Microsoft Sharepoint Server vulnerabilities
548 known vulnerabilities affecting microsoft/sharepoint_server.
Total CVEs
548
CISA KEV
18
actively exploited
Public exploits
29
Exploited in wild
31
Severity breakdown
CRITICAL44HIGH263MEDIUM226LOW15
Vulnerabilities
Page 5 of 28
CVE-2026-26114P2HIGHCVSS 8.8v2016v20192026-03-10
CVE-2026-26114 [HIGH] CWE-502 CVE-2026-26114: Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to ex
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
nvd
CVE-2023-24950P3MEDIUMCVSS 6.5v20192023-05-09
CVE-2023-24950 [MEDIUM] CWE-20 CVE-2023-24950: Microsoft SharePoint Server Spoofing Vulnerability
Microsoft SharePoint Server Spoofing Vulnerability
nvd
CVE-2025-47172P2HIGHCVSS 8.8≤ 16.0.18526.20396v20192025-06-10
CVE-2025-47172 [HIGH] CWE-89 CVE-2025-47172: Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Of
Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
nvd
CVE-2022-30157P2HIGHCVSS 8.8v2013v2016+1 more2022-06-15
CVE-2022-30157 [HIGH] CVE-2022-30157: Microsoft SharePoint Server Remote Code Execution Vulnerability
Microsoft SharePoint Server Remote Code Execution Vulnerability
nvd
CVE-2026-26106P2HIGHCVSS 8.8fixed in 16.0.19725.20076v2016+1 more2026-03-10
CVE-2026-26106 [HIGH] CWE-20 CVE-2026-26106: Improper input validation in Microsoft Office SharePoint allows an authorized attacker to execute co
Improper input validation in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
nvd
CVE-2025-59228P2HIGHCVSS 8.8fixed in 16.0.19127.20262v2016+1 more2025-10-14
CVE-2025-59228 [HIGH] CWE-20 CVE-2025-59228: Improper input validation in Microsoft Office SharePoint allows an authorized attacker to execute co
Improper input validation in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
nvd
CVE-2019-0585P3HIGHCVSS 8.8v2013-sp1v2016+1 more2019-01-08
CVE-2019-0585 [HIGH] CVE-2019-0585: A remote code execution vulnerability exists in Microsoft Word software when it fails to properly ha
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka "Microsoft Word Remote Code Execution Vulnerability." This affects Word, Microsoft Office, Microsoft Office Word Viewer, Office 365 ProPlus, Microsoft SharePoint, Microsoft Office Online Server, Microsoft Word, Microsoft SharePoint Ser
nvd
CVE-2015-0085P2CRITICALCVSS 9.3v2007v2010+1 more2015-03-11
CVE-2015-0085 [CRITICAL] CVE-2015-0085: Use-after-free vulnerability in Microsoft Office 2007 SP3, Excel 2007 SP3, PowerPoint 2007 SP3, Word
Use-after-free vulnerability in Microsoft Office 2007 SP3, Excel 2007 SP3, PowerPoint 2007 SP3, Word 2007 SP3, Office 2010 SP2, Excel 2010 SP2, PowerPoint 2010 SP2, Word 2010 SP2, Office 2013 Gold and SP1, Word 2013 Gold and SP1, Office 2013 RT Gold and SP1, Word 2013 RT Gold and SP1, Excel Viewer, Office Compatibility Pack SP3, Word Automation Services on
nvd
CVE-2018-0792P3HIGHCVSS 8.8v20162018-01-10
CVE-2018-0792 [HIGH] CWE-787 CVE-2018-0792: Microsoft Word 2016 in Microsoft Office 2016 allows a remote code execution vulnerability due to the
Microsoft Word 2016 in Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Word Remote Code Execution Vulnerability". This CVE is unique from CVE-2018-0794.
