📦 Sharepoint Server

by Microsoft

🔍 What is Sharepoint Server?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-53770

CRITICAL CVSS 9.8 Jul 20, 2025

CVE-2025-53770 is a critical deserialization vulnerability in on-premises Microsoft SharePoint Server that allows unauthenticated attackers to execute arbitrary code remotely. This affects organizatio...

CVE-2023-29357

CRITICAL CVSS 9.8 Jun 14, 2023

CVE-2023-29357 is a critical elevation of privilege vulnerability in Microsoft SharePoint Server that allows attackers to bypass authentication and gain administrative access. This affects organizatio...

CVE-2020-1595

CRITICAL CVSS 9.9 Sep 11, 2020

CVE-2020-1595 is a critical remote code execution vulnerability in Microsoft SharePoint where improperly protected APIs allow attackers to execute arbitrary code by sending specially-formatted input. ...

CVE-2020-1210

CRITICAL CVSS 9.9 Sep 11, 2020

This is a critical remote code execution vulnerability in Microsoft SharePoint that allows attackers to run arbitrary code by uploading a specially crafted application package. Exploitation requires u...

CVE-2020-1025

CRITICAL CVSS 9.8 Jul 14, 2020

CVE-2020-1025 is an authentication bypass vulnerability in Microsoft SharePoint Server and Skype for Business Server where improper OAuth token validation allows attackers to modify tokens and gain un...

CVE-2019-1205

CRITICAL CVSS 9.8 Aug 14, 2019

A remote code execution vulnerability in Microsoft Word allows attackers to execute arbitrary code by tricking users into opening malicious files. This affects users of Microsoft Word who open special...

CVE-2026-21511

HIGH CVSS 7.5 Feb 10, 2026

This vulnerability allows attackers to spoof identities or data in Microsoft Office Outlook by exploiting insecure deserialization of untrusted data. Organizations using affected Outlook versions are ...

CVE-2026-20963

HIGH CVSS 8.8 Jan 13, 2026

This vulnerability allows an authorized attacker to execute arbitrary code on Microsoft SharePoint servers by exploiting insecure deserialization of untrusted data. Attackers with network access and v...

CVE-2026-20947

HIGH CVSS 8.8 Jan 13, 2026

This SQL injection vulnerability in Microsoft Office SharePoint allows authenticated attackers to execute arbitrary SQL commands over the network. Attackers could potentially read, modify, or delete d...

CVE-2026-20948

HIGH CVSS 7.8 Jan 13, 2026

This vulnerability allows an unauthorized attacker to execute arbitrary code on a local system by exploiting an untrusted pointer dereference in Microsoft Office Word. Attackers can achieve this by tr...

CVE-2026-20951

HIGH CVSS 7.8 Jan 13, 2026

This vulnerability allows an unauthorized attacker to execute arbitrary code on SharePoint servers through improper input validation. Organizations using affected Microsoft SharePoint versions are at ...

CVE-2026-20943

HIGH CVSS 7.0 Jan 13, 2026

This vulnerability allows an unauthorized attacker to execute arbitrary code on a local system by exploiting an untrusted search path in Microsoft Office. Attackers can place malicious DLLs in directo...

CVE-2025-64672

HIGH CVSS 8.8 Dec 9, 2025

This cross-site scripting (XSS) vulnerability in Microsoft Office SharePoint allows authenticated attackers to inject malicious scripts into web pages, which can then execute in victims' browsers. The...

CVE-2025-62204

HIGH CVSS 8.0 Nov 11, 2025

This vulnerability allows an authenticated attacker to execute arbitrary code on Microsoft SharePoint servers by sending specially crafted deserialized data. It affects organizations running vulnerabl...

CVE-2025-54906

HIGH CVSS 7.8 Sep 9, 2025

This vulnerability in Microsoft Office involves a use-after-free memory corruption issue that allows an attacker to execute arbitrary code on a victim's system. Attackers can exploit this by tricking ...

CVE-2025-53760

HIGH CVSS 7.1 Aug 12, 2025

This Server-Side Request Forgery (SSRF) vulnerability in Microsoft Office SharePoint allows authenticated attackers to make unauthorized requests from the SharePoint server to internal network resourc...

CVE-2025-53733

HIGH CVSS 8.4 Aug 12, 2025

A type conversion vulnerability in Microsoft Office Word allows attackers to execute arbitrary code on vulnerable systems by tricking users into opening malicious documents. This affects all users run...

CVE-2025-49704

HIGH CVSS 8.8 Jul 8, 2025

This CVE describes a code injection vulnerability in Microsoft Office SharePoint that allows authenticated attackers to execute arbitrary code over the network. Attackers with valid SharePoint credent...

CVE-2025-47172

HIGH CVSS 8.8 Jun 10, 2025

This SQL injection vulnerability in Microsoft Office SharePoint allows authenticated attackers to execute arbitrary code remotely over the network. It affects SharePoint servers with improper input va...

CVE-2025-47168

HIGH CVSS 7.8 Jun 10, 2025

A use-after-free vulnerability in Microsoft Office Word allows attackers to execute arbitrary code on a victim's system by tricking them into opening a malicious document. This affects users running v...

