVSS 5.4≥ 16.0.0, < publication2021-01-12
CVE-2021-1717 [MEDIUM] CVE-2021-1717: Microsoft SharePoint Server Spoofing Vulnerability
Microsoft SharePoint Server Spoofing Vulnerability
nvd
CVE-2021-1641P4MEDIUMCVSS 5.4≥ 16.0.0, < publication2021-01-12
CVE-2021-1641 [MEDIUM] CVE-2021-1641: Microsoft SharePoint Server Spoofing Vulnerability
Microsoft SharePoint Server Spoofing Vulnerability
nvd
CVE-2020-17060P4MEDIUMCVSS 5.4≥ 16.0.0, < publication2020-11-11
CVE-2020-17060 [MEDIUM] CVE-2020-17060: Microsoft SharePoint Server Spoofing Vulnerability
Microsoft SharePoint Server Spoofing Vulnerability
nvd
CVE-2021-34517P4MEDIUMCVSS 5.3≥ 16.0.0, < 16.0.10376.200012021-07-14
CVE-2021-34517 [MEDIUM] CVE-2021-34517: Microsoft SharePoint Server Spoofing Vulnerability
Microsoft SharePoint Server Spoofing Vulnerability
nvd
CVE-2023-21743P4MEDIUMCVSS 5.3≥ 16.0.0, < 16.0.10394.200212023-01-10
CVE-2023-21743 [MEDIUM] CWE-306 CVE-2023-21743: Microsoft SharePoint Server Security Feature Bypass Vulnerability
Microsoft SharePoint Server Security Feature Bypass Vulnerability
nvd
CVE-2026-55027P4MEDIUMCVSS 5.5≥ 16.0.0, < 16.0.10417.201752026-07-14
CVE-2026-55027 [MEDIUM] CWE-125 CVE-2026-55027: Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information local
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
nvd
CVE-2026-55023P4MEDIUMCVSS 5.5≥ 16.0.0, < 16.0.10417.201752026-07-14
CVE-2026-55023 [MEDIUM] CWE-125 CVE-2026-55023: Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information local
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
nvd
CVE-2026-55047P4MEDIUMCVSS 5.5≥ 16.0.0, < 16.0.10417.201752026-07-14
CVE-2026-55047 [MEDIUM] CWE-125 CVE-2026-55047: Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information local
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
nvd
CVE-2026-56192P4MEDIUMCVSS 5.5≥ 16.0.0, < 16.0.10417.201752026-07-14
CVE-2026-56192 [MEDIUM] CWE-125 CVE-2026-56192: Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information local
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
nvd