cbcvebase.

Microsoft Sharepoint Server vulnerabilities

548 known vulnerabilities affecting microsoft/sharepoint_server.

Total CVEs
548
CISA KEV
18
actively exploited
Public exploits
29
Exploited in wild
31
Severity breakdown
CRITICAL44HIGH263MEDIUM226LOW15

Vulnerabilities

Page 7 of 28
CVE-2020-1024P3HIGHCVSS 8.8v20192020-05-21
CVE-2020-1024 [HIGH] CVE-2020-1024: A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to chec A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1023, CVE-2020-1102.
nvd
CVE-2013-3857P3CRITICALCVSS 9.3v20102013-09-11
CVE-2013-3857 [CRITICAL] CWE-119 CVE-2013-3857: Microsoft Word Automation Services in SharePoint Server 2010 SP1 and SP2, Word Web App 2010 SP1 and Microsoft Word Automation Services in SharePoint Server 2010 SP1 and SP2, Word Web App 2010 SP1 and SP2 in Office Web Apps 2010, Word 2003 SP3, Word 2007 SP3, Word 2010 SP1 and SP2, Office Compatibility Pack SP3, and Word Viewer allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office docu
nvd
CVE-2023-33134P3HIGHCVSS 8.8v2016v20192023-07-11
CVE-2023-33134 [HIGH] CWE-502 CVE-2023-33134: Microsoft SharePoint Server Remote Code Execution Vulnerability Microsoft SharePoint Server Remote Code Execution Vulnerability
nvd
CVE-2026-40365P3HIGHCVSS 8.8fixed in 16.0.19725.20280v2016+1 more2026-05-12
CVE-2026-40365 [HIGH] CWE-1220 CVE-2026-40365: Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to ex Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
nvd
CVE-2025-49701P2HIGHCVSS 8.8fixed in 16.0.18526.20424v2016+1 more2025-07-08
CVE-2025-49701 [HIGH] CWE-285 CVE-2025-49701: Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
nvd
CVE-2017-8509P3HIGHCVSS 8.8v2010v2013+1 more2017-06-15
CVE-2017-8509 [HIGH] CVE-2017-8509: A remote code execution vulnerability exists in Microsoft Office when the software fails to properly A remote code execution vulnerability exists in Microsoft Office when the software fails to properly handle objects in memory, aka "Office Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-8510, CVE-2017-8511, CVE-2017-8512, CVE-2017-0260, and CVE-2017-8506.
nvd
CVE-2020-1460P3HIGHCVSS 8.8v20192020-09-11
CVE-2020-1460 [HIGH] CVE-2020-1460: <p>A remote code execution vulnerability exists in Microsoft SharePoint Server when it fails to prop A remote code execution vulnerability exists in Microsoft SharePoint Server when it fails to properly identify and filter unsafe ASP.Net web controls. An authenticated attacker who successfully exploited the vulnerability could use a specially crafted page to perform actions in the security context of the SharePoint application pool process. To exploit the vuln
nvd
CVE-2021-1707P3HIGHCVSS 8.8v20192021-01-12
CVE-2021-1707 [HIGH] CVE-2021-1707: Microsoft SharePoint Server Remote Code Execution Vulnerability Microsoft SharePoint Server Remote Code Execution Vulnerability
nvd
CVE-2020-17061P3HIGHCVSS 8.8v2016v20192020-11-11
CVE-2020-17061 [HIGH] CVE-2020-17061: Microsoft SharePoint Remote Code Execution Vulnerability Microsoft SharePoint Remote Code Execution Vulnerability
nvd
CVE-2020-17121P3HIGHCVSS 8.8v2016v20192020-12-10
CVE-2020-17121 [HIGH] CVE-2020-17121: Microsoft SharePoint Remote Code Execution Vulnerability Microsoft SharePoint Remote Code Execution Vulnerability
nvd
CVE-2021-34520P3HIGHCVSS 8.8v2016v20192021-07-14
CVE-2021-34520 [HIGH] CWE-502 CVE-2021-34520: Microsoft SharePoint Server Remote Code Execution Vulnerability Microsoft SharePoint Server Remote Code Execution Vulnerability
nvd
CVE-2021-26420P3HIGHCVSS 8.8v20192021-06-08
CVE-2021-26420 [HIGH] CVE-2021-26420: Microsoft SharePoint Server Remote Code Execution Vulnerability Microsoft SharePoint Server Remote Code Execution Vulnerability
nvd
CVE-2023-21744P3HIGHCVSS 8.8v2013v2016+1 more2023-01-10
CVE-2023-21744 [HIGH] CWE-502 CVE-2023-21744: Microsoft SharePoint Server Remote Code Execution Vulnerability Microsoft SharePoint Server Remote Code Execution Vulnerability
nvd
CVE-2022-30158P3HIGHCVSS 8.8v2013v2016+1 more2022-06-15
CVE-2022-30158 [HIGH] CVE-2022-30158: Microsoft SharePoint Server Remote Code Execution Vulnerability Microsoft SharePoint Server Remote Code Execution Vulnerability
nvd
CVE-2019-1295P3HIGHCVSS 8.8v20192019-09-11
CVE-2019-1295 [HIGH] CVE-2019-1295: A remote code execution vulnerability exists in Microsoft SharePoint where APIs aren't properly prot A remote code execution vulnerability exists in Microsoft SharePoint where APIs aren't properly protected from unsafe data input, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1257, CVE-2019-1296.
nvd
CVE-2019-1296P3HIGHCVSS 8.8v20192019-09-11
CVE-2019-1296 [HIGH] CVE-2019-1296: A remote code execution vulnerability exists in Microsoft SharePoint where APIs aren't properly prot A remote code execution vulnerability exists in Microsoft SharePoint where APIs aren't properly protected from unsafe data input, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1257, CVE-2019-1295.
nvd
CVE-2020-1595P3HIGHCVSS 8.8v20192020-09-11
CVE-2020-1595 [HIGH] CWE-494 CVE-2020-1595: <p>A remote code execution vulnerability exists in Microsoft SharePoint where APIs aren't properly p A remote code execution vulnerability exists in Microsoft SharePoint where APIs aren't properly protected from unsafe data input. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the SharePoint application pool and the SharePoint server farm account. Exploitation of this vulnerability requires that a us
nvd
CVE-2022-44693P3HIGHCVSS 8.8v20192022-12-13
CVE-2022-44693 [HIGH] CVE-2022-44693: Microsoft SharePoint Server Remote Code Execution Vulnerability Microsoft SharePoint Server Remote Code Execution Vulnerability
nvd
CVE-2019-1205P3CRITICALCVSS 9.8v20192019-08-14
CVE-2019-1205 [CRITICAL] CVE-2019-1205: A remote code execution vulnerability exists in Microsoft Word software when it fails to properly ha A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could use a specially crafted file to perform actions in the security context of the current user. The file could then take actions on behalf of the logged-on user with the same
nvd
CVE-2018-8635P3HIGHCVSS 8.8v2010-sp22018-12-12
CVE-2018-8635 [HIGH] CWE-20 CVE-2018-8635: An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sa An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted authentication request to an affected SharePoint server, aka "Microsoft SharePoint Server Elevation of Privilege Vulnerability." This affects Microsoft SharePoint Server, Microsoft SharePoint.
nvd
Microsoft Sharepoint Server vulnerabilities | cvebase