Microsoft Sharepoint Server vulnerabilities
548 known vulnerabilities affecting microsoft/sharepoint_server.
Total CVEs
548
CISA KEV
18
actively exploited
Public exploits
29
Exploited in wild
31
Severity breakdown
CRITICAL44HIGH263MEDIUM226LOW15
Vulnerabilities
Page 4 of 28
CVE-2009-3830P3MEDIUMCVSS 5.0PoCv20072009-10-30
CVE-2009-3830 [MEDIUM] CWE-20 CVE-2009-3830: The download functionality in Team Services in Microsoft Office SharePoint Server 2007 12.0.0.4518 a
The download functionality in Team Services in Microsoft Office SharePoint Server 2007 12.0.0.4518 and 12.0.0.6219 allows remote attackers to read ASP.NET source code via pathnames in the SourceUrl and Source parameters to _layouts/download.aspx.
nvd
CVE-2025-47163P2HIGHCVSS 8.8fixed in 16.0.18526.20396v20192025-06-10
CVE-2025-47163 [HIGH] CWE-502 CVE-2025-47163: Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to ex
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
nvd
CVE-2025-21400P2HIGHCVSS 8.0fixed in 16.0.17928.20396v2016+1 more2025-02-11
CVE-2025-21400 [HIGH] CWE-285 CVE-2025-21400: Microsoft SharePoint Server Remote Code Execution Vulnerability
Microsoft SharePoint Server Remote Code Execution Vulnerability
nvd
CVE-2026-55040P2CRITICALCVSS 9.1fixed in 16.0.19725.20434v2016+1 more2026-07-14
CVE-2026-55040 [CRITICAL] CWE-1390 CVE-2026-55040: Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a secur
Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.
nvd
CVE-2008-3006P2CRITICALCVSS 9.3v20072008-08-12
CVE-2008-3006 [CRITICAL] CWE-399 CVE-2008-3006: Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP2 and SP3, and 2007 Gold and SP1; Office Excel Vie
Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP2 and SP3, and 2007 Gold and SP1; Office Excel Viewer 2003 Gold and SP3; Office Excel Viewer; Office Compatibility Pack 2007 Gold and SP1; Office SharePoint Server 2007 Gold and SP1; and Office 2004 and 2008 for Mac do not properly parse Country record values when loading Excel files, which allows re
nvd
CVE-2022-29108P2HIGHCVSS 8.8v20192022-05-10
CVE-2022-29108 [HIGH] CVE-2022-29108: Microsoft SharePoint Server Remote Code Execution Vulnerability
Microsoft SharePoint Server Remote Code Execution Vulnerability
nvd
CVE-2025-29794P2HIGHCVSS 8.8fixed in 16.0.18526.20172v20192025-04-08
CVE-2025-29794 [HIGH] CWE-285 CVE-2025-29794: Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code
Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
nvd
CVE-2024-30043P3HIGHCVSS 7.5fixed in 16.0.17328.20292v2016+1 more2024-05-14
CVE-2024-30043 [HIGH] CWE-611 CVE-2024-30043: Microsoft SharePoint Server Information Disclosure Vulnerability
Microsoft SharePoint Server Information Disclosure Vulnerability
nvd
CVE-2008-4019P2CRITICALCVSS 9.3v20072008-10-15
CVE-2008-4019 [CRITICAL] CWE-190 CVE-2008-4019: Integer overflow in the REPT function in Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2 and SP3, and 2
Integer overflow in the REPT function in Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2 and SP3, and 2007 Gold and SP1; Office Excel Viewer 2003 SP3; Office Excel Viewer; Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats Gold and SP1; Office SharePoint Server 2007 Gold and SP1; Office 2004 and 2008 for Mac; and Open XML File
nvd
CVE-2015-6093P2CRITICALCVSS 9.3v2010v20132015-11-11
CVE-2015-6093 [CRITICAL] CWE-119 CVE-2015-6093: Microsoft Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office 2013 RT SP1, Office 2016, Word A
Microsoft Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office 2013 RT SP1, Office 2016, Word Automation Services on SharePoint Server 2010 SP2 and 2013 SP1, Office Web Apps 2010 SP2, and Office Web Apps Server 2013 SP1 allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulner
nvd
CVE-2015-1650P2CRITICALCVSS 9.3v2010v20132015-04-14
CVE-2015-1650 [CRITICAL] CVE-2015-1650: Use-after-free vulnerability in Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 S
Use-after-free vulnerability in Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word Viewer, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2010 SP2 and 2013 SP1, and Office Web Apps Server 2010 SP2 and 2013 SP1 allows remote attackers to execute arbitrary code via a crafted Office docu
nvd
CVE-2024-43464P2HIGHCVSS 7.2v2016v20192024-09-10
CVE-2024-43464 [HIGH] CWE-502 CVE-2024-43464: Microsoft SharePoint Server Remote Code Execution Vulnerability
Microsoft SharePoint Server Remote Code Execution Vulnerability
nvd
CVE-2013-0007P3CRITICALCVSS 9.3v20072013-01-09
CVE-2013-0007 [CRITICAL] CWE-94 CVE-2013-0007: Microsoft XML Core Services (aka MSXML) 4.0, 5.0, and 6.0 does not properly parse XML content, which
Microsoft XML Core Services (aka MSXML) 4.0, 5.0, and 6.0 does not properly parse XML content, which allows remote attackers to execute arbitrary code via a crafted web page, aka "MSXML XSLT Vulnerability."
