cbcvebase.

Microsoft Sharepoint Enterprise Server vulnerabilities

256 known vulnerabilities affecting microsoft/sharepoint_enterprise_server.

Total CVEs
256
CISA KEV
5
actively exploited
Public exploits
9
Exploited in wild
8
Severity breakdown
CRITICAL3HIGH120MEDIUM129LOW4

Vulnerabilities

Page 5 of 13
CVE-2023-21717P3HIGHCVSS 8.8v2013v20162023-02-14
CVE-2023-21717 [HIGH] CWE-284 CVE-2023-21717: Microsoft SharePoint Server Elevation of Privilege Vulnerability Microsoft SharePoint Server Elevation of Privilege Vulnerability
nvd
CVE-2018-0917P3HIGHCVSS 8.8v20162018-03-14
CVE-2018-0917 [HIGH] CVE-2018-0917: Microsoft SharePoint Enterprise Server 2016 allows an elevation of privilege vulnerability to due ho Microsoft SharePoint Enterprise Server 2016 allows an elevation of privilege vulnerability to due how specially crafted web requests are sanitized, aka "Microsoft SharePoint Elevation of Privilege Vulnerability". This CVE is unique from CVE-2018-0909, CVE-2018-0910. CVE-2018-0911, CVE-2018-0912, CVE-2018-0913 CVE-2018-0914, CVE-2018-0915, CVE-2018-0916, CVE-201
nvd
CVE-2018-0911P3HIGHCVSS 8.8v20162018-03-14
CVE-2018-0911 [HIGH] CVE-2018-0911: Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation of privilege vulnerability to due how specially crafted web requests are sanitized, aka "Microsoft SharePoint Elevation of Privilege Vulnerability". This CVE is unique from CVE-2018-0909, CVE-2018-0910, CVE-2018-0912, CVE-2018-0913, CVE-2018-0914, CVE-2018-0915,
nvd
CVE-2018-0921P3HIGHCVSS 8.8v20162018-03-14
CVE-2018-0921 [HIGH] CVE-2018-0921: Microsoft SharePoint Enterprise Server 2016 allows an elevation of privilege vulnerability to due ho Microsoft SharePoint Enterprise Server 2016 allows an elevation of privilege vulnerability to due how specially crafted web requests are sanitized, aka "Microsoft SharePoint Elevation of Privilege Vulnerability". This CVE is unique from CVE-2018-0909, CVE-2018-0910. CVE-2018-0911, CVE-2018-0912, CVE-2018-0913 CVE-2018-0914, CVE-2018-0915, CVE-2018-0916, CVE-201
nvd
CVE-2018-0923P3HIGHCVSS 8.8v2013v20162018-03-14
CVE-2018-0923 [HIGH] CVE-2018-0923: Microsoft SharePoint Enterprise Server 2016 allows an elevation of privilege vulnerability to due ho Microsoft SharePoint Enterprise Server 2016 allows an elevation of privilege vulnerability to due how specially crafted web requests are sanitized, aka "Microsoft SharePoint Elevation of Privilege Vulnerability". This CVE is unique from CVE-2018-0909, CVE-2018-0910. CVE-2018-0911, CVE-2018-0912, CVE-2018-0913 CVE-2018-0914, CVE-2018-0915, CVE-2018-0916, CVE-201
nvd
CVE-2018-0914P3HIGHCVSS 8.8v20162018-03-14
CVE-2018-0914 [HIGH] CVE-2018-0914: Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation of privilege vulnerability to due how specially crafted web requests are sanitized, aka "Microsoft SharePoint Elevation of Privilege Vulnerability". This CVE is unique from CVE-2018-0909, CVE-2018-0910. CVE-2018-0911, CVE-2018-0912, CVE-2018-0913, CVE-2018-0915,
nvd
CVE-2018-0947P3HIGHCVSS 8.8v2013v20162018-03-14
CVE-2018-0947 [HIGH] CVE-2018-0947: Microsoft SharePoint Foundation 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an el Microsoft SharePoint Foundation 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation of privilege vulnerability to due how specially crafted web requests are sanitized, aka "Microsoft SharePoint Elevation of Privilege Vulnerability". This CVE is unique from CVE-2018-0909, CVE-2018-0910. CVE-2018-0911, CVE-2018-0912, CVE-2018-0913 CVE-2018
nvd
CVE-2018-0909P3HIGHCVSS 8.8v20162018-03-14
CVE-2018-0909 [HIGH] CWE-79 CVE-2018-0909: Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation of privilege vulnerability to due how specially crafted web requests are sanitized, aka "Microsoft SharePoint Elevation of Privilege Vulnerability". This CVE is unique from CVE-2018-0910, CVE-2018-0911, CVE-2018-0912, CVE-2018-0913, CVE-2018-0914, CVE-201
nvd
CVE-2018-0944P3HIGHCVSS 8.8v20162018-03-14
