VendorsMicrosoftsharepoint_serverall versions
Vulnerabilities

Microsoft Sharepoint Server

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

604CVEs
CVE-2020-1439
A remote code execution vulnerability exists in PerformancePoint Services for SharePoint Server when the software fails to check the source markup of XML file input, aka 'PerformancePoint Services Remote Code Execution Vulnerability'.
Published 2020-07-14 · Modified
8.8EPSS 0.203
CVE-2025-49712
Microsoft SharePoint Remote Code Execution Vulnerability
Published 2025-08-12 · Analyzed
8.8EPSS 0.192
CVE-2025-54897
Microsoft SharePoint Remote Code Execution Vulnerability
Published 2025-09-09 · Analyzed
8.8EPSS 0.191
CVE-2026-20947
Microsoft SharePoint Server Remote Code Execution Vulnerability
Published 2026-01-13 · Analyzed
8.8EPSS 0.188
CVE-2022-22005
Microsoft SharePoint Server Remote Code Execution Vulnerability
Published 2022-02-09 · Modified
8.8EPSS 0.164
CVE-2021-27076
Microsoft SharePoint Server Remote Code Execution Vulnerability
Published 2021-03-11 · Modified
8.8EPSS 0.152
CVE-2020-0971
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0920, CVE-2020-0929, CVE-2020-0931, CVE-2020-0932, CVE-2020-0974.
Published 2020-04-15 · Modified
8.8EPSS 0.132
CVE-2019-0594
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0604.
Published 2019-03-06 · Modified
8.8EPSS 0.121
CVE-2022-29108
Microsoft SharePoint Server Remote Code Execution Vulnerability
Published 2022-05-10 · Modified
8.8EPSS 0.119
CVE-2019-1257
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1295, CVE-2019-1296.
Published 2019-09-11 · Modified
8.8EPSS 0.117
CVE-2020-1446
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1447, CVE-2020-1448.
Published 2020-07-14 · Modified
8.8EPSS 0.112
CVE-2020-0931
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0920, CVE-2020-0929, CVE-2020-0932, CVE-2020-0971, CVE-2020-0974.
Published 2020-04-15 · Modified
8.8EPSS 0.107
CVE-2020-0929
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0920, CVE-2020-0931, CVE-2020-0932, CVE-2020-0971, CVE-2020-0974.
Published 2020-04-15 · Modified
8.8EPSS 0.107
CVE-2020-0974
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0920, CVE-2020-0929, CVE-2020-0931, CVE-2020-0932, CVE-2020-0971.
Published 2020-04-15 · Modified
8.8EPSS 0.107
CVE-2020-1447
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1446, CVE-2020-1448.
Published 2020-07-14 · Modified
8.8EPSS 0.106
CVE-2020-0920
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0929, CVE-2020-0931, CVE-2020-0932, CVE-2020-0971, CVE-2020-0974.
Published 2020-04-15 · Modified
8.8EPSS 0.104
CVE-2020-1448
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1446, CVE-2020-1447.
Published 2020-07-14 · Modified
8.8EPSS 0.100
CVE-2020-0850
A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft Word Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0851, CVE-2020-0852, CVE-2020-0855, CVE-2020-0892.
Published 2020-03-12 · Modified
8.8EPSS 0.088
CVE-2019-1295
A remote code execution vulnerability exists in Microsoft SharePoint where APIs aren't properly protected from unsafe data input, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1257, CVE-2019-1296.
Published 2019-09-11 · Modified
8.8EPSS 0.083
CVE-2019-1296
A remote code execution vulnerability exists in Microsoft SharePoint where APIs aren't properly protected from unsafe data input, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-1257, CVE-2019-1295.
Published 2019-09-11 · Modified
8.8EPSS 0.083
CVE-2022-30157
Microsoft SharePoint Server Remote Code Execution Vulnerability
Published 2022-06-15 · Modified
8.8EPSS 0.070
CVE-2021-34467
Microsoft SharePoint Server Remote Code Execution Vulnerability
Published 2021-07-16 · Modified
8.8EPSS 0.066
CVE-2021-41344
Microsoft SharePoint Server Remote Code Execution Vulnerability
Published 2021-10-13 · Modified
8.8EPSS 0.065
CVE-2021-24066
Microsoft SharePoint Remote Code Execution Vulnerability
Published 2021-02-25 · Modified
8.8EPSS 0.063
CVE-2018-8635
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted authentication request to an affected SharePoint server, aka "Microsoft SharePoint Server Elevation of Privilege Vulnerability." This affects Microsoft SharePoint Server, Microsoft SharePoint.
Published 2018-12-12 · Modified
8.8EPSS 0.061
CVE-2017-8569
Microsoft SharePoint Server allows an elevation of privilege vulnerability due to the way that it sanitizes a specially crafted web request to an affected SharePoint server, aka "SharePoint Server XSS Vulnerability".
Published 2017-07-11 · Modified
8.8EPSS 0.054
CVE-2020-1102
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1023, CVE-2020-1024.
Published 2020-05-21 · Modified
8.8EPSS 0.052
CVE-2025-29794
Microsoft SharePoint Remote Code Execution Vulnerability
Published 2025-04-08 · Analyzed
8.8EPSS 0.051
CVE-2020-1583
Microsoft Word Information Disclosure Vulnerability
Published 2020-08-17 · Modified
8.8EPSS 0.049
CVE-2021-34520
Microsoft SharePoint Server Remote Code Execution Vulnerability
Published 2021-07-14 · Modified
8.8EPSS 0.044
CVE-2023-33160
Microsoft SharePoint Server Remote Code Execution Vulnerability
Published 2023-07-11 · Modified
8.8EPSS 0.043
CVE-2020-17061
Microsoft SharePoint Remote Code Execution Vulnerability
Published 2020-11-11 · Modified
8.8EPSS 0.043
CVE-2020-1069
A remote code execution vulnerability exists in Microsoft SharePoint Server when it fails to properly identify and filter unsafe ASP.Net web controls, aka 'Microsoft SharePoint Server Remote Code Execution Vulnerability'.
Published 2020-05-21 · Modified
8.8EPSS 0.040
CVE-2020-1338
Microsoft Word Remote Code Execution Vulnerability
Published 2020-09-11 · Modified
8.8EPSS 0.039
CVE-2020-1335
Microsoft Excel Remote Code Execution Vulnerability
Published 2020-09-11 · Modified
8.8EPSS 0.039
CVE-2020-1218
Microsoft Word Remote Code Execution Vulnerability
Published 2020-09-11 · Modified
8.8EPSS 0.038
CVE-2020-1024
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1023, CVE-2020-1102.
Published 2020-05-21 · Modified
8.8EPSS 0.037
CVE-2020-1023
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1024, CVE-2020-1102.
Published 2020-05-21 · Modified
8.8EPSS 0.037
CVE-2020-1460
Microsoft SharePoint Server Remote Code Execution Vulnerability
Published 2020-09-11 · Modified
8.8EPSS 0.037
CVE-2022-30158
Microsoft SharePoint Server Remote Code Execution Vulnerability
Published 2022-06-15 · Modified
8.8EPSS 0.034
← Prev4 / 16Next →