CVE-2025-47166

HIGH CVSS 8.8 Jun 10, 2025

CVE-2025-47166 is a deserialization vulnerability in Microsoft Office SharePoint that allows authenticated attackers to execute arbitrary code remotely. This affects organizations using vulnerable Sha...

CVE-2025-30384

HIGH CVSS 7.4 May 13, 2025

This vulnerability allows remote code execution on Microsoft SharePoint servers through deserialization of untrusted data. Attackers can execute arbitrary code with the privileges of the SharePoint ap...

CVE-2025-30382

HIGH CVSS 7.8 May 13, 2025

This vulnerability allows an unauthorized attacker to execute arbitrary code on SharePoint servers by exploiting insecure deserialization of untrusted data. It affects organizations running vulnerable...

CVE-2025-29793

HIGH CVSS 7.2 Apr 8, 2025

This vulnerability allows an authenticated attacker to execute arbitrary code on Microsoft SharePoint servers by exploiting insecure deserialization of untrusted data. It affects organizations running...

CVE-2025-27747

HIGH CVSS 7.8 Apr 8, 2025

A use-after-free vulnerability in Microsoft Office Word allows attackers to execute arbitrary code on affected systems by tricking users into opening malicious documents. This affects all users runnin...

CVE-2025-21400

HIGH CVSS 8.0 Feb 11, 2025

CVE-2025-21400 is a remote code execution vulnerability in Microsoft SharePoint Server that allows an authenticated attacker to execute arbitrary code on the server by exploiting improper authorizatio...

CVE-2025-21344

HIGH CVSS 7.8 Jan 14, 2025

This vulnerability allows remote attackers to execute arbitrary code on Microsoft SharePoint Server by sending specially crafted requests. It affects organizations running vulnerable SharePoint Server...

CVE-2025-21348

HIGH CVSS 7.2 Jan 14, 2025

This vulnerability allows remote attackers to execute arbitrary code on Microsoft SharePoint Server systems. Attackers could gain control of affected servers, potentially compromising sensitive data a...

CVE-2024-49070

HIGH CVSS 7.4 Dec 12, 2024

This vulnerability allows remote attackers to execute arbitrary code on Microsoft SharePoint servers by deserializing untrusted data. It affects organizations running vulnerable SharePoint versions, p...

CVE-2024-49068

HIGH CVSS 8.2 Dec 12, 2024

This vulnerability allows authenticated attackers to elevate their privileges within Microsoft SharePoint, potentially gaining administrative access. It affects organizations running vulnerable ShareP...

CVE-2024-43503

HIGH CVSS 7.8 Oct 8, 2024

This vulnerability allows authenticated attackers to elevate their privileges within Microsoft SharePoint, potentially gaining administrative access. It affects organizations running vulnerable ShareP...

CVE-2024-38228

HIGH CVSS 7.2 Sep 10, 2024

This vulnerability allows authenticated attackers to execute arbitrary code on Microsoft SharePoint Server by sending specially crafted requests. It affects organizations running vulnerable SharePoint...

CVE-2024-38018

HIGH CVSS 8.8 Sep 10, 2024

This vulnerability allows remote attackers to execute arbitrary code on Microsoft SharePoint Server by exploiting insecure deserialization. It affects organizations running vulnerable SharePoint Serve...

CVE-2024-38023

HIGH CVSS 7.2 Jul 9, 2024

This vulnerability allows remote attackers to execute arbitrary code on Microsoft SharePoint Server by exploiting insecure deserialization. It affects organizations running vulnerable SharePoint Serve...

CVE-2024-32987

HIGH CVSS 7.5 Jul 9, 2024

This vulnerability in Microsoft SharePoint Server allows attackers to access sensitive information without proper authorization. It affects organizations running vulnerable SharePoint Server versions,...

CVE-2024-30100

HIGH CVSS 7.8 Jun 11, 2024

This vulnerability in Microsoft SharePoint Server allows authenticated attackers to execute arbitrary code remotely by uploading specially crafted files. It affects organizations running vulnerable Sh...

CVE-2024-30044

HIGH CVSS 7.2 May 14, 2024

CVE-2024-30044 is a remote code execution vulnerability in Microsoft SharePoint Server that allows authenticated attackers to execute arbitrary code on affected systems. This affects organizations run...

CVE-2024-21426

HIGH CVSS 7.8 Mar 12, 2024

This vulnerability in Microsoft SharePoint Server allows authenticated attackers to execute arbitrary code remotely by exploiting a use-after-free memory corruption issue. It affects organizations run...

CVE-2024-21318

HIGH CVSS 8.8 Jan 9, 2024

This vulnerability allows remote attackers to execute arbitrary code on Microsoft SharePoint Server by deserializing untrusted data. It affects organizations running vulnerable SharePoint Server versi...

CVE-2023-36762

HIGH CVSS 7.3 Sep 12, 2023

CVE-2023-36762 is a remote code execution vulnerability in Microsoft Word that allows attackers to execute arbitrary code on a victim's system by tricking them into opening a specially crafted malicio...

