VendorsMicrosoftsharepoint_serverall versions
Vulnerabilities

Microsoft Sharepoint Server

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

604CVEs
CVE-2026-62839
Microsoft SharePoint Server Spoofing Vulnerability
Published 2026-08-11 · Analyzed
6.5EPSS 0.009
CVE-2026-63512
Microsoft SharePoint Server Tampering Vulnerability
Published 2026-08-11 · Analyzed
6.5EPSS 0.007
CVE-2020-1482
Microsoft Office SharePoint XSS Vulnerability
Published 2020-09-11 · Modified
6.3EPSS 0.020
CVE-2020-1440
Microsoft SharePoint Server Tampering Vulnerability
Published 2020-09-11 · Modified
6.3EPSS 0.018
CVE-2025-21393
Microsoft SharePoint Server Spoofing Vulnerability
Published 2025-01-14 · Analyzed
6.3EPSS 0.011
CVE-2023-33132
Microsoft SharePoint Server Spoofing Vulnerability
Published 2023-06-13 · Modified
6.3EPSS 0.009
CVE-2026-55026
Microsoft Office Information Disclosure Vulnerability
Published 2026-07-14 · Analyzed
6.2EPSS 0.004
CVE-2015-6117
Microsoft SharePoint Server 2013 SP1 and SharePoint Foundation 2013 SP1 allow remote authenticated users to bypass intended Access Control Policy restrictions and conduct cross-site scripting (XSS) attacks by modifying a webpart, aka "Microsoft SharePoint Security Feature Bypass," a different vulnerability than CVE-2016-0011.
Published 2016-01-13 · Modified
6.1EPSS 0.069
CVE-2020-1106
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE-2020-1099, CVE-2020-1100, CVE-2020-1101.
Published 2020-05-21 · Modified
6.1EPSS 0.040
CVE-2020-1323
An open redirect vulnerability exists in Microsoft SharePoint that could lead to spoofing.To exploit the vulnerability, an attacker could send a link that has a specially crafted URL and convince the user to click the link, aka 'SharePoint Open Redirect Vulnerability'.
Published 2020-06-09 · Modified
6.1EPSS 0.021
CVE-2026-33113
Microsoft SharePoint Server Spoofing Vulnerability
Published 2026-06-09 · Modified
6.1EPSS 0.006
CVE-2015-1700
Microsoft SharePoint Server 2007 SP3, SharePoint Foundation 2010 SP2, SharePoint Server 2010 SP2, and SharePoint Foundation 2013 SP1 allow remote authenticated users to execute arbitrary code via crafted page content, aka "Microsoft SharePoint Page Content Vulnerabilities."
Published 2015-05-13 · Modified
6.0EPSS 0.121
CVE-2020-17060
Microsoft SharePoint Server Spoofing Vulnerability
Published 2020-11-11 · Modified
5.8EPSS 0.019
CVE-2021-1717
Microsoft SharePoint Server Spoofing Vulnerability
Published 2021-01-12 · Modified
5.8EPSS 0.018
CVE-2021-1641
Microsoft SharePoint Server Spoofing Vulnerability
Published 2021-01-12 · Modified
5.8EPSS 0.018
CVE-2021-24104
Microsoft SharePoint Server Spoofing Vulnerability
Published 2021-03-11 · Modified
5.8EPSS 0.014
CVE-2019-0949
A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-0950, CVE-2019-0951.
Published 2019-05-16 · Modified
5.7EPSS 0.025
CVE-2019-0950
A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-0949, CVE-2019-0951.
Published 2019-05-16 · Modified
5.7EPSS 0.025
CVE-2017-0105
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word for Mac 2011, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2010 SP2, and Office Web Apps 2010 SP2 allow remote attackers to obtain sensitive information from out-of-bound memory via a crafted Office document, aka "Microsoft Office Information Disclosure Vulnerability."
Published 2017-03-17 · Modified
5.5EPSS 0.304
CVE-2016-3234
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Office Compatibility Pack SP3, Word Viewer, Word Automation Services on SharePoint Server 2010 SP2, Word Automation Services on SharePoint Server 2013 SP1, Office Web Apps 2010 SP2, and Office Web Apps Server 2013 SP1 allow remote attackers to obtain sensitive information from process memory via a crafted Office document, aka "Microsoft Office Information Disclosure Vulnerability."
Published 2016-06-16 · Modified
5.5EPSS 0.241
CVE-2016-3279