nvd
CVE-2020-1025P2CRITICALCVSS 9.8v20192020-07-14
CVE-2020-1025 [CRITICAL] CWE-20 CVE-2020-1025: An elevation of privilege vulnerability exists when Microsoft SharePoint Server and Skype for Busine
An elevation of privilege vulnerability exists when Microsoft SharePoint Server and Skype for Business Server improperly handle OAuth token validation. An attacker who successfully exploited the vulnerability could bypass authentication and achieve improper access.
To exploit this vulnerability, an attacker would need to modify the token.
The update
nvd
CVE-2015-1682P2CRITICALCVSS 9.3v2010v20132015-05-13
CVE-2015-1682 [CRITICAL] CWE-119 CVE-2015-1682: Microsoft Office 2010 SP2, Excel 2010 SP2, PowerPoint 2010 SP2, Word 2010 SP2, Office 2013 SP1, Exce
Microsoft Office 2010 SP2, Excel 2010 SP2, PowerPoint 2010 SP2, Word 2010 SP2, Office 2013 SP1, Excel 2013 SP1, PowerPoint 2013 SP1, Word 2013 SP1, Office 2013 RT SP1, Excel 2013 RT SP1, PowerPoint 2013 RT SP1, Word 2013 RT SP1, Office for Mac 2011, Excel for Mac 2011, PowerPoint for Mac 2011, Word for Mac 2011, PowerPoint Viewer, Word Automation Se
nvd
CVE-2018-8504P2HIGHCVSS 8.8v2010-sp22018-10-10
CVE-2018-8504 [HIGH] CVE-2018-8504: A remote code execution vulnerability exists in Microsoft Word software when the software fails to p
A remote code execution vulnerability exists in Microsoft Word software when the software fails to properly handle objects in Protected View, aka "Microsoft Word Remote Code Execution Vulnerability." This affects Microsoft SharePoint Server, Office 365 ProPlus, Microsoft Office, Microsoft Word.
nvd
CVE-2011-1989P2CRITICALCVSS 9.3v2007v20102011-09-15
CVE-2011-1989 [CRITICAL] CWE-20 CVE-2011-1989: Microsoft Excel 2003 SP3 and 2007 SP2; Excel in Office 2007 SP2; Excel 2010 Gold and SP1; Excel in O
Microsoft Excel 2003 SP3 and 2007 SP2; Excel in Office 2007 SP2; Excel 2010 Gold and SP1; Excel in Office 2010 Gold and SP1; Office 2004, 2008, and 2011 for Mac; Open XML File Format Converter for Mac; Excel Viewer SP2; Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2; Excel Services on Office SharePoint Server 2007 SP2
nvd
CVE-2013-3889P2CRITICALCVSS 9.3v2007v2013+1 more2013-10-09
CVE-2013-3889 [CRITICAL] CWE-119 CVE-2013-3889: Microsoft Excel 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT; Office 2007 SP3, 2010 SP1 and SP2, 20
Microsoft Excel 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT; Office 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT; Office for Mac 2011; Excel Viewer; Office Compatibility Pack SP3; and Excel Services and Word Automation Services in SharePoint Server 2013 allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft
nvd
CVE-2011-1990P2CRITICALCVSS 9.3v20072011-09-15
CVE-2011-1990 [CRITICAL] CWE-119 CVE-2011-1990: Microsoft Excel 2007 SP2; Excel in Office 2007 SP2; Excel Viewer SP2; Office Compatibility Pack for
Microsoft Excel 2007 SP2; Excel in Office 2007 SP2; Excel Viewer SP2; Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2; and Excel Services on Office SharePoint Server 2007 SP2 do not properly validate the sign of an unspecified array index, which allows remote attackers to execute arbitrary code via a crafted spreadshee
nvd
CVE-2026-33112P2HIGHCVSS 8.8fixed in 16.0.19725.20280v2016+1 more2026-05-12
CVE-2026-33112 [HIGH] CWE-502 CVE-2026-33112: Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to ex
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
nvd