Microsoft Sharepoint Server vulnerabilities
548 known vulnerabilities affecting microsoft/sharepoint_server.
Total CVEs
548
CISA KEV
18
actively exploited
Public exploits
29
Exploited in wild
31
Severity breakdown
CRITICAL44HIGH263MEDIUM226LOW15
Vulnerabilities
Page 13 of 28
CVE-2026-55127P3HIGHCVSS 7.8fixed in 16.0.19725.20434v2016+1 more2026-07-14
CVE-2026-55127 [HIGH] CWE-122 CVE-2026-55127: Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-55055P3HIGHCVSS 7.8fixed in 16.0.19725.20434v2016+1 more2026-07-14
CVE-2026-55055 [HIGH] CWE-121 CVE-2026-55055: Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code
Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-55128P3HIGHCVSS 7.8fixed in 16.0.19725.20434v2016+1 more2026-07-14
CVE-2026-55128 [HIGH] CWE-416 CVE-2026-55128: Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-55130P3HIGHCVSS 7.8fixed in 16.0.19725.20434v2016+1 more2026-07-14
CVE-2026-55130 [HIGH] CWE-122 CVE-2026-55130: Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-55032P3HIGHCVSS 7.8fixed in 16.0.19725.20434v2016+1 more2026-07-14
CVE-2026-55032 [HIGH] CWE-416 CVE-2026-55032: Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-55134P3HIGHCVSS 7.8fixed in 16.0.19725.20434v2016+1 more2026-07-14
CVE-2026-55134 [HIGH] CWE-121 CVE-2026-55134: Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code
Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally.
nvd
CVE-2020-0852P3HIGHCVSS 7.8v20192020-03-12
CVE-2020-0852 [HIGH] CVE-2020-0852: A remote code execution vulnerability exists in Microsoft Word software when it fails to properly ha
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0850, CVE-2020-0851, CVE-2020-0855, CVE-2020-0892.
nvd
CVE-2020-0892P3HIGHCVSS 7.8v2010v20192020-03-12
CVE-2020-0892 [HIGH] CVE-2020-0892: A remote code execution vulnerability exists in Microsoft Word software when it fails to properly ha
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0850, CVE-2020-0851, CVE-2020-0852, CVE-2020-0855.
nvd
CVE-2020-17016P3HIGHCVSS 8.8v20192020-11-11
CVE-2020-17016 [HIGH] CVE-2020-17016: Microsoft SharePoint Server Spoofing Vulnerability
Microsoft SharePoint Server Spoofing Vulnerability
nvd
CVE-2026-55034P3HIGHCVSS 8.7fixed in 16.0.19725.20434v2016+1 more2026-07-14
CVE-2026-55034 [HIGH] CWE-79 CVE-2026-55034: Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Of
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
nvd
CVE-2021-31966P3HIGHCVSS 7.2v2013v2016+1 more2021-06-08
CVE-2021-31966 [HIGH] CVE-2021-31966: Microsoft SharePoint Server Remote Code Execution Vulnerability
Microsoft SharePoint Server Remote Code Execution Vulnerability
nvd
CVE-2024-49068P3HIGHCVSS 8.2v2016v20192024-12-12
CVE-2024-49068 [HIGH] CWE-284 CVE-2024-49068: Microsoft SharePoint Elevation of Privilege Vulnerability
Microsoft SharePoint Elevation of Privilege Vulnerability
nvd
CVE-2013-3895P3MEDIUMCVSS 6.8v2007v2010+1 more2013-10-09
CVE-2013-3895 [MEDIUM] CWE-264 CVE-2013-3895: Microsoft SharePoint Server 2007 SP3 and 2010 SP1 and SP2 allows remote attackers to conduct clickja
Microsoft SharePoint Server 2007 SP3 and 2010 SP1 and SP2 allows remote attackers to conduct clickjacking attacks via a crafted web page, aka "Parameter Injection Vulnerability."
nvd
CVE-2026-20951P3HIGHCVSS 7.8fixed in 16.0.19127.20442v2016+1 more2026-01-13
CVE-2026-20951 [HIGH] CWE-20 CVE-2026-20951: Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute
Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-55132P3HIGHCVSS 7.8fixed in 16.0.19725.20434v2016+1 more2026-07-14
CVE-2026-55132 [HIGH] CWE-415 CVE-2026-55132: Double free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
Double free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-59222P3HIGHCVSS 7.8v2016v20192025-10-14
CVE-2025-59222 [HIGH] CWE-416 CVE-2025-59222: Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
nvd
CVE-2016-3279P3MEDIUMCVSS 5.5v20102016-07-13
CVE-2016-3279 [MEDIUM] CWE-254 CVE-2016-3279: Microsoft Office 2010 SP2, Excel 2010 SP2, PowerPoint 2010 SP2, Word 2010 SP2, Excel 2013 SP1, Power
Microsoft Office 2010 SP2, Excel 2010 SP2, PowerPoint 2010 SP2, Word 2010 SP2, Excel 2013 SP1, PowerPoint 2013 SP1, Word 2013 SP1, Excel 2013 RT SP1, PowerPoint 2013 RT SP1, Word 2013 RT SP1, Excel 2016, Word 2016, Word Automation Services on SharePoint Server 2010 SP2, and Office Web Apps 2010 SP2 allow remote attackers to execute arbitrary code via
nvd
CVE-2025-64672P3CRITICALCVSS 9.0fixed in 16.0.19127.203782025-12-09
CVE-2025-64672 [CRITICAL] CWE-79 CVE-2025-64672: Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Of
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
nvd
CVE-2026-55021P3HIGHCVSS 8.7fixed in 16.0.19725.20434v2016+1 more2026-07-14
CVE-2026-55021 [HIGH] CWE-79 CVE-2026-55021: Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Of
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
nvd
CVE-2024-49070P3HIGHCVSS 7.4v2016v20192024-12-12
CVE-2024-49070 [HIGH] CWE-502 CVE-2024-49070: Microsoft SharePoint Remote Code Execution Vulnerability
Microsoft SharePoint Remote Code Execution Vulnerability
nvd