VendorsMicrosoftsharepoint_serverall versions
Vulnerabilities

Microsoft Sharepoint Server

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

604CVEs
CVE-2025-47168
Microsoft Word Remote Code Execution Vulnerability
Published 2025-06-10 · Analyzed
7.8EPSS 0.006
CVE-2025-62559
Microsoft Word Remote Code Execution Vulnerability
Published 2025-12-09 · Analyzed
7.8EPSS 0.006
CVE-2025-62558
Microsoft Word Remote Code Execution Vulnerability
Published 2025-12-09 · Analyzed
7.8EPSS 0.006
CVE-2025-49703
Microsoft Word Remote Code Execution Vulnerability
Published 2025-07-08 · Analyzed
7.8EPSS 0.006
CVE-2025-29976
Microsoft SharePoint Server Elevation of Privilege Vulnerability
Published 2025-05-13 · Analyzed
7.8EPSS 0.006
CVE-2026-20948
Microsoft Word Remote Code Execution Vulnerability
Published 2026-01-13 · Analyzed
7.8EPSS 0.006
CVE-2026-55032
Microsoft Word Remote Code Execution Vulnerability
Published 2026-07-14 · Analyzed
7.8EPSS 0.006
CVE-2026-45471
Microsoft Word Remote Code Execution Vulnerability
Published 2026-06-09 · Analyzed
7.8EPSS 0.006
CVE-2026-45475
Microsoft Office Remote Code Execution Vulnerability
Published 2026-06-09 · Analyzed
7.8EPSS 0.006
CVE-2026-55033
Microsoft Word Remote Code Execution Vulnerability
Published 2026-07-14 · Analyzed
7.8EPSS 0.006
CVE-2026-55038
Microsoft Word Remote Code Execution Vulnerability
Published 2026-07-14 · Analyzed
7.8EPSS 0.006
CVE-2026-55055
Microsoft Word Remote Code Execution Vulnerability
Published 2026-07-14 · Analyzed
7.8EPSS 0.006
CVE-2026-55125
Microsoft Office Remote Code Execution Vulnerability
Published 2026-07-14 · Analyzed
7.8EPSS 0.006
CVE-2026-55127
Microsoft Word Remote Code Execution Vulnerability
Published 2026-07-14 · Analyzed
7.8EPSS 0.006
CVE-2026-55128
Microsoft Word Remote Code Execution Vulnerability
Published 2026-07-14 · Analyzed
7.8EPSS 0.006
CVE-2026-55130
Microsoft Word Remote Code Execution Vulnerability
Published 2026-07-14 · Analyzed
7.8EPSS 0.006
CVE-2026-55132
Microsoft Word Remote Code Execution Vulnerability
Published 2026-07-14 · Analyzed
7.8EPSS 0.006
CVE-2026-55134
Microsoft Word Remote Code Execution Vulnerability
Published 2026-07-14 · Analyzed
7.8EPSS 0.006
CVE-2026-44819
Microsoft Office Remote Code Execution Vulnerability
Published 2026-06-09 · Analyzed
7.8EPSS 0.006
CVE-2026-44824
Microsoft Office Remote Code Execution Vulnerability
Published 2026-06-09 · Analyzed
7.8EPSS 0.006
CVE-2025-59222
Microsoft Word Remote Code Execution Vulnerability
Published 2025-10-14 · Analyzed
7.8EPSS 0.005
CVE-2026-69683
Microsoft Office SharePoint Information Disclosure Vulnerability
Published 2026-09-08 · Analyzed
7.7EPSS 0.008
CVE-2021-36940
Microsoft SharePoint Server Spoofing Vulnerability
Published 2021-08-12 · Modified
7.6EPSS 0.040
CVE-2021-28478
Microsoft SharePoint Server Spoofing Vulnerability
Published 2021-05-11 · Modified
7.6EPSS 0.016
CVE-2021-40484
Microsoft SharePoint Server Spoofing Vulnerability
Published 2021-10-13 · Modified
7.6EPSS 0.014
CVE-2021-40483
Microsoft SharePoint Server Spoofing Vulnerability
Published 2021-10-13 · Modified
7.6EPSS 0.014
CVE-2021-38651
Microsoft SharePoint Server Spoofing Vulnerability
Published 2021-09-15 · Modified
7.6EPSS 0.013
CVE-2021-43242
Microsoft SharePoint Server Spoofing Vulnerability
Published 2021-12-15 · Modified
7.6EPSS 0.012
CVE-2010-3964
Unrestricted file upload vulnerability in the Document Conversions Launcher Service in Microsoft Office SharePoint Server 2007 SP2, when the Document Conversions Load Balancer Service is enabled, allows remote attackers to execute arbitrary code via a crafted SOAP request to TCP port 8082, aka "Malformed Request Code Execution Vulnerability."
Published 2010-12-16 · Modified
7.51 PoCEPSS 0.942
CVE-2024-30043
Microsoft SharePoint Server Information Disclosure Vulnerability
Published 2024-05-14 · Analyzed
7.5EPSS 0.561
CVE-2013-0084
Directory traversal vulnerability in Microsoft SharePoint Server 2010 SP1 and SharePoint Foundation 2010 SP1 allows remote attackers to bypass intended read restrictions for content, and hijack user accounts, via a crafted URL, aka "SharePoint Directory Traversal Vulnerability."
Published 2013-03-13 · Modified
7.5EPSS 0.214
CVE-2013-0080
Microsoft SharePoint Server 2010 SP1 and SharePoint Foundation 2010 SP1 allow remote attackers to bypass intended read restrictions for content, and hijack user accounts, via a crafted URL, aka "Callback Function Vulnerability."
Published 2013-03-13 · Modified
7.5EPSS 0.193
CVE-2019-1006
An authentication bypass vulnerability exists in Windows Communication Foundation (WCF) and Windows Identity Foundation (WIF), allowing signing of SAML tokens with arbitrary symmetric keys, aka 'WCF/WIF SAML Token Authentication Bypass Vulnerability'.
Published 2019-07-15 · Modified
7.5EPSS 0.060
CVE-2024-43466
Microsoft SharePoint Server Denial of Service Vulnerability
Published 2024-09-10 · Analyzed
7.5EPSS 0.045
CVE-2026-21511
Microsoft Outlook Spoofing Vulnerability
Published 2026-02-10 · Analyzed
7.5EPSS 0.038
CVE-2024-32987
Microsoft SharePoint Server Information Disclosure Vulnerability
Published 2024-07-09 · Modified
7.5EPSS 0.023
CVE-2021-40482
Microsoft SharePoint Server Information Disclosure Vulnerability
Published 2021-10-13 · Modified
7.5EPSS 0.023
CVE-2026-21260
Microsoft Outlook Spoofing Vulnerability
Published 2026-02-10 · Analyzed
7.5EPSS 0.015
CVE-2023-33165
Microsoft SharePoint Server Security Feature Bypass Vulnerability
Published 2023-07-11 · Modified
7.5EPSS 0.011
CVE-2026-69804
Microsoft Office SharePoint Remote Code Execution Vulnerability
Published 2026-09-08 · Analyzed
7.5EPSS 0.005
← Prev8 / 16Next →