VendorsMicrosoftsharepoint_serverall versions
Vulnerabilities

Microsoft Sharepoint Server

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

604CVEs
CVE-2024-49065
Microsoft Office Remote Code Execution Vulnerability
Published 2024-12-10 · Analyzed
5.5EPSS 0.011
CVE-2022-41103
Microsoft Word Information Disclosure Vulnerability
Published 2022-11-09 · Modified
5.5EPSS 0.009
CVE-2020-16941
Microsoft SharePoint Information Disclosure Vulnerability
Published 2020-10-16 · Modified
5.5EPSS 0.009
CVE-2022-41060
Microsoft Word Information Disclosure Vulnerability
Published 2022-11-09 · Modified
5.5EPSS 0.008
CVE-2026-55023
Microsoft Office Information Disclosure Vulnerability
Published 2026-07-14 · Analyzed
5.5EPSS 0.006
CVE-2026-55027
Microsoft Office Information Disclosure Vulnerability
Published 2026-07-14 · Analyzed
5.5EPSS 0.006
CVE-2026-55028
Microsoft Office Information Disclosure Vulnerability
Published 2026-07-14 · Analyzed
5.5EPSS 0.006
CVE-2026-55047
Microsoft Office Information Disclosure Vulnerability
Published 2026-07-14 · Analyzed
5.5EPSS 0.006
CVE-2026-55050
Microsoft Word Information Disclosure Vulnerability
Published 2026-07-14 · Analyzed
5.5EPSS 0.006
CVE-2026-55124
Microsoft Word Information Disclosure Vulnerability
Published 2026-07-14 · Analyzed
5.5EPSS 0.006
CVE-2026-55142
Microsoft Word Information Disclosure Vulnerability
Published 2026-07-14 · Analyzed
5.5EPSS 0.006
CVE-2026-56192
Microsoft Office Information Disclosure Vulnerability
Published 2026-07-14 · Analyzed
5.5EPSS 0.006
CVE-2026-44821
Microsoft Office Information Disclosure Vulnerability
Published 2026-06-09 · Analyzed
5.5EPSS 0.006
CVE-2026-55035
Microsoft Office Information Disclosure Vulnerability
Published 2026-07-14 · Analyzed
5.5EPSS 0.006
CVE-2026-55121
Microsoft Office Information Disclosure Vulnerability
Published 2026-07-14 · Analyzed
5.5EPSS 0.005
CVE-2026-20945
Microsoft SharePoint Server Spoofing Vulnerability
Published 2026-04-14 · Analyzed
5.4EPSS 0.191
CVE-2026-20959
Microsoft SharePoint Server Spoofing Vulnerability
Published 2026-01-13 · Analyzed
5.4EPSS 0.076
CVE-2016-0011
Microsoft SharePoint Server 2013 SP1 and SharePoint Foundation 2013 SP1 allow remote authenticated users to bypass intended Access Control Policy restrictions and conduct cross-site scripting (XSS) attacks by modifying a webpart, aka "Microsoft SharePoint Security Feature Bypass," a different vulnerability than CVE-2015-6117.
Published 2016-01-13 · Modified
5.4EPSS 0.053
CVE-2017-0195
Microsoft Excel Services on Microsoft SharePoint Server 2010 SP1 and SP2, Microsoft Excel Web Apps 2010 SP2, Microsoft Office Web Apps 2010 SP2, Microsoft Office Web Apps Server 2013 SP1 and Office Online Server allows remote attackers to perform cross-site scripting and run script with local user privileges via a crafted request, aka "Microsoft Office XSS Elevation of Privilege Vulnerability."
Published 2017-04-12 · Modified
5.4EPSS 0.038
CVE-2018-8149
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft SharePoint Server, Microsoft SharePoint. This CVE ID is unique from CVE-2018-8155, CVE-2018-8156, CVE-2018-8168.
Published 2018-05-09 · Modified
5.4EPSS 0.029
CVE-2018-8155
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft SharePoint. This CVE ID is unique from CVE-2018-8149, CVE-2018-8156, CVE-2018-8168.
Published 2018-05-09 · Modified
5.4EPSS 0.029
CVE-2018-8156
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft SharePoint, Microsoft Project Server. This CVE ID is unique from CVE-2018-8149, CVE-2018-8155, CVE-2018-8168.
Published 2018-05-09 · Modified
5.4EPSS 0.029
CVE-2018-8252
