VendorsMicrosoftsharepoint_serverall versions
Vulnerabilities

Microsoft Sharepoint Server

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

604CVEs
CVE-2012-1862
Open redirect vulnerability in Microsoft Office SharePoint Server 2007 SP2 and SP3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL, aka "SharePoint URL Redirection Vulnerability."
Published 2012-07-10 · Modified
6.8EPSS 0.108
CVE-2013-5059
Microsoft SharePoint Server 2010 SP1 and SP2 and 2013, and Office Web Apps 2013, allows remote attackers to execute arbitrary code via crafted page content, aka "SharePoint Page Content Vulnerabilities."
Published 2013-12-11 · Modified
6.8EPSS 0.107
CVE-2020-17017
Microsoft SharePoint Information Disclosure Vulnerability
Published 2020-11-11 · Modified
6.8EPSS 0.038
CVE-2023-38177
Microsoft SharePoint Server Remote Code Execution Vulnerability
Published 2023-11-14 · Modified
6.8EPSS 0.034
CVE-2024-26251
Microsoft SharePoint Server Spoofing Vulnerability
Published 2024-04-09 · Analyzed
6.8EPSS 0.014
CVE-2025-53736
Microsoft Word Information Disclosure Vulnerability
Published 2025-08-12 · Analyzed
6.8EPSS 0.005
CVE-2025-53771
Microsoft SharePoint Server Spoofing Vulnerability
Published 2025-07-20 · Analyzed
6.5EPSS 0.998
CVE-2025-49706
Microsoft SharePoint Server Spoofing Vulnerability
Published 2025-07-08 · Analyzed
6.5KEVEPSS 0.991
CVE-2023-24950
Microsoft SharePoint Server Spoofing Vulnerability
Published 2023-05-09 · Modified
6.5EPSS 0.675
CVE-2016-7233
Microsoft Word 2007, Office 2010 SP2, Word 2010 SP2, Word for Mac 2011, Excel for Mac 2011, Word Viewer, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2013 SP1, and Office Web Apps 2010 SP2 allow remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read) via a crafted Office document, aka "Microsoft Office Information Disclosure Vulnerability."
Published 2016-11-10 · Modified
6.5EPSS 0.224
CVE-2018-8160
An information disclosure vulnerability exists in Outlook when a message is opened, aka "Microsoft Outlook Information Disclosure Vulnerability." This affects Word, Microsoft Office.
Published 2018-05-09 · Modified
6.5EPSS 0.086
CVE-2019-1443
An information disclosure vulnerability exists in Microsoft SharePoint when an attacker uploads a specially crafted file to the SharePoint Server.An authenticated attacker who successfully exploited this vulnerability could potentially leverage SharePoint functionality to obtain SMB hashes.The security update addresses the vulnerability by correcting how SharePoint checks file content., aka 'Microsoft SharePoint Information Disclosure Vulnerability'.
Published 2019-11-12 · Modified
6.5EPSS 0.057
CVE-2021-31965
Microsoft SharePoint Server Information Disclosure Vulnerability
Published 2021-06-08 · Modified
6.5EPSS 0.045
CVE-2020-16948
Microsoft SharePoint Information Disclosure Vulnerability
Published 2020-10-16 · Modified
6.5EPSS 0.038
CVE-2020-16953
Microsoft SharePoint Information Disclosure Vulnerability
Published 2020-10-16 · Modified
6.5EPSS 0.038
CVE-2024-49062
Microsoft SharePoint Information Disclosure Vulnerability
Published 2024-12-10 · Analyzed
6.5EPSS 0.032
CVE-2020-16979
Microsoft SharePoint Information Disclosure Vulnerability
Published 2020-11-11 · Modified
6.5EPSS 0.031
CVE-2020-17120