nvd
CVE-2015-1649P2CRITICALCVSS 9.3v2010v20132015-04-14
CVE-2015-1649 [CRITICAL] CVE-2015-1649: Use-after-free vulnerability in Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word Viewer
Use-after-free vulnerability in Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word Viewer, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2010 SP2, and Office Web Apps Server 2010 SP2 allows remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Component Use After Free Vulner
nvd
CVE-2020-17118P2CRITICALCVSS 9.8v2016v20192020-12-10
CVE-2020-17118 [CRITICAL] CVE-2020-17118: Microsoft SharePoint Remote Code Execution Vulnerability
Microsoft SharePoint Remote Code Execution Vulnerability
nvd
CVE-2013-0006P3HIGHCVSS 8.8v20072013-01-09
CVE-2013-0006 [HIGH] CWE-189 CVE-2013-0006: Microsoft XML Core Services (aka MSXML) 3.0, 5.0, and 6.0 does not properly parse XML content, which
Microsoft XML Core Services (aka MSXML) 3.0, 5.0, and 6.0 does not properly parse XML content, which allows remote attackers to execute arbitrary code via a crafted web page, aka "MSXML Integer Truncation Vulnerability."
nvd
CVE-2020-1069P2HIGHCVSS 8.8v20192020-05-21
CVE-2020-1069 [HIGH] CWE-476 CVE-2020-1069: A remote code execution vulnerability exists in Microsoft SharePoint Server when it fails to properl
A remote code execution vulnerability exists in Microsoft SharePoint Server when it fails to properly identify and filter unsafe ASP.Net web controls, aka 'Microsoft SharePoint Server Remote Code Execution Vulnerability'.
nvd
CVE-2015-6094P3CRITICALCVSS 9.3v20132015-11-11
CVE-2015-6094 [CRITICAL] CWE-119 CVE-2015-6094: Microsoft Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Excel for Mac 2011, Excel 2
Microsoft Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Excel for Mac 2011, Excel 2016 for Mac, and Excel Services on SharePoint Server 2013 SP1 allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."
nvd
CVE-2020-1102P2HIGHCVSS 8.8v20192020-05-21
CVE-2020-1102 [HIGH] CVE-2020-1102: A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to chec
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1023, CVE-2020-1024.
nvd
CVE-2025-59237P2HIGHCVSS 8.8fixed in 16.0.19127.20262v2016+1 more2025-10-14
CVE-2025-59237 [HIGH] CWE-502 CVE-2025-59237: Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to ex
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
nvd
CVE-2020-0971P2HIGHCVSS 8.8v20192020-04-15
CVE-2020-0971 [HIGH] CVE-2020-0971: A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to chec
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0920, CVE-2020-0929, CVE-2020-0931, CVE-2020-0932, CVE-2020-0974.
nvd
CVE-2026-58277P2HIGHCVSS 8.8v2016v20192026-07-14
CVE-2026-58277 [HIGH] CWE-285 CVE-2026-58277: Improper authorization in Microsoft Office SharePoint allows an authorized attacker to elevate privi
Improper authorization in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2014-4117P3CRITICALCVSS 9.3v20102014-10-15
CVE-2014-4117 [CRITICAL] CWE-20 CVE-2014-4117: Microsoft Office 2007 SP3, Word 2007 SP3, Office 2010 SP1 and SP2, Word 2010 SP1 and SP2, Office for
Microsoft Office 2007 SP3, Word 2007 SP3, Office 2010 SP1 and SP2, Word 2010 SP1 and SP2, Office for Mac 2011, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2010 SP1 and SP2, and Word Web Apps 2010 Gold, SP1, and SP2 allow remote attackers to execute arbitrary code via crafted properties in a Word document, aka "Microso
nvd
CVE-2013-1315P3CRITICALCVSS 9.3v2007v20102013-09-11
CVE-2013-1315 [CRITICAL] CWE-119 CVE-2013-1315: Microsoft SharePoint Server 2007 SP3, 2010 SP1 and SP2, and 2013; Office Web Apps 2010; Excel 2003 S
Microsoft SharePoint Server 2007 SP3, 2010 SP1 and SP2, and 2013; Office Web Apps 2010; Excel 2003 SP3, 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT; Office for Mac 2011; Excel Viewer; and Office Compatibility Pack SP3 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, ak
nvd