Microsoft Sharepoint Server vulnerabilities
548 known vulnerabilities affecting microsoft/sharepoint_server.
Total CVEs
548
CISA KEV
18
actively exploited
Public exploits
29
Exploited in wild
31
Severity breakdown
CRITICAL44HIGH263MEDIUM226LOW15
Vulnerabilities
Page 6 of 28
CVE-2023-33160P2HIGHCVSS 8.8v2016v20192023-07-11
CVE-2023-33160 [HIGH] CWE-502 CVE-2023-33160: Microsoft SharePoint Server Remote Code Execution Vulnerability
Microsoft SharePoint Server Remote Code Execution Vulnerability
nvd
CVE-2015-2555P3CRITICALCVSS 9.3v2010v20132015-10-14
CVE-2015-2555 [CRITICAL] CVE-2015-2555: Use-after-free vulnerability in Microsoft Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2
Use-after-free vulnerability in Microsoft Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Excel for Mac 2011, Excel 2016 for Mac, and Excel Services on SharePoint Server 2010 SP2 and 2013 SP1 allows remote attackers to execute arbitrary code via a crafted calculatedColumnFormula object in an Office document, aka "Microsoft Office Memory Corru
nvd
CVE-2015-2558P3CRITICALCVSS 9.3v2010v20132015-10-14
CVE-2015-2558 [CRITICAL] CVE-2015-2558: Use-after-free vulnerability in Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013
Use-after-free vulnerability in Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Excel for Mac 2011, Excel 2016 for Mac, Excel Viewer, Office Compatibility Pack SP3, and Excel Services on SharePoint Server 2007 SP3, 2010 SP2, and 2013 SP1 allows remote attackers to execute arbitrary code via a long fileVersion element
nvd
CVE-2026-35439P2HIGHCVSS 8.8fixed in 16.0.19725.20280v2016+1 more2026-05-12
CVE-2026-35439 [HIGH] CWE-502 CVE-2026-35439: Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to ex
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
nvd
CVE-2026-45454P2HIGHCVSS 8.8fixed in 16.0.19725.20384v2016+1 more2026-06-09
CVE-2026-45454 [HIGH] CWE-22 CVE-2026-45454: Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Office S
Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
nvd
CVE-2019-0594P2HIGHCVSS 8.8v2010v20192019-03-05
CVE-2019-0594 [HIGH] CWE-20 CVE-2019-0594: A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to chec
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0604.
nvd
CVE-2021-41344P3HIGHCVSS 8.8v20192021-10-13
CVE-2021-41344 [HIGH] CVE-2021-41344: Microsoft SharePoint Server Remote Code Execution Vulnerability
Microsoft SharePoint Server Remote Code Execution Vulnerability
nvd
CVE-2021-24066P2HIGHCVSS 8.8v20192021-02-25
CVE-2021-24066 [HIGH] CWE-502 CVE-2021-24066: Microsoft SharePoint Remote Code Execution Vulnerability
Microsoft SharePoint Remote Code Execution Vulnerability
nvd
CVE-2019-1257P3HIGHCVSS 8.8v20192019-09-11
CVE-2019-1257 [HIGH] CWE-20 CVE-2019-1257: A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to chec
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1295, CVE-2019-1296.
nvd
CVE-2025-29793P3HIGHCVSS 7.2fixed in 16.0.18526.20172v20192025-04-08
CVE-2025-29793 [HIGH] CWE-502 CVE-2025-29793: Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to ex
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
nvd
CVE-2020-0929P2HIGHCVSS 8.8v20192020-04-15
CVE-2020-0929 [HIGH] CVE-2020-0929: A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to chec
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0920, CVE-2020-0931, CVE-2020-0932, CVE-2020-0971, CVE-2020-0974.
nvd
CVE-2020-0931P2HIGHCVSS 8.8v20192020-04-15
CVE-2020-0931 [HIGH] CVE-2020-0931: A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to chec
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0920, CVE-2020-0929, CVE-2020-0932, CVE-2020-0971, CVE-2020-0974.
nvd
CVE-2020-0974P2HIGHCVSS 8.8v20192020-04-15
CVE-2020-0974 [HIGH] CVE-2020-0974: A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to chec
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0920, CVE-2020-0929, CVE-2020-0931, CVE-2020-0932, CVE-2020-0971.
nvd
CVE-2020-0920P2HIGHCVSS 8.8v20192020-04-15
CVE-2020-0920 [HIGH] CWE-434 CVE-2020-0920: A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to chec
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0929, CVE-2020-0931, CVE-2020-0932, CVE-2020-0971, CVE-2020-0974.
nvd
CVE-2016-0183P3HIGHCVSS 8.8v20102016-05-11
CVE-2016-0183 [HIGH] CWE-284 CVE-2016-0183: The Windows font library in Microsoft Office 2010 SP2, Word 2010 SP2, Word Automation Services on Sh
The Windows font library in Microsoft Office 2010 SP2, Word 2010 SP2, Word Automation Services on SharePoint Server 2010 SP2, and Office Web Apps 2010 SP2 allows remote attackers to execute arbitrary code via a crafted embedded font, aka "Microsoft Office Graphics RCE Vulnerability."
nvd
CVE-2026-33110P2HIGHCVSS 8.8fixed in 16.0.19725.20280v2016+1 more2026-05-12
CVE-2026-33110 [HIGH] CWE-502 CVE-2026-33110: Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to ex
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
nvd
CVE-2026-40357P2HIGHCVSS 8.8fixed in 16.0.19725.20280v2016+1 more2026-05-12
CVE-2026-40357 [HIGH] CWE-502 CVE-2026-40357: Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to ex
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
nvd
CVE-2026-55052P2HIGHCVSS 8.8fixed in 16.0.19725.20434v2016+1 more2026-07-14
CVE-2026-55052 [HIGH] CWE-862 CVE-2026-55052: Missing authorization in Microsoft Office SharePoint allows an authorized attacker to elevate privil
Missing authorization in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2021-34467P3HIGHCVSS 8.8v2016v20192021-07-16
CVE-2021-34467 [HIGH] CVE-2021-34467: Microsoft SharePoint Server Remote Code Execution Vulnerability
Microsoft SharePoint Server Remote Code Execution Vulnerability
nvd
CVE-2020-1023P3HIGHCVSS 8.8v20192020-05-21
CVE-2020-1023 [HIGH] CWE-434 CVE-2020-1023: A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to chec
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1024, CVE-2020-1102.
nvd