VendorsMicrosoftsharepoint_enterprise_server2016
Vulnerabilities

Microsoft Sharepoint Enterprise Server 2016

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

246CVEs
CVE-2020-1595
Microsoft SharePoint Remote Code Execution Vulnerability
Published 2020-09-11 · Modified
9.9EPSS 0.020
CVE-2020-1210
Microsoft SharePoint Remote Code Execution Vulnerability
Published 2020-09-11 · Modified
9.9EPSS 0.019
CVE-2019-0604
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0594.
Published 2019-03-06 · Analyzed
9.8KEV1 PoCEPSS 0.999
CVE-2023-21716
Microsoft Word Remote Code Execution Vulnerability
Published 2023-02-14 · Modified
9.8EPSS 0.848
CVE-2020-1025
Microsoft Office Elevation of Privilege Vulnerability
Published 2020-07-14 · Modified
9.8EPSS 0.059
CVE-2017-11826
Microsoft Office 2010, SharePoint Enterprise Server 2010, SharePoint Server 2010, Web Applications, Office Web Apps Server 2010 and 2013, Word Viewer, Word 2007, 2010, 2013 and 2016, Word Automation Services, and Office Online Server allow remote code execution when the software fails to properly handle objects in memory.
Published 2017-10-13 · Analyzed
9.3KEVEPSS 0.812
CVE-2018-8284
A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka ".NET Framework Remote Code Injection Vulnerability." This affects Microsoft .NET Framework 2.0, Microsoft .NET Framework 3.0, Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.5.2, Microsoft .NET Framework 4.6, Microsoft .NET Framework 4.7/4.7.1/4.7.2, Microsoft .NET Framework 4.7.1/4.7.2, Microsoft .NET Framework 3.5, Microsoft .NET Framework 3.5.1, Microsoft .NET Framework 4.6/4.6.1/4.6.2, Microsoft .NET Framework 4.6/4.6.1/4.6.2/4.7/4.7.1/4.7.1/4.7.2, Microsoft .NET Framework 4.7.2.
Published 2018-07-11 · Modified
9.3EPSS 0.415
CVE-2018-0797
Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow a remote code execution vulnerability due to the way RTF content is handled, aka "Microsoft Word Memory Corruption Vulnerability".
Published 2018-01-10 · Modified
9.3EPSS 0.248
CVE-2017-0003
Microsoft Word 2016 and SharePoint Enterprise Server 2016 allow remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability."
Published 2017-01-10 · Modified
9.3EPSS 0.247
CVE-2017-8512
A remote code execution vulnerability exists in Microsoft Office when the software fails to properly handle objects in memory, aka "Office Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-8509, CVE-2017-8510, CVE-2017-8511, CVE-2017-0260, and CVE-2017-8506.
Published 2017-06-15 · Modified
9.3EPSS 0.221
CVE-2017-8742
A remote code execution vulnerability exists in Microsoft PowerPoint 2007 Service Pack 3, Microsoft PowerPoint 2010 Service Pack 2, Microsoft PowerPoint 2013 Service Pack 1, Microsoft PowerPoint 2013 RT Service Pack 1, Microsoft PowerPoint 2016, Microsoft PowerPoint Viewer 2007, Microsoft SharePoint Server 2013 Service Pack 1, Microsoft SharePoint Enterprise Server 2016, Microsoft Office Web Apps 2010 Service Pack 2, and Microsoft Office Compatibility Pack Service Pack 3 when they fail to properly handle objects in memory, aka "PowerPoint Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-8743.
Published 2017-09-13 · Modified
9.3EPSS 0.221
CVE-2018-1028
A remote code execution vulnerability exists when the Office graphics component improperly handles specially crafted embedded fonts, aka "Microsoft Office Graphics Remote Code Execution Vulnerability." This affects Word, Microsoft Office, Microsoft SharePoint, Excel, Microsoft SharePoint Server.
Published 2018-04-12 · Modified
9.3EPSS 0.189
CVE-2018-0922
Microsoft Office 2010 SP2, 2013 SP1, and 2016, Microsoft Office 2016 Click-to-Run Microsoft Office 2016 for Mac, Microsoft Office Compatibility Pack SP2, Microsoft Office Web Apps 2010 SP2, Microsoft Office Web Apps 2013 SP1, Microsoft Office Word Viewer, Microsoft SharePoint Enterprise Server 2013 SP1, Microsoft SharePoint Enterprise Server 2016, Microsoft Office Compatibility Pack SP2, Microsoft Online Server 2016, Microsoft SharePoint Server 2010 SP2, Microsoft Word 2007 SP3, Microsoft Word 2010 SP2, Word 2013 and Microsoft Word 2016 allow a remote code execution vulnerability due to how objects are handled in memory, aka "Microsoft Office Memory Corruption Vulnerability".
Published 2018-03-14 · Modified
9.3EPSS 0.180
CVE-2018-8628
