Microsoft Sharepoint Enterprise Server vulnerabilities
256 known vulnerabilities affecting microsoft/sharepoint_enterprise_server.
Total CVEs
256
CISA KEV
5
actively exploited
Public exploits
9
Exploited in wild
8
Severity breakdown
CRITICAL3HIGH120MEDIUM129LOW4
Vulnerabilities
Page 5 of 13
CVE-2023-21717P3HIGHCVSS 8.8v2013v20162023-02-14
CVE-2023-21717 [HIGH] CWE-284 CVE-2023-21717: Microsoft SharePoint Server Elevation of Privilege Vulnerability
Microsoft SharePoint Server Elevation of Privilege Vulnerability
nvd
CVE-2018-0917P3HIGHCVSS 8.8v20162018-03-14
CVE-2018-0917 [HIGH] CVE-2018-0917: Microsoft SharePoint Enterprise Server 2016 allows an elevation of privilege vulnerability to due ho
Microsoft SharePoint Enterprise Server 2016 allows an elevation of privilege vulnerability to due how specially crafted web requests are sanitized, aka "Microsoft SharePoint Elevation of Privilege Vulnerability". This CVE is unique from CVE-2018-0909, CVE-2018-0910. CVE-2018-0911, CVE-2018-0912, CVE-2018-0913 CVE-2018-0914, CVE-2018-0915, CVE-2018-0916, CVE-201
nvd
CVE-2018-0911P3HIGHCVSS 8.8v20162018-03-14
CVE-2018-0911 [HIGH] CVE-2018-0911: Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation
Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation of privilege vulnerability to due how specially crafted web requests are sanitized, aka "Microsoft SharePoint Elevation of Privilege Vulnerability". This CVE is unique from CVE-2018-0909, CVE-2018-0910, CVE-2018-0912, CVE-2018-0913, CVE-2018-0914, CVE-2018-0915,
nvd
CVE-2018-0921P3HIGHCVSS 8.8v20162018-03-14
CVE-2018-0921 [HIGH] CVE-2018-0921: Microsoft SharePoint Enterprise Server 2016 allows an elevation of privilege vulnerability to due ho
Microsoft SharePoint Enterprise Server 2016 allows an elevation of privilege vulnerability to due how specially crafted web requests are sanitized, aka "Microsoft SharePoint Elevation of Privilege Vulnerability". This CVE is unique from CVE-2018-0909, CVE-2018-0910. CVE-2018-0911, CVE-2018-0912, CVE-2018-0913 CVE-2018-0914, CVE-2018-0915, CVE-2018-0916, CVE-201
nvd
CVE-2018-0923P3HIGHCVSS 8.8v2013v20162018-03-14
CVE-2018-0923 [HIGH] CVE-2018-0923: Microsoft SharePoint Enterprise Server 2016 allows an elevation of privilege vulnerability to due ho
Microsoft SharePoint Enterprise Server 2016 allows an elevation of privilege vulnerability to due how specially crafted web requests are sanitized, aka "Microsoft SharePoint Elevation of Privilege Vulnerability". This CVE is unique from CVE-2018-0909, CVE-2018-0910. CVE-2018-0911, CVE-2018-0912, CVE-2018-0913 CVE-2018-0914, CVE-2018-0915, CVE-2018-0916, CVE-201
nvd
CVE-2018-0914P3HIGHCVSS 8.8v20162018-03-14
CVE-2018-0914 [HIGH] CVE-2018-0914: Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation
Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation of privilege vulnerability to due how specially crafted web requests are sanitized, aka "Microsoft SharePoint Elevation of Privilege Vulnerability". This CVE is unique from CVE-2018-0909, CVE-2018-0910. CVE-2018-0911, CVE-2018-0912, CVE-2018-0913, CVE-2018-0915,
nvd
CVE-2018-0947P3HIGHCVSS 8.8v2013v20162018-03-14
CVE-2018-0947 [HIGH] CVE-2018-0947: Microsoft SharePoint Foundation 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an el
Microsoft SharePoint Foundation 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation of privilege vulnerability to due how specially crafted web requests are sanitized, aka "Microsoft SharePoint Elevation of Privilege Vulnerability". This CVE is unique from CVE-2018-0909, CVE-2018-0910. CVE-2018-0911, CVE-2018-0912, CVE-2018-0913 CVE-2018
nvd
CVE-2018-0909P3HIGHCVSS 8.8v20162018-03-14
CVE-2018-0909 [HIGH] CWE-79 CVE-2018-0909: Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation
Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation of privilege vulnerability to due how specially crafted web requests are sanitized, aka "Microsoft SharePoint Elevation of Privilege Vulnerability". This CVE is unique from CVE-2018-0910, CVE-2018-0911, CVE-2018-0912, CVE-2018-0913, CVE-2018-0914, CVE-201
nvd
CVE-2018-0944P3HIGHCVSS 8.8v20162018-03-14
CVE-2018-0944 [HIGH] CVE-2018-0944: Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allows an elevatio
Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allows an elevation of privilege vulnerability to due how specially crafted web requests are sanitized, aka "Microsoft SharePoint Elevation of Privilege Vulnerability". This CVE is unique from CVE-2018-0909, CVE-2018-0910. CVE-2018-0911, CVE-2018-0912, CVE-2018-0913 CVE-2018-0914,
nvd
CVE-2018-0912P3HIGHCVSS 8.8v20162018-03-14
CVE-2018-0912 [HIGH] CVE-2018-0912: Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation
Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation of privilege vulnerability to due how specially crafted web requests are sanitized, aka "Microsoft SharePoint Elevation of Privilege Vulnerability". This CVE is unique from CVE-2018-0909, CVE-2018-0910. CVE-2018-0911, CVE-2018-0913, CVE-2018-0914, CVE-2018-0915,
nvd
CVE-2018-0910P3HIGHCVSS 8.8v20162018-03-14
CVE-2018-0910 [HIGH] CVE-2018-0910: Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation
Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation of privilege vulnerability to due how specially crafted web requests are sanitized, aka "Microsoft SharePoint Elevation of Privilege Vulnerability". This CVE is unique from CVE-2018-0909, CVE-2018-0911, CVE-2018-0912, CVE-2018-0913, CVE-2018-0914, CVE-2018-0915,
nvd
CVE-2018-0915P3HIGHCVSS 8.8v20162018-03-14
CVE-2018-0915 [HIGH] CVE-2018-0915: Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation
Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation of privilege vulnerability to due how specially crafted web requests are sanitized, aka "Microsoft SharePoint Elevation of Privilege Vulnerability". This CVE is unique from CVE-2018-0909, CVE-2018-0910. CVE-2018-0911, CVE-2018-0912, CVE-2018-0914, CVE-2018-0916,
nvd
CVE-2018-0913P3HIGHCVSS 8.8v20162018-03-14
CVE-2018-0913 [HIGH] CVE-2018-0913: Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation
Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation of privilege vulnerability to due how specially crafted web requests are sanitized, aka "Microsoft SharePoint Elevation of Privilege Vulnerability". This CVE is unique from CVE-2018-0909, CVE-2018-0910. CVE-2018-0911, CVE-2018-0913, CVE-2018-0914, CVE-2018-0915,
nvd
CVE-2018-0916P3HIGHCVSS 8.8v20162018-03-14
CVE-2018-0916 [HIGH] CVE-2018-0916: Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation
Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation of privilege vulnerability to due how specially crafted web requests are sanitized, aka "Microsoft SharePoint Elevation of Privilege Vulnerability". This CVE is unique from CVE-2018-0909, CVE-2018-0910. CVE-2018-0911, CVE-2018-0912, CVE-2018-0913 CVE-2018-0914,
nvd
CVE-2020-1295P3HIGHCVSS 8.8v2013v20162020-06-09
CVE-2020-1295 [HIGH] CVE-2020-1295: An elevation of privilege vulnerability exists in Microsoft SharePoint, aka 'Microsoft SharePoint El
An elevation of privilege vulnerability exists in Microsoft SharePoint, aka 'Microsoft SharePoint Elevation of Privilege Vulnerability'.
nvd
CVE-2020-0980P3HIGHCVSS 7.8v2013v20162020-04-15
CVE-2020-0980 [HIGH] CVE-2020-0980: A remote code execution vulnerability exists in Microsoft Word software when it fails to properly ha
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'.
nvd
CVE-2025-53733P3HIGHCVSS 8.4v20162025-08-12
CVE-2025-53733 [HIGH] CWE-681 CVE-2025-53733: Incorrect conversion between numeric types in Microsoft Office Word allows an unauthorized attacker
Incorrect conversion between numeric types in Microsoft Office Word allows an unauthorized attacker to execute code locally.
nvd
CVE-2020-0892P3HIGHCVSS 7.8v2013v20162020-03-12
CVE-2020-0892 [HIGH] CVE-2020-0892: A remote code execution vulnerability exists in Microsoft Word software when it fails to properly ha
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0850, CVE-2020-0851, CVE-2020-0852, CVE-2020-0855.
nvd
CVE-2020-17016P3HIGHCVSS 8.8v20162020-11-11
CVE-2020-17016 [HIGH] CVE-2020-17016: Microsoft SharePoint Server Spoofing Vulnerability
Microsoft SharePoint Server Spoofing Vulnerability
nvd
CVE-2025-47994P3HIGHCVSS 8.6v20162025-07-08
CVE-2025-47994 [HIGH] CWE-502 CVE-2025-47994: Deserialization of untrusted data in Microsoft Office allows an unauthorized attacker to elevate pri
Deserialization of untrusted data in Microsoft Office allows an unauthorized attacker to elevate privileges locally.
nvd