VulnSea

sharepoint_server vulnerabilities

CVEs whose affected-version data names the sharepoint_server package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

37 CVEsRSS

CVE-2026-69904Low· 3.5
2w ago

Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.

Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.

Sunlitmicrosoft · sharepoint_serverEPSS 0.58%via NVD
CVE-2026-69804High· 7.5
2w ago

Time-of-check time-of-use (toctou) race condition in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Time-of-check time-of-use (toctou) race condition in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Twilightmicrosoft · sharepoint_serverEPSS 0.51%via NVD
CVE-2026-69724High· 8.8
2w ago

Missing authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Missing authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Twilightmicrosoft · sharepoint_serverEPSS 0.78%via NVD
CVE-2026-69716High· 8.8
2w ago

Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.

Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.

Twilightmicrosoft · sharepoint_serverEPSS 0.92%via NVD
CVE-2026-69690Medium· 4.6
2w ago

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Sunlitmicrosoft · sharepoint_serverEPSS 0.40%via NVD
CVE-2026-69683Medium· 6.5
2w ago

Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.

Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.

Sunlitmicrosoft · sharepoint_serverEPSS 0.84%via NVD
CVE-2026-69636Medium· 6.5
2w ago

Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.

Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.

Sunlitmicrosoft · sharepoint_serverEPSS 0.95%via NVD
CVE-2026-69615Low· 3.5
2w ago

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Sunlitmicrosoft · sharepoint_serverEPSS 0.40%via NVD
CVE-2026-69465High· 8.8
2w ago

Missing authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Missing authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Twilightmicrosoft · sharepoint_serverEPSS 0.82%via NVD
CVE-2026-69464High· 8.8
2w ago

Execution with unnecessary privileges in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.

Execution with unnecessary privileges in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.

Twilightmicrosoft · sharepoint_serverEPSS 0.92%via NVD
CVE-2026-69417High· 7.3
2w ago

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Twilightmicrosoft · sharepoint_serverEPSS 0.45%via NVD
CVE-2026-69409Medium· 6.5
2w ago

Execution with unnecessary privileges in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.

Execution with unnecessary privileges in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.

Sunlitmicrosoft · sharepoint_serverEPSS 0.95%via NVD
CVE-2026-69402High· 7.3
2w ago

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Twilightmicrosoft · sharepoint_serverEPSS 0.41%via NVD
CVE-2026-69282High· 8.8
2w ago

Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Twilightmicrosoft · sharepoint_serverEPSS 0.53%via NVD
CVE-2026-69273High· 8.8
2w ago

Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Twilightmicrosoft · sharepoint_serverEPSS 0.53%via NVD
CVE-2026-69268High· 8.8
2w ago

Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Twilightmicrosoft · sharepoint_serverEPSS 0.73%via NVD
CVE-2026-58644Critical· 9.8CISA KEVPoC
2mo ago

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

Hadalmicrosoft · sharepoint_serverEPSS 61%via NVD
CVE-2026-47294High· 8.0
3mo ago

Improper neutralization of special elements used in an os command ('os command injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Improper neutralization of special elements used in an os command ('os command injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Twilightmicrosoft · sharepoint_serverEPSS 0.66%via NVD
CVE-2026-45659High· 8.8CISA KEVPoC
4mo ago

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Abyssalmicrosoft · sharepoint_serverEPSS 76%via NVD
CVE-2025-53770Critical· 9.8CISA KEV0dayPoC
1y ago

Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware that an exploit for CVE-2025-53770 exists in the wild. Microsoft is preparing…

Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware that an exploit for CVE-2025-53770 exists in the wild. Microsoft is preparing…

Hadalmicrosoft · sharepoint_serverEPSS 100%via NVD
CVE-2025-49706Medium· 6.5CISA KEVPoC
1y ago

Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

Midnightmicrosoft · sharepoint_enterprise_serverEPSS 99%via NVD
CVE-2021-34520High· 8.10day
5y ago

Microsoft SharePoint Server Remote Code Execution Vulnerability

Microsoft SharePoint Server Remote Code Execution Vulnerability

Abyssalmicrosoft · sharepoint_foundationEPSS 4.4%via NVD
CVE-2021-34519Medium· 5.30day
5y ago

Microsoft SharePoint Server Information Disclosure Vulnerability

Microsoft SharePoint Server Information Disclosure Vulnerability

Midnightmicrosoft · sharepoint_foundationEPSS 6.1%via NVD
CVE-2021-34517Medium· 5.3
5y ago

Microsoft SharePoint Server Spoofing Vulnerability

Microsoft SharePoint Server Spoofing Vulnerability

Sunlitmicrosoft · sharepoint_foundationEPSS 1.9%via NVD
CVE-2021-34468High· 7.10day
5y ago

Microsoft SharePoint Server Remote Code Execution Vulnerability

Microsoft SharePoint Server Remote Code Execution Vulnerability

Abyssalmicrosoft · sharepoint_foundationEPSS 2.1%via NVD
CVE-2020-1107Medium· 5.4
6y ago

A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server

A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a speciall…

Sunlitmicrosoft · sharepoint_enterprise_serverEPSS 1.5%via NVD
CVE-2020-1106Medium· 6.1
6y ago

A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server

A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by …

Sunlitmicrosoft · sharepoint_enterprise_serverEPSS 4.0%via NVD
CVE-2020-1105Medium· 5.4
6y ago

A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server

A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a speciall…

Sunlitmicrosoft · sharepoint_enterprise_serverEPSS 1.7%via NVD
CVE-2020-1104Medium· 5.4
6y ago

A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server

A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a speciall…

Sunlitmicrosoft · sharepoint_enterprise_serverEPSS 1.7%via NVD
CVE-2020-1103Medium· 6.5
6y ago

An information disclosure vulnerability exists where certain modes of the search function in Microsoft SharePoint Server are vulnerable to cross-site search attacks (a variant of cross-site request forgery, CSRF). When users are simultan…

An information disclosure vulnerability exists where certain modes of the search function in Microsoft SharePoint Server are vulnerable to cross-site search attacks (a variant of cross-site request forgery, CSRF). When users are simultan…

Sunlitmicrosoft · sharepoint_enterprise_serverEPSS 2.4%via NVD
sharepoint_server vulnerabilities (CVEs) · VulnSea