VendorsMicrosoftsharepoint_serverall versions
Vulnerabilities

Microsoft Sharepoint Server

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

604CVEs
CVE-2024-33881
An issue was discovered in VirtoSoftware Virto Bulk File Download 5.5.44 for SharePoint 2019. The Virto.SharePoint.FileDownloader/Api/Download.ashx isCompleted method allows an NTLMv2 hash leak via a UNC share pathname in the path parameter.
Published 2024-06-24 · Modified
7.5EPSS 0.005
CVE-2020-1345
Microsoft Office SharePoint XSS Vulnerability
Published 2020-09-11 · Modified
7.4EPSS 0.027
CVE-2020-1198
Microsoft Office SharePoint XSS Vulnerability
Published 2020-09-11 · Modified
7.4EPSS 0.027
CVE-2024-49070
Microsoft SharePoint Remote Code Execution Vulnerability
Published 2024-12-10 · Analyzed
7.4EPSS 0.023
CVE-2025-30384
Microsoft SharePoint Server Remote Code Execution Vulnerability
Published 2025-05-13 · Analyzed
7.4EPSS 0.013
CVE-2023-33130
Microsoft SharePoint Server Spoofing Vulnerability
Published 2023-06-13 · Modified
7.3EPSS 0.012
CVE-2023-36762
Microsoft Word Remote Code Execution Vulnerability
Published 2023-09-12 · Modified
7.3EPSS 0.008
CVE-2026-55126
Microsoft SharePoint Server Spoofing Vulnerability
Published 2026-07-14 · Analyzed
7.3EPSS 0.006
CVE-2026-45481
Microsoft SharePoint Server Spoofing Vulnerability
Published 2026-06-09 · Analyzed
7.3EPSS 0.006
CVE-2026-64900
Microsoft SharePoint Server Spoofing Vulnerability
Published 2026-08-11 · Modified
7.3EPSS 0.006
CVE-2026-47634
Microsoft SharePoint Server Spoofing Vulnerability
Published 2026-06-09 · Modified
7.3EPSS 0.005
CVE-2026-69402
Microsoft Office SharePoint Spoofing Vulnerability
Published 2026-09-08 · Analyzed
7.3EPSS 0.004
CVE-2026-69417
Microsoft Office SharePoint Spoofing Vulnerability
Published 2026-09-08 · Analyzed
7.3EPSS 0.004
CVE-2023-24955
Microsoft SharePoint Server Remote Code Execution Vulnerability
Published 2023-05-09 · Analyzed
7.2KEVEPSS 0.854
CVE-2024-30044
Microsoft SharePoint Server Remote Code Execution Vulnerability
Published 2024-05-14 · Analyzed
7.2EPSS 0.840
CVE-2024-38023
Microsoft SharePoint Server Remote Code Execution Vulnerability
Published 2024-07-09 · Modified
7.2EPSS 0.529
CVE-2024-38094
Microsoft SharePoint Remote Code Execution Vulnerability
Published 2024-07-09 · Analyzed
7.2KEVEPSS 0.509
CVE-2024-38024
Microsoft SharePoint Server Remote Code Execution Vulnerability
Published 2024-07-09 · Modified
7.2EPSS 0.452
CVE-2024-43464
Microsoft SharePoint Server Remote Code Execution Vulnerability
Published 2024-09-10 · Analyzed
7.2EPSS 0.363
CVE-2025-29793
Microsoft SharePoint Remote Code Execution Vulnerability
Published 2025-04-08 · Analyzed
7.2EPSS 0.236
CVE-2024-38227
Microsoft SharePoint Server Remote Code Execution Vulnerability
Published 2024-09-10 · Analyzed
7.2EPSS 0.082
CVE-2021-31966
Microsoft SharePoint Server Remote Code Execution Vulnerability
Published 2021-06-08 · Modified
7.2EPSS 0.046
CVE-2024-38228
Microsoft SharePoint Server Remote Code Execution Vulnerability
Published 2024-09-10 · Analyzed
7.2EPSS 0.042
CVE-2021-42294
Microsoft SharePoint Server Remote Code Execution Vulnerability
Published 2021-12-15 · Modified
7.2EPSS 0.022
CVE-2025-21348