A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fails to properly handle objects in memory, aka "Microsoft PowerPoint Remote Code Execution Vulnerability." This affects Microsoft Office, Office 365 ProPlus, Microsoft PowerPoint, Microsoft SharePoint, Microsoft PowerPoint Viewer, Office Online Server, Microsoft SharePoint Server.
Published 2018-12-12 · Modified
9.3EPSS 0.159
CVE-2020-0892
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0850, CVE-2020-0851, CVE-2020-0852, CVE-2020-0855.
Published 2020-03-12 · Modified
9.3EPSS 0.118
CVE-2020-0980
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'.
Published 2020-04-15 · Modified
9.3EPSS 0.118
CVE-2019-1034
Microsoft Word Remote Code Execution Vulnerability
Published 2019-06-12 · Modified
9.3EPSS 0.049
CVE-2019-1201
Microsoft Word Remote Code Execution Vulnerability
Published 2019-08-14 · Modified
9.3EPSS 0.049
CVE-2021-1716
Microsoft Word Remote Code Execution Vulnerability
Published 2021-01-12 · Modified
9.3EPSS 0.036
CVE-2021-1715
Microsoft Word Remote Code Execution Vulnerability
Published 2021-01-12 · Modified
9.3EPSS 0.036
CVE-2018-0789
Microsoft SharePoint Foundation 2010, Microsoft SharePoint Server 2013 and Microsoft SharePoint Server 2016 allow an elevation of privilege vulnerability due to the way web requests are handled, aka "Microsoft SharePoint Elevation of Privilege Vulnerability". This CVE is unique from CVE-2018-0790.
Published 2018-01-10 · Modified
9.0EPSS 0.064
CVE-2021-1707
Microsoft SharePoint Server Remote Code Execution Vulnerability
Published 2021-01-12 · Modified
9.0EPSS 0.036
CVE-2022-38053
Microsoft SharePoint Server Remote Code Execution Vulnerability
Published 2022-10-11 · Modified
8.8EPSS 0.764
CVE-2020-1181
A remote code execution vulnerability exists in Microsoft SharePoint Server when it fails to properly identify and filter unsafe ASP.Net web controls, aka 'Microsoft SharePoint Server Remote Code Execution Vulnerability'.
Published 2020-06-09 · Modified
8.8EPSS 0.693
CVE-2022-35823
Microsoft SharePoint Remote Code Execution Vulnerability
Published 2022-09-13 · Modified
8.8EPSS 0.536
CVE-2022-37961
Microsoft SharePoint Server Remote Code Execution Vulnerability
Published 2022-09-13 · Modified
8.8EPSS 0.507
CVE-2021-40487
Microsoft SharePoint Server Remote Code Execution Vulnerability
Published 2021-10-13 · Modified
8.8EPSS 0.482
CVE-2020-0932
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0920, CVE-2020-0929, CVE-2020-0931, CVE-2020-0971, CVE-2020-0974.
Published 2020-04-15 · Modified
8.8EPSS 0.353
CVE-2021-31181
Microsoft SharePoint Remote Code Execution Vulnerability
Published 2021-05-11 · Modified
8.8EPSS 0.288
CVE-2025-47166
Microsoft SharePoint Server Remote Code Execution Vulnerability
Published 2025-06-10 · Analyzed
8.81 PoCEPSS 0.212
CVE-2025-47163
Microsoft SharePoint Server Remote Code Execution Vulnerability
Published 2025-06-10 · Analyzed
8.8EPSS 0.205
CVE-2020-1439
A remote code execution vulnerability exists in PerformancePoint Services for SharePoint Server when the software fails to check the source markup of XML file input, aka 'PerformancePoint Services Remote Code Execution Vulnerability'.
Published 2020-07-14 · Modified
8.8EPSS 0.203
CVE-2022-22005
Microsoft SharePoint Server Remote Code Execution Vulnerability
Published 2022-02-09 · Modified
8.8EPSS 0.164
CVE-2018-8300
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka "Microsoft SharePoint Remote Code Execution Vulnerability." This affects Microsoft SharePoint.
Published 2018-07-11 · Modified
8.8EPSS 0.136
CVE-2020-0971
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0920, CVE-2020-0929, CVE-2020-0931, CVE-2020-0932, CVE-2020-0974.
Published 2020-04-15 · Modified
8.8EPSS 0.132
CVE-2019-0594
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0604.
Published 2019-03-06 · Modified
8.8EPSS 0.121
CVE-2022-29108
Microsoft SharePoint Server Remote Code Execution Vulnerability
Published 2022-05-10 · Modified
8.8EPSS 0.119
CVE-2019-1257
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1295, CVE-2019-1296.
Published 2019-09-11 · Modified
8.8EPSS 0.117
CVE-2020-1446
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1447, CVE-2020-1448.
Published 2020-07-14 · Modified
8.8EPSS 0.112
CVE-2020-0974
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0920, CVE-2020-0929, CVE-2020-0931, CVE-2020-0932, CVE-2020-0971.
Published 2020-04-15 · Modified
8.8EPSS 0.107
1 / 7Next →