Microsoft Sharepoint Enterprise Server vulnerabilities
256 known vulnerabilities affecting microsoft/sharepoint_enterprise_server.
Total CVEs
256
CISA KEV
5
actively exploited
Public exploits
9
Exploited in wild
8
Severity breakdown
CRITICAL3HIGH120MEDIUM129LOW4
Vulnerabilities
Page 1 of 13
CVE-2019-0604P1CRITICALCVSS 9.8KEVPoCRansomwarev20162019-03-05
CVE-2019-0604 [CRITICAL] CVE-2019-0604: A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to chec
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0594.
nvd
CVE-2025-49706P1MEDIUMCVSS 6.5KEVPoCRansomwarev20162025-07-08
CVE-2025-49706 [MEDIUM] CWE-287 CVE-2025-49706: Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform sp
Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
nvd
CVE-2023-24955P1HIGHCVSS 7.2KEVPoCRansomwarev20162023-05-09
CVE-2023-24955 [HIGH] CWE-94 CVE-2023-24955: Microsoft SharePoint Server Remote Code Execution Vulnerability
Microsoft SharePoint Server Remote Code Execution Vulnerability
nvd
CVE-2020-1147P1HIGHCVSS 7.8KEVPoCv2013v20162020-07-14
CVE-2020-1147 [HIGH] CVE-2020-1147: A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Stu
A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of XML file input, aka '.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability'.
nvd
CVE-2017-11826P1HIGHCVSS 7.8KEVPoCv20162017-10-13
CVE-2017-11826 [HIGH] CWE-119 CVE-2017-11826: Microsoft Office 2010, SharePoint Enterprise Server 2010, SharePoint Server 2010, Web Applications,
Microsoft Office 2010, SharePoint Enterprise Server 2010, SharePoint Server 2010, Web Applications, Office Web Apps Server 2010 and 2013, Word Viewer, Word 2007, 2010, 2013 and 2016, Word Automation Services, and Office Online Server allow remote code execution when the software fails to properly handle objects in memory.
nvd
CVE-2023-21716P1CRITICALCVSS 9.8ExploitedPoCv2013v20162023-02-14
CVE-2023-21716 [CRITICAL] CWE-190 CVE-2023-21716: Microsoft Word Remote Code Execution Vulnerability
Microsoft Word Remote Code Execution Vulnerability
nvd
CVE-2022-22005P1HIGHCVSS 8.8Exploitedv20162022-02-09
CVE-2022-22005 [HIGH] CWE-502 CVE-2022-22005: Microsoft SharePoint Server Remote Code Execution Vulnerability
Microsoft SharePoint Server Remote Code Execution Vulnerability
nvd
CVE-2020-1210P1HIGHCVSS 8.8ExploitedRansomwarev2013v20162020-09-11
CVE-2020-1210 [HIGH] CWE-494 CVE-2020-1210: <p>A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to c
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the SharePoint application pool and the SharePoint server farm account.
Exploitation of this vulnerability r
nvd
CVE-2021-31181P2HIGHCVSS 8.8PoCv20162021-05-11
CVE-2021-31181 [HIGH] CWE-94 CVE-2021-31181: Microsoft SharePoint Remote Code Execution Vulnerability
Microsoft SharePoint Remote Code Execution Vulnerability
nvd
CVE-2020-16952P2HIGHCVSS 7.8PoCv20162020-10-16
CVE-2020-16952 [HIGH] CWE-346 CVE-2020-16952: <p>A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to c
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the SharePoint application pool and the SharePoint server farm account.
Exploitation of this vulnerability
nvd
CVE-2025-47166P2HIGHCVSS 8.8PoCv20162025-06-10
CVE-2025-47166 [HIGH] CWE-502 CVE-2025-47166: Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to ex
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
nvd
CVE-2022-38053P2HIGHCVSS 8.8v2013v20162022-10-11
CVE-2022-38053 [HIGH] CVE-2022-38053: Microsoft SharePoint Server Remote Code Execution Vulnerability
Microsoft SharePoint Server Remote Code Execution Vulnerability
nvd
CVE-2020-1181P2HIGHCVSS 8.8v20162020-06-09
CVE-2020-1181 [HIGH] CVE-2020-1181: A remote code execution vulnerability exists in Microsoft SharePoint Server when it fails to properl
A remote code execution vulnerability exists in Microsoft SharePoint Server when it fails to properly identify and filter unsafe ASP.Net web controls, aka 'Microsoft SharePoint Server Remote Code Execution Vulnerability'.
nvd
CVE-2022-35823P2HIGHCVSS 8.8v2013v20162022-09-13
CVE-2022-35823 [HIGH] CVE-2022-35823: Microsoft SharePoint Remote Code Execution Vulnerability
Microsoft SharePoint Remote Code Execution Vulnerability
nvd
CVE-2022-37961P2HIGHCVSS 8.8v2013v20162022-09-13
CVE-2022-37961 [HIGH] CVE-2022-37961: Microsoft SharePoint Server Remote Code Execution Vulnerability
Microsoft SharePoint Server Remote Code Execution Vulnerability
nvd
CVE-2021-40487P2HIGHCVSS 8.8v20162021-10-13
CVE-2021-40487 [HIGH] CWE-94 CVE-2021-40487: Microsoft SharePoint Server Remote Code Execution Vulnerability
Microsoft SharePoint Server Remote Code Execution Vulnerability
nvd
CVE-2020-0932P2HIGHCVSS 8.8v20162020-04-15
CVE-2020-0932 [HIGH] CVE-2020-0932: A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to chec
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0920, CVE-2020-0929, CVE-2020-0931, CVE-2020-0971, CVE-2020-0974.
nvd
CVE-2020-1439P2HIGHCVSS 8.8v2013v20162020-07-14
CVE-2020-1439 [HIGH] CWE-502 CVE-2020-1439: A remote code execution vulnerability exists in PerformancePoint Services for SharePoint Server when
A remote code execution vulnerability exists in PerformancePoint Services for SharePoint Server when the software fails to check the source markup of XML file input, aka 'PerformancePoint Services Remote Code Execution Vulnerability'.
nvd
CVE-2018-8284P2HIGHCVSS 8.1v2013-sp1v20162018-07-11
CVE-2018-8284 [HIGH] CWE-94 CVE-2018-8284: A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate inp
A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka ".NET Framework Remote Code Injection Vulnerability." This affects Microsoft .NET Framework 2.0, Microsoft .NET Framework 3.0, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.5.2, Microsoft .NET Framework 4.6, Mi
nvd
CVE-2025-47163P2HIGHCVSS 8.8v20162025-06-10
CVE-2025-47163 [HIGH] CWE-502 CVE-2025-47163: Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to ex
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
nvd
1 / 13Next →