Microsoft Sharepoint Server Subscription Edition vulnerabilities
189 known vulnerabilities affecting microsoft/microsoft_sharepoint_server_subscription_edition.
Total CVEs
189
CISA KEV
10
actively exploited
Public exploits
10
Exploited in wild
16
Severity breakdown
CRITICAL9HIGH109MEDIUM67LOW4
Vulnerabilities
Page 3 of 10
CVE-2026-26106P2HIGHCVSS 8.8≥ 16.0.0, < 16.0.19725.200762026-03-10
CVE-2026-26106 [HIGH] CWE-20 CVE-2026-26106: Improper input validation in Microsoft Office SharePoint allows an authorized attacker to execute co
Improper input validation in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
nvd
CVE-2025-59228P2HIGHCVSS 8.8≥ 16.0.0, < 16.0.19127.202622025-10-14
CVE-2025-59228 [HIGH] CWE-20 CVE-2025-59228: Improper input validation in Microsoft Office SharePoint allows an authorized attacker to execute co
Improper input validation in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
nvd
CVE-2025-59237P2HIGHCVSS 8.8≥ 16.0.0, < 16.0.19127.202622025-10-14
CVE-2025-59237 [HIGH] CWE-502 CVE-2025-59237: Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to ex
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
nvd
CVE-2023-33160P2HIGHCVSS 8.8≥ 16.0.0, < 16.0.16130.206422023-07-11
CVE-2023-33160 [HIGH] CWE-502 CVE-2023-33160: Microsoft SharePoint Server Remote Code Execution Vulnerability
Microsoft SharePoint Server Remote Code Execution Vulnerability
nvd
CVE-2026-35439P2HIGHCVSS 8.8≥ 16.0.0, < 16.0.19725.202802026-05-12
CVE-2026-35439 [HIGH] CWE-502 CVE-2026-35439: Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to ex
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
nvd
CVE-2026-45454P2HIGHCVSS 8.8≥ 16.0.0, < 16.0.19725.203842026-06-09
CVE-2026-45454 [HIGH] CWE-22 CVE-2026-45454: Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Office S
Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
nvd
CVE-2025-29793P3HIGHCVSS 7.2≥ 16.0.0, < 16.0.18526.201722025-04-08
CVE-2025-29793 [HIGH] CWE-502 CVE-2025-29793: Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to ex
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
nvd
CVE-2026-33110P2HIGHCVSS 8.8≥ 16.0.0, < 16.0.19725.202802026-05-12
CVE-2026-33110 [HIGH] CWE-502 CVE-2026-33110: Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to ex
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
nvd
CVE-2026-40357P2HIGHCVSS 8.8≥ 16.0.0, < 16.0.19725.202802026-05-12
CVE-2026-40357 [HIGH] CWE-502 CVE-2026-40357: Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to ex
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
nvd
CVE-2026-55052P2HIGHCVSS 8.8≥ 16.0.0, < 16.0.19725.204342026-07-14
CVE-2026-55052 [HIGH] CWE-862 CVE-2026-55052: Missing authorization in Microsoft Office SharePoint allows an authorized attacker to elevate privil
Missing authorization in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2023-33134P3HIGHCVSS 8.8≥ 16.0.0, < 16.0.16130.206422023-07-11
CVE-2023-33134 [HIGH] CWE-502 CVE-2023-33134: Microsoft SharePoint Server Remote Code Execution Vulnerability
Microsoft SharePoint Server Remote Code Execution Vulnerability
nvd
CVE-2026-40365P3HIGHCVSS 8.8≥ 16.0.0, < 16.0.19725.202802026-05-12
CVE-2026-40365 [HIGH] CWE-1220 CVE-2026-40365: Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to ex
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
nvd
CVE-2025-49701P2HIGHCVSS 8.8≥ 16.0.0, < 16.0.18526.204242025-07-08
CVE-2025-49701 [HIGH] CWE-285 CVE-2025-49701: Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code
Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
nvd
CVE-2023-21744P3HIGHCVSS 8.8≥ 16.0.0, < 16.0.15601.204182023-01-10
CVE-2023-21744 [HIGH] CWE-502 CVE-2023-21744: Microsoft SharePoint Server Remote Code Execution Vulnerability
Microsoft SharePoint Server Remote Code Execution Vulnerability
nvd
CVE-2022-30158P3HIGHCVSS 8.8≥ 16.0.0, < 16.0.14931.204182022-06-15
CVE-2022-30158 [HIGH] CVE-2022-30158: Microsoft SharePoint Server Remote Code Execution Vulnerability
Microsoft SharePoint Server Remote Code Execution Vulnerability
nvd
CVE-2022-44693P3HIGHCVSS 8.8≥ 16.0.0, < 15601.203162022-12-13
CVE-2022-44693 [HIGH] CVE-2022-44693: Microsoft SharePoint Server Remote Code Execution Vulnerability
Microsoft SharePoint Server Remote Code Execution Vulnerability
nvd
CVE-2022-21837P3HIGHCVSS 8.8≥ 16.0.0, < 16.0.14326.207142022-01-11
CVE-2022-21837 [HIGH] CVE-2022-21837: Microsoft SharePoint Server Remote Code Execution Vulnerability
Microsoft SharePoint Server Remote Code Execution Vulnerability
nvd
CVE-2021-42309P3HIGHCVSS 8.8≥ 16.0.0, < 16.0.14326.206202021-12-15
CVE-2021-42309 [HIGH] CWE-94 CVE-2021-42309: Microsoft SharePoint Server Remote Code Execution Vulnerability
Microsoft SharePoint Server Remote Code Execution Vulnerability
nvd
CVE-2022-41038P3HIGHCVSS 8.8≥ 16.0.0, < 16.0.15601.201582022-10-11
CVE-2022-41038 [HIGH] CVE-2022-41038: Microsoft SharePoint Server Remote Code Execution Vulnerability
Microsoft SharePoint Server Remote Code Execution Vulnerability
nvd
CVE-2022-38009P3HIGHCVSS 8.8≥ 16.0.0, < 16.0.15601.200522022-09-13
CVE-2022-38009 [HIGH] CVE-2022-38009: Microsoft SharePoint Server Remote Code Execution Vulnerability
Microsoft SharePoint Server Remote Code Execution Vulnerability
nvd