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft SharePoint. This CVE ID is unique from CVE-2018-8254.
Published 2018-06-14 · Modified
5.4EPSS 0.028
CVE-2018-8254
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft Project Server, Microsoft SharePoint. This CVE ID is unique from CVE-2018-8252.
Published 2018-06-14 · Modified
5.4EPSS 0.028
CVE-2018-0864
SharePoint Project Server 2013 and SharePoint Enterprise Server 2016 allow an information disclosure vulnerability due to how web requests are handled, aka "Microsoft SharePoint Information Disclosure Vulnerability".
Published 2018-02-15 · Modified
5.4EPSS 0.026
CVE-2018-8168
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft SharePoint Server, Microsoft SharePoint. This CVE ID is unique from CVE-2018-8149, CVE-2018-8155, CVE-2018-8156.
Published 2018-05-09 · Modified
5.4EPSS 0.024
CVE-2017-8629
Microsoft SharePoint Server 2013 Service Pack 1 allows an elevation of privilege vulnerability when it fails to properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint XSS Vulnerability".
Published 2017-09-13 · Modified
5.4EPSS 0.024
CVE-2018-8568
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft SharePoint Server, Microsoft SharePoint. This CVE ID is unique from CVE-2018-8572.
Published 2018-11-14 · Modified
5.4EPSS 0.023
CVE-2018-8431
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft SharePoint Server, Microsoft SharePoint. This CVE ID is unique from CVE-2018-8428.
Published 2018-09-13 · Modified
5.4EPSS 0.023
CVE-2020-1456
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE-2020-1450, CVE-2020-1451.
Published 2020-07-14 · Modified
5.4EPSS 0.022
CVE-2017-8654
Microsoft SharePoint Server 2010 Service Pack 2 allows a cross-site scripting (XSS) vulnerability when it does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft Office SharePoint XSS Vulnerability".
Published 2017-08-08 · Modified
5.4EPSS 0.021
CVE-2019-0557
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft Office SharePoint XSS Vulnerability." This affects Microsoft SharePoint. This CVE ID is unique from CVE-2019-0556, CVE-2019-0558.
Published 2019-01-08 · Modified
5.4EPSS 0.021
CVE-2019-0558
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft Office SharePoint XSS Vulnerability." This affects Microsoft SharePoint Server, Microsoft SharePoint, Microsoft Business Productivity Servers. This CVE ID is unique from CVE-2019-0556, CVE-2019-0557.
Published 2019-01-08 · Modified
5.4EPSS 0.020
CVE-2020-0924
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE-2020-0923, CVE-2020-0925, CVE-2020-0926, CVE-2020-0927, CVE-2020-0930, CVE-2020-0933, CVE-2020-0954, CVE-2020-0973, CVE-2020-0978.
Published 2020-04-15 · Modified
5.4EPSS 0.018
CVE-2020-1100
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE-2020-1099, CVE-2020-1101, CVE-2020-1106.
Published 2020-05-21 · Modified
5.4EPSS 0.017
CVE-2020-1099
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE-2020-1100, CVE-2020-1101, CVE-2020-1106.
Published 2020-05-21 · Modified
5.4EPSS 0.017
CVE-2020-1101
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE-2020-1099, CVE-2020-1100, CVE-2020-1106.
Published 2020-05-21 · Modified
5.4EPSS 0.017
CVE-2019-1203
Microsoft Office SharePoint XSS Vulnerability
Published 2019-08-14 · Modified
5.4EPSS 0.017
CVE-2020-1104
A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Spoofing Vulnerability'. This CVE ID is unique from CVE-2020-1105, CVE-2020-1107.
Published 2020-05-21 · Modified
5.4EPSS 0.017
CVE-2020-1105
A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Spoofing Vulnerability'. This CVE ID is unique from CVE-2020-1104, CVE-2020-1107.
Published 2020-05-21 · Modified
5.4EPSS 0.017
← Prev12 / 16Next →