Microsoft SharePoint Server Remote Code Execution Vulnerability
Published 2025-01-14 · Analyzed
7.2EPSS 0.018
CVE-2016-7290
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Office Compatibility Pack SP3, Word for Mac 2011, Word Automation Services on SharePoint Server 2010 SP2, and Office Web Apps 2010 SP2 allow remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read) via a crafted document, aka "Microsoft Office Information Disclosure Vulnerability," a different vulnerability than CVE-2016-7291.
Published 2016-12-20 · Modified
7.1EPSS 0.228
CVE-2016-7291
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Office Compatibility Pack SP3, Word for Mac 2011, Word Automation Services on SharePoint Server 2010 SP2, and Office Web Apps 2010 SP2 allow remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read) via a crafted document, aka "Microsoft Office Information Disclosure Vulnerability," a different vulnerability than CVE-2016-7290.
Published 2016-12-20 · Modified
7.1EPSS 0.228
CVE-2016-7268
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Office Compatibility Pack SP3, Word Viewer, Word for Mac 2011, Word Automation Services on SharePoint Server 2010 SP2, and Office Web Apps 2010 SP2 allow remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read) via a crafted document, aka "Microsoft Office Information Disclosure Vulnerability."
Published 2016-12-20 · Modified
7.1EPSS 0.226
CVE-2016-7265
Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Office Compatibility Pack SP3, Excel Viewer, Excel Services on SharePoint Server 2007 SP3, and Excel Services on SharePoint Server 2010 SP2 allow remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read) via a crafted document, aka "Microsoft Office Information Disclosure Vulnerability."
Published 2016-12-20 · Modified
7.1EPSS 0.226
CVE-2025-53760
Microsoft SharePoint Elevation of Privilege Vulnerability
Published 2025-08-12 · Analyzed
7.1EPSS 0.165
CVE-2021-31172
Microsoft SharePoint Server Spoofing Vulnerability
Published 2021-05-11 · Modified
7.1EPSS 0.018
CVE-2021-26418
Microsoft SharePoint Server Spoofing Vulnerability
Published 2021-05-11 · Modified
7.1EPSS 0.012
CVE-2025-59235
Microsoft Excel Information Disclosure Vulnerability
Published 2025-10-14 · Analyzed
7.1EPSS 0.007
CVE-2025-54905
Microsoft Word Information Disclosure Vulnerability
Published 2025-09-09 · Analyzed
7.1EPSS 0.006
CVE-2025-59232
Microsoft Excel Information Disclosure Vulnerability
Published 2025-10-14 · Analyzed
7.1EPSS 0.005
CVE-2025-30378
Microsoft SharePoint Server Remote Code Execution Vulnerability
Published 2025-05-13 · Analyzed
7.0EPSS 0.014
CVE-2026-20943
Microsoft Office Click-To-Run Remote Code Execution Vulnerability
Published 2026-01-13 · Analyzed
7.0EPSS 0.007
CVE-2025-62555
Microsoft Word Remote Code Execution Vulnerability
Published 2025-12-09 · Analyzed
7.0EPSS 0.005
CVE-2025-59221
Microsoft Word Remote Code Execution Vulnerability
Published 2025-10-14 · Analyzed
7.0EPSS 0.004
CVE-2013-3895
Microsoft SharePoint Server 2007 SP3 and 2010 SP1 and SP2 allows remote attackers to conduct clickjacking attacks via a crafted web page, aka "Parameter Injection Vulnerability."
Published 2013-10-09 · Modified
6.8EPSS 0.296
← Prev9 / 16Next →