CVE-2018-0944 [HIGH] CVE-2018-0944: Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allows an elevatio Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allows an elevation of privilege vulnerability to due how specially crafted web requests are sanitized, aka "Microsoft SharePoint Elevation of Privilege Vulnerability". This CVE is unique from CVE-2018-0909, CVE-2018-0910. CVE-2018-0911, CVE-2018-0912, CVE-2018-0913 CVE-2018-0914,
nvd
CVE-2018-0912P3HIGHCVSS 8.8v20162018-03-14
CVE-2018-0912 [HIGH] CVE-2018-0912: Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation of privilege vulnerability to due how specially crafted web requests are sanitized, aka "Microsoft SharePoint Elevation of Privilege Vulnerability". This CVE is unique from CVE-2018-0909, CVE-2018-0910. CVE-2018-0911, CVE-2018-0913, CVE-2018-0914, CVE-2018-0915,
nvd
CVE-2018-0910P3HIGHCVSS 8.8v20162018-03-14
CVE-2018-0910 [HIGH] CVE-2018-0910: Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation of privilege vulnerability to due how specially crafted web requests are sanitized, aka "Microsoft SharePoint Elevation of Privilege Vulnerability". This CVE is unique from CVE-2018-0909, CVE-2018-0911, CVE-2018-0912, CVE-2018-0913, CVE-2018-0914, CVE-2018-0915,
nvd
CVE-2018-0915P3HIGHCVSS 8.8v20162018-03-14
CVE-2018-0915 [HIGH] CVE-2018-0915: Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation of privilege vulnerability to due how specially crafted web requests are sanitized, aka "Microsoft SharePoint Elevation of Privilege Vulnerability". This CVE is unique from CVE-2018-0909, CVE-2018-0910. CVE-2018-0911, CVE-2018-0912, CVE-2018-0914, CVE-2018-0916,
nvd
CVE-2018-0913P3HIGHCVSS 8.8v20162018-03-14
CVE-2018-0913 [HIGH] CVE-2018-0913: Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation of privilege vulnerability to due how specially crafted web requests are sanitized, aka "Microsoft SharePoint Elevation of Privilege Vulnerability". This CVE is unique from CVE-2018-0909, CVE-2018-0910. CVE-2018-0911, CVE-2018-0913, CVE-2018-0914, CVE-2018-0915,
nvd
CVE-2018-0916P3HIGHCVSS 8.8v20162018-03-14
CVE-2018-0916 [HIGH] CVE-2018-0916: Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation Microsoft Project Server 2013 SP1 and Microsoft SharePoint Enterprise Server 2016 allow an elevation of privilege vulnerability to due how specially crafted web requests are sanitized, aka "Microsoft SharePoint Elevation of Privilege Vulnerability". This CVE is unique from CVE-2018-0909, CVE-2018-0910. CVE-2018-0911, CVE-2018-0912, CVE-2018-0913 CVE-2018-0914,
nvd
CVE-2020-1295P3HIGHCVSS 8.8v2013v20162020-06-09
CVE-2020-1295 [HIGH] CVE-2020-1295: An elevation of privilege vulnerability exists in Microsoft SharePoint, aka 'Microsoft SharePoint El An elevation of privilege vulnerability exists in Microsoft SharePoint, aka 'Microsoft SharePoint Elevation of Privilege Vulnerability'.
nvd
CVE-2020-0980P3HIGHCVSS 7.8v2013v20162020-04-15
CVE-2020-0980 [HIGH] CVE-2020-0980: A remote code execution vulnerability exists in Microsoft Word software when it fails to properly ha A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'.
nvd
CVE-2025-53733P3HIGHCVSS 8.4v20162025-08-12
CVE-2025-53733 [HIGH] CWE-681 CVE-2025-53733: Incorrect conversion between numeric types in Microsoft Office Word allows an unauthorized attacker Incorrect conversion between numeric types in Microsoft Office Word allows an unauthorized attacker to execute code locally.
nvd
CVE-2020-0892P3HIGHCVSS 7.8v2013v20162020-03-12
CVE-2020-0892 [HIGH] CVE-2020-0892: A remote code execution vulnerability exists in Microsoft Word software when it fails to properly ha A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0850, CVE-2020-0851, CVE-2020-0852, CVE-2020-0855.
nvd
CVE-2020-17016P3HIGHCVSS 8.8v20162020-11-11
CVE-2020-17016 [HIGH] CVE-2020-17016: Microsoft SharePoint Server Spoofing Vulnerability Microsoft SharePoint Server Spoofing Vulnerability
nvd
CVE-2025-47994P3HIGHCVSS 8.6v20162025-07-08
CVE-2025-47994 [HIGH] CWE-502 CVE-2025-47994: Deserialization of untrusted data in Microsoft Office allows an unauthorized attacker to elevate pri Deserialization of untrusted data in Microsoft Office allows an unauthorized attacker to elevate privileges locally.
nvd
Microsoft Sharepoint Enterprise Server vulnerabilities | cvebase