Microsoft Office 2010 SP2, Excel 2010 SP2, PowerPoint 2010 SP2, Word 2010 SP2, Excel 2013 SP1, PowerPoint 2013 SP1, Word 2013 SP1, Excel 2013 RT SP1, PowerPoint 2013 RT SP1, Word 2013 RT SP1, Excel 2016, Word 2016, Word Automation Services on SharePoint Server 2010 SP2, and Office Web Apps 2010 SP2 allow remote attackers to execute arbitrary code via a crafted XLA file, aka "Microsoft Office Remote Code Execution Vulnerability."
Published 2016-07-13 · Modified
5.5EPSS 0.164
CVE-2012-1860
Microsoft Office SharePoint Server 2007 SP2 and SP3, SharePoint Server 2010 Gold and SP1, and Office Web Apps 2010 Gold and SP1 do not properly check permissions for search scopes, which allows remote authenticated users to obtain sensitive information or cause a denial of service (data modification) by changing a parameter in a search-scope URL, aka "SharePoint Search Scope Vulnerability."
Published 2012-07-10 · Modified
5.5EPSS 0.130
CVE-2019-1446
An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka 'Microsoft Excel Information Disclosure Vulnerability'.
Published 2019-11-12 · Modified
5.5EPSS 0.089
CVE-2018-8627
An information disclosure vulnerability exists when Microsoft Excel software reads out of bound memory due to an uninitialized variable, which could disclose the contents of memory, aka "Microsoft Excel Information Disclosure Vulnerability." This affects Microsoft Office, Office 365 ProPlus, Microsoft Excel, Microsoft Excel Viewer, Excel. This CVE ID is unique from CVE-2018-8598.
Published 2018-12-12 · Modified
5.5EPSS 0.086
CVE-2018-8378
An information disclosure vulnerability exists when Microsoft Office software reads out of bound memory due to an uninitialized variable, which could disclose the contents of memory, aka "Microsoft Office Information Disclosure Vulnerability." This affects Word, Microsoft SharePoint Server, Microsoft Office Word Viewer, Microsoft Excel Viewer, Microsoft SharePoint, Microsoft Office.
Published 2018-08-15 · Modified
5.5EPSS 0.082
CVE-2019-0561
An information disclosure vulnerability exists when Microsoft Word macro buttons are used improperly, aka "Microsoft Word Information Disclosure Vulnerability." This affects Microsoft Word, Office 365 ProPlus, Microsoft Office, Word.
Published 2019-01-08 · Modified
5.5EPSS 0.079
CVE-2020-1342
An information disclosure vulnerability exists when Microsoft Office software reads out of bound memory due to an uninitialized variable, which could disclose the contents of memory, aka 'Microsoft Office Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-1445.
Published 2020-07-14 · Modified
5.5EPSS 0.064
CVE-2020-1502
Microsoft Word Information Disclosure Vulnerability
Published 2020-08-17 · Modified
5.5EPSS 0.046
CVE-2022-22716
Microsoft Excel Information Disclosure Vulnerability
Published 2022-02-09 · Modified
5.5EPSS 0.046
CVE-2020-1503
Microsoft Word Information Disclosure Vulnerability
Published 2020-08-17 · Modified
5.5EPSS 0.046
CVE-2020-16950
Microsoft SharePoint Information Disclosure Vulnerability
Published 2020-10-16 · Modified
5.5EPSS 0.042
CVE-2022-30172
Microsoft Office Information Disclosure Vulnerability
Published 2022-06-15 · Modified
5.5EPSS 0.027
CVE-2022-30159
Microsoft Office Information Disclosure Vulnerability
Published 2022-06-15 · Modified
5.5EPSS 0.027
CVE-2022-30171
Microsoft Office Information Disclosure Vulnerability
Published 2022-06-15 · Modified
5.5EPSS 0.026
CVE-2019-1442
A security feature bypass vulnerability exists when Microsoft Office does not validate URLs.An attacker could send a victim a specially crafted file, which could trick the victim into entering credentials, aka 'Microsoft Office Security Feature Bypass Vulnerability'.
Published 2019-11-12 · Modified
5.5EPSS 0.022
CVE-2020-1573
Microsoft Office SharePoint XSS Vulnerability
Published 2020-08-17 · Modified
5.5EPSS 0.019
CVE-2020-1500
Microsoft SharePoint Spoofing Vulnerability
Published 2020-08-17 · Modified
5.5EPSS 0.018
CVE-2020-1499
Microsoft SharePoint Spoofing Vulnerability
Published 2020-08-17 · Modified
5.5EPSS 0.018
CVE-2020-1501
Microsoft SharePoint Spoofing Vulnerability
Published 2020-08-17 · Modified
5.5EPSS 0.017
CVE-2020-1505
Microsoft SharePoint Information Disclosure Vulnerability
Published 2020-08-17 · Modified
5.5EPSS 0.013
← Prev11 / 16Next →