Microsoft SharePoint Information Disclosure Vulnerability
Published 2020-12-09 · Modified
6.5EPSS 0.031
CVE-2021-27052
Microsoft SharePoint Server Information Disclosure Vulnerability
Published 2021-03-11 · Modified
6.5EPSS 0.029
CVE-2021-24071
Microsoft SharePoint Information Disclosure Vulnerability
Published 2021-02-25 · Modified
6.5EPSS 0.027
CVE-2019-1260
An elevation of privilege vulnerability exists in Microsoft SharePoint, aka 'Microsoft SharePoint Elevation of Privilege Vulnerability'.
Published 2019-09-11 · Modified
6.5EPSS 0.026
CVE-2024-49064
Microsoft SharePoint Information Disclosure Vulnerability
Published 2024-12-10 · Analyzed
6.5EPSS 0.025
CVE-2021-28450
Microsoft SharePoint Denial of Service Vulnerability
Published 2021-04-13 · Modified
6.5EPSS 0.024
CVE-2020-1103
An information disclosure vulnerability exists where certain modes of the search function in Microsoft SharePoint Server are vulnerable to cross-site search attacks (a variant of cross-site request forgery, CSRF).When users are simultaneously logged in to Microsoft SharePoint Server and visit a malicious web page, the attacker can, through standard browser functionality, induce the browser to invoke search queries as the logged in user, aka 'Microsoft SharePoint Information Disclosure Vulnerability'.
Published 2020-05-21 · Modified
6.5EPSS 0.024
CVE-2021-31173
Microsoft SharePoint Server Information Disclosure Vulnerability
Published 2021-05-11 · Modified
6.5EPSS 0.021
CVE-2023-36894
Microsoft SharePoint Server Information Disclosure Vulnerability
Published 2023-08-08 · Modified
6.5EPSS 0.021
CVE-2020-17015
Microsoft SharePoint Server Spoofing Vulnerability
Published 2020-11-11 · Modified
6.5EPSS 0.020
CVE-2023-33129
Microsoft SharePoint Server Denial of Service Vulnerability
Published 2023-06-13 · Modified
6.5EPSS 0.020
CVE-2026-63516
Microsoft SharePoint Server Spoofing Vulnerability
Published 2026-08-11 · Analyzed
6.5EPSS 0.019
CVE-2023-36890
Microsoft SharePoint Server Information Disclosure Vulnerability
Published 2023-08-08 · Modified
6.5EPSS 0.019
CVE-2023-24954
Microsoft SharePoint Server Information Disclosure Vulnerability
Published 2023-05-09 · Modified
6.5EPSS 0.018
CVE-2022-41122
Microsoft SharePoint Server Spoofing Vulnerability
Published 2022-11-09 · Modified
6.5EPSS 0.016
CVE-2026-62837
Microsoft SharePoint Server Information Disclosure Vulnerability
Published 2026-08-11 · Analyzed
6.5EPSS 0.012
CVE-2026-54108
Microsoft SharePoint Server Spoofing Vulnerability
Published 2026-07-14 · Analyzed
6.5EPSS 0.011
CVE-2023-33142
Microsoft SharePoint Server Elevation of Privilege Vulnerability
Published 2023-06-13 · Modified
6.5EPSS 0.010
CVE-2026-69409
Microsoft Office SharePoint Information Disclosure Vulnerability
Published 2026-09-08 · Analyzed
6.5EPSS 0.010
CVE-2026-69636
Microsoft Office SharePoint Information Disclosure Vulnerability
Published 2026-09-08 · Analyzed
6.5EPSS 0.010
CVE-2026-32201
Microsoft SharePoint Server Spoofing Vulnerability
Published 2026-04-14 · Analyzed
6.5KEVEPSS 0.010
CVE-2026-62839
Microsoft SharePoint Server Spoofing Vulnerability
Published 2026-08-11 · Analyzed
6.5EPSS 0.009
CVE-2026-55051
Microsoft SharePoint Server Information Disclosure Vulnerability
Published 2026-07-14 · Analyzed
6.5EPSS 0.009
← Prev10 / 16Next →