Microsoft Sharepoint Server vulnerabilities
548 known vulnerabilities affecting microsoft/sharepoint_server.
Total CVEs
548
CISA KEV
18
actively exploited
Public exploits
29
Exploited in wild
31
Severity breakdown
CRITICAL44HIGH263MEDIUM226LOW15
Vulnerabilities
Page 2 of 28
CVE-2023-21742P1HIGHCVSS 8.8ExploitedPoCv2013v2016+1 more2023-01-10
CVE-2023-21742 [HIGH] CWE-284 CVE-2023-21742: Microsoft SharePoint Server Remote Code Execution Vulnerability
Microsoft SharePoint Server Remote Code Execution Vulnerability
nvd
CVE-2010-0817P2MEDIUMCVSS 4.3ExploitedPoCv20072010-04-29
CVE-2010-0817 [MEDIUM] CWE-79 CVE-2010-0817: Cross-site scripting (XSS) vulnerability in _layouts/help.aspx in Microsoft SharePoint Server 2007 1
Cross-site scripting (XSS) vulnerability in _layouts/help.aspx in Microsoft SharePoint Server 2007 12.0.0.6421 and possibly earlier, and SharePoint Services 3.0 SP1 and SP2, versions, allows remote attackers to inject arbitrary web script or HTML via the cid0 parameter.
nvd
CVE-2022-22005P1HIGHCVSS 8.8Exploitedv20192022-02-09
CVE-2022-22005 [HIGH] CWE-502 CVE-2022-22005: Microsoft SharePoint Server Remote Code Execution Vulnerability
Microsoft SharePoint Server Remote Code Execution Vulnerability
nvd
CVE-2024-38023P2HIGHCVSS 7.2Exploitedv2016v20192024-07-09
CVE-2024-38023 [HIGH] CWE-502 CVE-2024-38023: Microsoft SharePoint Server Remote Code Execution Vulnerability
Microsoft SharePoint Server Remote Code Execution Vulnerability
nvd
CVE-2020-1210P1HIGHCVSS 8.8ExploitedRansomwarev20192020-09-11
CVE-2020-1210 [HIGH] CWE-494 CVE-2020-1210: <p>A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to c
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the SharePoint application pool and the SharePoint server farm account.
Exploitation of this vulnerability r
nvd
CVE-2024-38024P2HIGHCVSS 7.2Exploitedv2016v20192024-07-09
CVE-2024-38024 [HIGH] CWE-502 CVE-2024-38024: Microsoft SharePoint Server Remote Code Execution Vulnerability
Microsoft SharePoint Server Remote Code Execution Vulnerability
nvd
CVE-2021-27076P1HIGHCVSS 8.8Exploitedv2016v20192021-03-11
CVE-2021-27076 [HIGH] CVE-2021-27076: Microsoft SharePoint Server Remote Code Execution Vulnerability
Microsoft SharePoint Server Remote Code Execution Vulnerability
nvd
CVE-2012-2520P2MEDIUMCVSS 4.3Exploitedv2007v20102012-10-09
CVE-2012-2520 [MEDIUM] CWE-79 CVE-2012-2520: Cross-site scripting (XSS) vulnerability in Microsoft InfoPath 2007 SP2 and SP3 and 2010 SP1, Commun
Cross-site scripting (XSS) vulnerability in Microsoft InfoPath 2007 SP2 and SP3 and 2010 SP1, Communicator 2007 R2, Lync 2010 and 2010 Attendee, SharePoint Server 2007 SP2 and SP3 and 2010 SP1, Groove Server 2010 SP1, Windows SharePoint Services 3.0 SP2, SharePoint Foundation 2010 SP1, and Office Web Apps 2010 SP1 allows remote attackers to inject arbi
nvd
CVE-2018-8627P2MEDIUMCVSS 5.5Exploitedv2010-sp22018-12-12
CVE-2018-8627 [MEDIUM] CVE-2018-8627: An information disclosure vulnerability exists when Microsoft Excel software reads out of bound memo
An information disclosure vulnerability exists when Microsoft Excel software reads out of bound memory due to an uninitialized variable, which could disclose the contents of memory, aka "Microsoft Excel Information Disclosure Vulnerability." This affects Microsoft Office, Office 365 ProPlus, Microsoft Excel, Microsoft Excel Viewer, Excel. This CVE ID is uniqu
nvd
CVE-2018-8580P2MEDIUMCVSS 4.3Exploitedv2010-sp2v2013-sp1+1 more2018-12-12
CVE-2018-8580 [MEDIUM] CWE-200 CVE-2018-8580: An information disclosure vulnerability exists where certain modes of the search function in Microso
An information disclosure vulnerability exists where certain modes of the search function in Microsoft SharePoint Server are vulnerable to cross-site search attacks (a variant of cross-site request forgery, CSRF), aka "Microsoft SharePoint Information Disclosure Vulnerability." This affects Microsoft SharePoint.