CVE-2023-36764

HIGH CVSS 8.8 Sep 12, 2023

This vulnerability in Microsoft SharePoint Server allows authenticated attackers to elevate their privileges within the SharePoint environment. Attackers could gain administrative access to SharePoint...

CVE-2023-36891

HIGH CVSS 8.0 Aug 8, 2023

This vulnerability allows an attacker to inject malicious scripts into Microsoft SharePoint Server, which could execute when viewed by other users. It affects organizations running vulnerable SharePoi...

CVE-2023-33159

HIGH CVSS 8.8 Jul 11, 2023

CVE-2023-33159 is a cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server that allows attackers to inject malicious scripts into web pages. When exploited, it enables spoofing attack...

CVE-2023-33134

HIGH CVSS 8.8 Jul 11, 2023

This vulnerability allows remote attackers to execute arbitrary code on Microsoft SharePoint Server by exploiting insecure deserialization. It affects organizations running vulnerable SharePoint Serve...

CVE-2023-33157

HIGH CVSS 8.8 Jul 11, 2023

This vulnerability allows authenticated attackers to execute arbitrary code on Microsoft SharePoint servers by uploading specially crafted files. It affects organizations running vulnerable SharePoint...

CVE-2023-33130

HIGH CVSS 7.3 Jun 14, 2023

CVE-2023-33130 is a cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server that allows attackers to inject malicious scripts into web pages. When exploited, it enables spoofing attack...

CVE-2026-20958

MEDIUM CVSS 5.4 Jan 13, 2026

This Server-Side Request Forgery (SSRF) vulnerability in Microsoft Office SharePoint allows authenticated attackers to make the server send requests to internal systems, potentially exposing sensitive...

CVE-2026-20959

MEDIUM CVSS 4.6 Jan 13, 2026

This cross-site scripting (XSS) vulnerability in Microsoft Office SharePoint allows authenticated attackers to inject malicious scripts into web pages. When exploited, it enables spoofing attacks wher...

CVE-2025-49706

MEDIUM CVSS 6.5 Jul 8, 2025

CVE-2025-49706 is an improper authentication vulnerability in Microsoft SharePoint that allows unauthorized attackers to perform spoofing attacks over a network. This affects organizations running vul...

CVE-2025-21393

MEDIUM CVSS 6.3 Jan 14, 2025

This CVE describes a cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server that allows attackers to inject malicious scripts into web pages. When exploited, it enables content spoofi...

CVE-2024-49062

MEDIUM CVSS 6.5 Dec 12, 2024

This vulnerability in Microsoft SharePoint allows an authenticated attacker to access sensitive information they shouldn't have permission to view. It affects SharePoint Server installations where use...

CVE-2024-49065

MEDIUM CVSS 5.5 Dec 12, 2024

This vulnerability in Microsoft Office allows attackers to execute arbitrary code on a victim's system by tricking them into opening a specially crafted document. It affects users of Microsoft Office ...

CVE-2020-16948

MEDIUM CVSS 6.5 Oct 16, 2020

This CVE describes an information disclosure vulnerability in Microsoft SharePoint Server where improper memory handling allows authenticated attackers to access sensitive information. The vulnerabili...

CVE-2020-16950

MEDIUM CVSS 5.0 Oct 16, 2020

This CVE describes an information disclosure vulnerability in Microsoft SharePoint Server where improper memory handling could allow an authenticated attacker to access sensitive information. The vuln...

CVE-2020-16953

MEDIUM CVSS 6.5 Oct 16, 2020

This CVE describes an information disclosure vulnerability in Microsoft SharePoint Server where improper memory handling allows authenticated attackers to access sensitive information. The vulnerabili...

CVE-2020-16941

MEDIUM CVSS 4.1 Oct 16, 2020

Microsoft SharePoint Server discloses folder structure information when rendering specific web pages, allowing attackers to view script file paths. This affects organizations running vulnerable ShareP...

CVE-2020-1514

MEDIUM CVSS 5.4 Sep 11, 2020

This is an authenticated cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server that allows attackers to inject malicious scripts into web pages. When exploited, these scripts execute...

CVE-2020-1482

MEDIUM CVSS 6.3 Sep 11, 2020

This is a cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server where improper input sanitization allows authenticated attackers to inject malicious scripts. Successful exploitation ...

CVE-2020-1573

MEDIUM CVSS 5.5 Aug 17, 2020

This is a cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server where authenticated attackers can inject malicious scripts through specially crafted web requests. Successful exploita...

CVE-2020-1500

MEDIUM CVSS 5.4 Aug 17, 2020

This is a cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server where authenticated attackers can send specially crafted requests to bypass input sanitization. Successful exploitatio...

CVE-2020-1502

MEDIUM CVSS 5.5 Aug 17, 2020

This is an information disclosure vulnerability in Microsoft Word where specially crafted documents can leak memory contents when opened. Attackers could potentially use leaked information to further ...

CVE-2019-1203

MEDIUM CVSS 5.4 Aug 14, 2019

This is a cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server that allows authenticated attackers to inject malicious scripts into web pages. When exploited, these scripts execute ...