VendorsMicrosoftsharepoint_server2016
Vulnerabilities

Microsoft Sharepoint Server 2016

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

235CVEs
CVE-2021-31173
Microsoft SharePoint Server Information Disclosure Vulnerability
Published 2021-05-11 · Modified
6.5EPSS 0.021
CVE-2023-36894
Microsoft SharePoint Server Information Disclosure Vulnerability
Published 2023-08-08 · Modified
6.5EPSS 0.021
CVE-2026-63516
Microsoft SharePoint Server Spoofing Vulnerability
Published 2026-08-11 · Analyzed
6.5EPSS 0.019
CVE-2026-62837
Microsoft SharePoint Server Information Disclosure Vulnerability
Published 2026-08-11 · Analyzed
6.5EPSS 0.012
CVE-2026-54108
Microsoft SharePoint Server Spoofing Vulnerability
Published 2026-07-14 · Analyzed
6.5EPSS 0.011
CVE-2026-32201
Microsoft SharePoint Server Spoofing Vulnerability
Published 2026-04-14 · Analyzed
6.5KEVEPSS 0.010
CVE-2026-58639
Microsoft SharePoint Server Spoofing Vulnerability
Published 2026-08-11 · Analyzed
6.5EPSS 0.009
CVE-2026-62839
Microsoft SharePoint Server Spoofing Vulnerability
Published 2026-08-11 · Analyzed
6.5EPSS 0.009
CVE-2026-55051
Microsoft SharePoint Server Information Disclosure Vulnerability
Published 2026-07-14 · Analyzed
6.5EPSS 0.009
CVE-2026-63512
Microsoft SharePoint Server Tampering Vulnerability
Published 2026-08-11 · Analyzed
6.5EPSS 0.007
CVE-2025-21393
Microsoft SharePoint Server Spoofing Vulnerability
Published 2025-01-14 · Analyzed
6.3EPSS 0.011
CVE-2026-55026
Microsoft Office Information Disclosure Vulnerability
Published 2026-07-14 · Analyzed
6.2EPSS 0.004
CVE-2026-33113
Microsoft SharePoint Server Spoofing Vulnerability
Published 2026-06-09 · Modified
6.1EPSS 0.006
CVE-2019-0949
A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-0950, CVE-2019-0951.
Published 2019-05-16 · Modified
5.7EPSS 0.025
CVE-2019-0950
A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-0949, CVE-2019-0951.
Published 2019-05-16 · Modified
5.7EPSS 0.025
CVE-2022-30172
Microsoft Office Information Disclosure Vulnerability
Published 2022-06-15 · Modified
5.5EPSS 0.027
CVE-2022-30159
Microsoft Office Information Disclosure Vulnerability
Published 2022-06-15 · Modified
5.5EPSS 0.027
CVE-2022-30171
Microsoft Office Information Disclosure Vulnerability
Published 2022-06-15 · Modified
5.5EPSS 0.026
CVE-2024-49065
Microsoft Office Remote Code Execution Vulnerability
Published 2024-12-10 · Analyzed
5.5EPSS 0.011
CVE-2026-44821
Microsoft Office Information Disclosure Vulnerability
Published 2026-06-09 · Analyzed
5.5EPSS 0.006
CVE-2026-55023
Microsoft Office Information Disclosure Vulnerability
Published 2026-07-14 · Analyzed
5.5EPSS 0.006
CVE-2026-55027
Microsoft Office Information Disclosure Vulnerability
Published 2026-07-14 · Analyzed
5.5EPSS 0.006
CVE-2026-55028
Microsoft Office Information Disclosure Vulnerability
Published 2026-07-14 · Analyzed
5.5EPSS 0.006
CVE-2026-55047
Microsoft Office Information Disclosure Vulnerability
Published 2026-07-14 · Analyzed
5.5EPSS 0.006
CVE-2026-55050
Microsoft Word Information Disclosure Vulnerability
Published 2026-07-14 · Analyzed
5.5EPSS 0.006
CVE-2026-55124
Microsoft Word Information Disclosure Vulnerability
Published 2026-07-14 · Analyzed
5.5EPSS 0.006
CVE-2026-56192
Microsoft Office Information Disclosure Vulnerability
Published 2026-07-14 · Analyzed
5.5EPSS 0.006
CVE-2026-55142
Microsoft Word Information Disclosure Vulnerability
Published 2026-07-14 · Analyzed
5.5EPSS 0.006
CVE-2026-55035
Microsoft Office Information Disclosure Vulnerability
Published 2026-07-14 · Analyzed
5.5EPSS 0.006
CVE-2026-55121
Microsoft Office Information Disclosure Vulnerability
Published 2026-07-14 · Analyzed
5.5EPSS 0.005
CVE-2026-20945
Microsoft SharePoint Server Spoofing Vulnerability
Published 2026-04-14 · Analyzed
5.4EPSS 0.191
CVE-2026-20959
Microsoft SharePoint Server Spoofing Vulnerability
Published 2026-01-13 · Analyzed
5.4EPSS 0.076
CVE-2018-8149
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft SharePoint Server, Microsoft SharePoint. This CVE ID is unique from CVE-2018-8155, CVE-2018-8156, CVE-2018-8168.
Published 2018-05-09 · Modified
5.4EPSS 0.029
CVE-2018-8155
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft SharePoint. This CVE ID is unique from CVE-2018-8149, CVE-2018-8156, CVE-2018-8168.
Published 2018-05-09 · Modified
5.4EPSS 0.029
CVE-2018-8156
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft SharePoint, Microsoft Project Server. This CVE ID is unique from CVE-2018-8149, CVE-2018-8155, CVE-2018-8168.
Published 2018-05-09 · Modified
5.4EPSS 0.029
CVE-2018-8254
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft Project Server, Microsoft SharePoint. This CVE ID is unique from CVE-2018-8252.
Published 2018-06-14 · Modified
5.4EPSS 0.028
CVE-2018-8252
An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft SharePoint. This CVE ID is unique from CVE-2018-8254.
Published 2018-06-14 · Modified
5.4EPSS 0.028
CVE-2018-0864
SharePoint Project Server 2013 and SharePoint Enterprise Server 2016 allow an information disclosure vulnerability due to how web requests are handled, aka "Microsoft SharePoint Information Disclosure Vulnerability".
Published 2018-02-15 · Modified
5.4EPSS 0.026
CVE-2019-0557
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft Office SharePoint XSS Vulnerability." This affects Microsoft SharePoint. This CVE ID is unique from CVE-2019-0556, CVE-2019-0558.
Published 2019-01-08 · Modified
5.4EPSS 0.021
CVE-2019-0558
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft Office SharePoint XSS Vulnerability." This affects Microsoft SharePoint Server, Microsoft SharePoint, Microsoft Business Productivity Servers. This CVE ID is unique from CVE-2019-0556, CVE-2019-0557.
Published 2019-01-08 · Modified
5.4EPSS 0.020
← Prev5 / 6Next →