nvd
CVE-2013-1289P2MEDIUMCVSS 4.3Exploitedv20102013-04-09
CVE-2013-1289 [MEDIUM] CWE-79 CVE-2013-1289: Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2010 SP1, Groove Server 2010
Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2010 SP1, Groove Server 2010 SP1, SharePoint Foundation 2010 SP1, and Office Web Apps 2010 SP1 allows remote attackers to inject arbitrary web script or HTML via a crafted string, aka "HTML Sanitization Vulnerability."
nvd
CVE-2010-3964P2HIGHCVSS 7.5PoCv20072010-12-16
CVE-2010-3964 [HIGH] CVE-2010-3964: Unrestricted file upload vulnerability in the Document Conversions Launcher Service in Microsoft Off
Unrestricted file upload vulnerability in the Document Conversions Launcher Service in Microsoft Office SharePoint Server 2007 SP2, when the Document Conversions Load Balancer Service is enabled, allows remote attackers to execute arbitrary code via a crafted SOAP request to TCP port 8082, aka "Malformed Request Code Execution Vulnerability."
nvd
CVE-2021-31181P2HIGHCVSS 8.8PoCv20192021-05-11
CVE-2021-31181 [HIGH] CWE-94 CVE-2021-31181: Microsoft SharePoint Remote Code Execution Vulnerability
Microsoft SharePoint Remote Code Execution Vulnerability
nvd
CVE-2020-16952P2HIGHCVSS 7.8PoCv20192020-10-16
CVE-2020-16952 [HIGH] CWE-346 CVE-2020-16952: <p>A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to c
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the SharePoint application pool and the SharePoint server farm account.
Exploitation of this vulnerability
nvd
CVE-2025-47166P2HIGHCVSS 8.8PoCfixed in 16.0.18526.20396v20192025-06-10
CVE-2025-47166 [HIGH] CWE-502 CVE-2025-47166: Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to ex
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
nvd
CVE-2015-2468P2CRITICALCVSS 9.3PoCv2010v20132015-08-15
CVE-2015-2468 [CRITICAL] CWE-119 CVE-2015-2468: Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Office for
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Office for Mac 2011, Office for Mac 2016, Office Compatibility Pack SP3, Word Viewer, Word Automation Services on SharePoint Server 2010 SP2 and 2013 SP1, Word Web Apps 2010 SP2, and Office Web Apps Server 2013 SP1 allow remote attackers to execute arbitrary co
nvd
CVE-2015-0064P2CRITICALCVSS 9.3PoCv20102015-02-11
CVE-2015-0064 [CRITICAL] CWE-399 CVE-2015-0064: Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word Automation Services in SharePoint Serv
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word Automation Services in SharePoint Server 2010, Web Applications 2010 SP2, Word Viewer, and Office Compatibility Pack SP3 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Office Remote Code Execution Vulne
nvd
CVE-2022-44690P2HIGHCVSS 8.8v2013v2016+1 more2022-12-13
CVE-2022-44690 [HIGH] CVE-2022-44690: Microsoft SharePoint Server Remote Code Execution Vulnerability
Microsoft SharePoint Server Remote Code Execution Vulnerability
nvd
CVE-2022-38053P2HIGHCVSS 8.8v20192022-10-11
CVE-2022-38053 [HIGH] CVE-2022-38053: Microsoft SharePoint Server Remote Code Execution Vulnerability
Microsoft SharePoint Server Remote Code Execution Vulnerability
nvd
CVE-2020-1181P2HIGHCVSS 8.8v20192020-06-09
CVE-2020-1181 [HIGH] CVE-2020-1181: A remote code execution vulnerability exists in Microsoft SharePoint Server when it fails to properl
A remote code execution vulnerability exists in Microsoft SharePoint Server when it fails to properly identify and filter unsafe ASP.Net web controls, aka 'Microsoft SharePoint Server Remote Code Execution Vulnerability'.
nvd