Microsoft Sharepoint Server vulnerabilities
548 known vulnerabilities affecting microsoft/sharepoint_server.
Total CVEs
548
CISA KEV
18
actively exploited
Public exploits
29
Exploited in wild
31
Severity breakdown
CRITICAL44HIGH263MEDIUM226LOW15
Vulnerabilities
Page 15 of 28
CVE-2013-5059P3MEDIUMCVSS 6.8v2010v20132013-12-11
CVE-2013-5059 [MEDIUM] CWE-94 CVE-2013-5059: Microsoft SharePoint Server 2010 SP1 and SP2 and 2013, and Office Web Apps 2013, allows remote attac
Microsoft SharePoint Server 2010 SP1 and SP2 and 2013, and Office Web Apps 2013, allows remote attackers to execute arbitrary code via crafted page content, aka "SharePoint Page Content Vulnerabilities."
nvd
CVE-2021-31964P3HIGHCVSS 8.1v2016v20192021-06-08
CVE-2021-31964 [HIGH] CVE-2021-31964: Microsoft SharePoint Server Spoofing Vulnerability
Microsoft SharePoint Server Spoofing Vulnerability
nvd
CVE-2021-31948P3HIGHCVSS 8.1v20192021-06-08
CVE-2021-31948 [HIGH] CVE-2021-31948: Microsoft SharePoint Server Spoofing Vulnerability
Microsoft SharePoint Server Spoofing Vulnerability
nvd
CVE-2024-21426P3HIGHCVSS 7.8v2016v20192024-03-12
CVE-2024-21426 [HIGH] CWE-416 CVE-2024-21426: Microsoft SharePoint Server Remote Code Execution Vulnerability
Microsoft SharePoint Server Remote Code Execution Vulnerability
nvd
CVE-2025-29976P3HIGHCVSS 7.8fixed in 16.0.18526.20286v2016+1 more2025-05-13
CVE-2025-29976 [HIGH] CWE-269 CVE-2025-29976: Improper privilege management in Microsoft Office SharePoint allows an authorized attacker to elevat
Improper privilege management in Microsoft Office SharePoint allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-45471P3HIGHCVSS 7.8fixed in 16.0.19725.20384v2016+1 more2026-06-09
CVE-2026-45471 [HIGH] CWE-822 CVE-2026-45471: Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute co
Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.
nvd
CVE-2019-1034P3HIGHCVSS 7.8v2010v20192019-06-12
CVE-2019-1034 [HIGH] CVE-2019-1034: A remote code execution vulnerability exists in Microsoft Word software when it fails to properly ha
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could use a specially crafted file to perform actions in the security context of the current user. For example, the file could then take actions on behalf of the logged-on user with
nvd
CVE-2019-1201P3HIGHCVSS 7.8v2010v20192019-08-14
CVE-2019-1201 [HIGH] CVE-2019-1201: A remote code execution vulnerability exists in Microsoft Word software when it fails to properly ha
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could use a specially crafted file to perform actions in the security context of the current user. The file could then take actions on behalf of the logged-on user with the same perm
nvd
CVE-2008-1888P4MEDIUMCVSS 4.3PoCv2.02008-04-18
CVE-2008-1888 [MEDIUM] CWE-79 CVE-2008-1888: Cross-site scripting (XSS) vulnerability in Microsoft Windows SharePoint Services 2.0 allows remote
Cross-site scripting (XSS) vulnerability in Microsoft Windows SharePoint Services 2.0 allows remote attackers to inject arbitrary web script or HTML via the Picture Source (aka picture object source) field in the Rich Text Editor.
nvd
CVE-2021-1716P3HIGHCVSS 7.8v2010v20192021-01-12
CVE-2021-1716 [HIGH] CVE-2021-1716: Microsoft Word Remote Code Execution Vulnerability
Microsoft Word Remote Code Execution Vulnerability
nvd
CVE-2021-1715P3HIGHCVSS 7.8v2010v20192021-01-12
CVE-2021-1715 [HIGH] CWE-787 CVE-2021-1715: Microsoft Word Remote Code Execution Vulnerability
Microsoft Word Remote Code Execution Vulnerability
nvd
CVE-2020-17122P3HIGHCVSS 7.8v20102020-12-10
CVE-2020-17122 [HIGH] CVE-2020-17122: Microsoft Excel Remote Code Execution Vulnerability
Microsoft Excel Remote Code Execution Vulnerability
nvd
CVE-2020-17115P3HIGHCVSS 8.0v2016v20192020-12-10
CVE-2020-17115 [HIGH] CVE-2020-17115: Microsoft SharePoint Server Spoofing Vulnerability
Microsoft SharePoint Server Spoofing Vulnerability
nvd
CVE-2020-17089P3HIGHCVSS 8.0v2016v20192020-12-10
CVE-2020-17089 [HIGH] CVE-2020-17089: Microsoft SharePoint Elevation of Privilege Vulnerability
Microsoft SharePoint Elevation of Privilege Vulnerability
nvd
CVE-2016-7291P3HIGHCVSS 7.1v20102016-12-20
CVE-2016-7291 [HIGH] CVE-2016-7291: Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Office Compatibility Pack SP3, Word for Mac
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Office Compatibility Pack SP3, Word for Mac 2011, Word Automation Services on SharePoint Server 2010 SP2, and Office Web Apps 2010 SP2 allow remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read) via a crafted document, aka "Microsoft Office
nvd
CVE-2016-7290P3HIGHCVSS 7.1v20102016-12-20
CVE-2016-7290 [HIGH] CWE-125 CVE-2016-7290: Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Office Compatibility Pack SP3, Word for Mac
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Office Compatibility Pack SP3, Word for Mac 2011, Word Automation Services on SharePoint Server 2010 SP2, and Office Web Apps 2010 SP2 allow remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read) via a crafted document, aka "Microsoft
nvd
CVE-2016-7268P3HIGHCVSS 7.1v20102016-12-20
CVE-2016-7268 [HIGH] CWE-125 CVE-2016-7268: Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Office Compatibility Pack SP3, Word Viewer,
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Office Compatibility Pack SP3, Word Viewer, Word for Mac 2011, Word Automation Services on SharePoint Server 2010 SP2, and Office Web Apps 2010 SP2 allow remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read) via a crafted document, a
nvd
CVE-2013-3180P4MEDIUMCVSS 4.3v20102013-09-11
CVE-2013-3180 [MEDIUM] CWE-79 CVE-2013-3180: Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2010 SP1 and SP2 and 2013 al
Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2010 SP1 and SP2 and 2013 allows remote attackers to inject arbitrary web script or HTML via a crafted POST request, aka "POST XSS Vulnerability."
nvd
CVE-2021-1719P3HIGHCVSS 8.0v20192021-01-12
CVE-2021-1719 [HIGH] CWE-269 CVE-2021-1719: Microsoft SharePoint Elevation of Privilege Vulnerability
Microsoft SharePoint Elevation of Privilege Vulnerability
nvd
CVE-2021-1712P3HIGHCVSS 8.0v20192021-01-12
CVE-2021-1712 [HIGH] CWE-269 CVE-2021-1712: Microsoft SharePoint Elevation of Privilege Vulnerability
Microsoft SharePoint Elevation of Privilege Vulnerability
nvd