Showing 22 vulnerabilities on this page for SharePoint

Signals CISA KEV Ransomware Nuclei
Microsoft vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Microsoft SharePoint Server Security Feature Bypass Vulnerability

Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.

CWE-1390Jul 14, 2026
CVSS9.1v3.1EPSS2.96%PoCs2SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Microsoft SharePoint Remote Code Execution Vulnerability

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

CWE-502Jul 14, 2026
CVSS9.8v3.1EPSS6.37%PoCs1SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Microsoft SharePoint Remote Code Execution Vulnerability

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

CWE-502Jul 14, 2026
CVSS9.8v3.1EPSS77%PoCs5SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Microsoft SharePoint Server Elevation of Privilege Vulnerability

Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.

CWE-306Jul 14, 2026
CVSS5.3v3.1EPSS22.4%PoCs3SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Microsoft SharePoint Remote Code Execution Vulnerability

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

CWE-502May 22, 2026
CVSS8.8v3.1EPSS9.86%PoCs4SignalsListed in CISA KEVKnown ransomware useNo Nuclei templatesSTIX

Microsoft SharePoint Server Spoofing Vulnerability

Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

CWE-20Apr 14, 2026
CVSS6.5v3.1EPSS22.8%PoCs1SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Microsoft SharePoint Remote Code Execution Vulnerability

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

CWE-502Jan 13, 2026
CVSS9.8v3.1EPSS31.6%PoCs0SignalsListed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Microsoft SharePoint Server Spoofing Vulnerability

Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

CWE-20CWE-287Jul 20, 20251 related artifact
CVSS6.5v3.1EPSS>99.9%PoCs2SignalsNot listed in CISA KEVKnown ransomware use1 Nuclei templateSTIX

Microsoft SharePoint Server Remote Code Execution Vulnerability

Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware that an exploit for CVE-2025-53770 exists in the wild. Microsoft is preparing and fully testing a comprehensive update to address this vulnerability. In the meantime, please make sure that the mitigation provided in this CVE documentation is in place so that you are protected from exploitation.

CWE-502Jul 20, 20251 related artifact
CVSS9.8v3.1EPSS>99.9%PoCs48SignalsListed in CISA KEVKnown ransomware use1 Nuclei templateSTIX

Microsoft SharePoint Server Spoofing Vulnerability

Improper authentication in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

CWE-287Jul 8, 20251 related artifact
CVSS6.5v3.1EPSS99.9%PoCs4SignalsListed in CISA KEVKnown ransomware use1 Nuclei templateSTIX

Microsoft SharePoint Remote Code Execution Vulnerability

Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

CWE-94Jul 8, 2025
CVSS8.8v3.1EPSS>99.9%PoCs1SignalsListed in CISA KEVKnown ransomware useNo Nuclei templatesSTIX

Microsoft SharePoint Remote Code Execution Vulnerability

Microsoft SharePoint Remote Code Execution Vulnerability

CWE-502Jul 9, 2024
CVSS7.2v3.1EPSS50.9%PoCs0SignalsListed in CISA KEVKnown ransomware useNo Nuclei templatesSTIX

Microsoft SharePoint Server Remote Code Execution Vulnerability

Microsoft SharePoint Server Remote Code Execution Vulnerability

CWE-502Jul 9, 2024
CVSS7.2v3.1EPSS45.2%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Microsoft SharePoint Server Remote Code Execution Vulnerability

Microsoft SharePoint Server Remote Code Execution Vulnerability

CWE-502Jul 9, 2024
CVSS7.2v3.1EPSS52.9%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Microsoft SharePoint Server Elevation of Privilege Vulnerability

Microsoft SharePoint Server Elevation of Privilege Vulnerability

CWE-303Jun 13, 20231 related artifact
CVSS9.8v3.1EPSS99.6%PoCs9SignalsListed in CISA KEVKnown ransomware use1 Nuclei templateSTIX

Microsoft SharePoint Server Remote Code Execution Vulnerability

Microsoft SharePoint Server Remote Code Execution Vulnerability

CWE-94May 9, 2023
CVSS7.2v3.1EPSS85.4%PoCs3SignalsListed in CISA KEVKnown ransomware useNo Nuclei templatesSTIX

Microsoft SharePoint Server Remote Code Execution Vulnerability

Microsoft SharePoint Server Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2023-21744.

CWE-284Jan 10, 2023
CVSS8.8v3.1EPSS55.8%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Microsoft SharePoint Server Remote Code Execution Vulnerability

Microsoft SharePoint Server Remote Code Execution Vulnerability.

CWE-502Feb 9, 2022
CVSS8.8v3.1EPSS16.8%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Microsoft SharePoint Remote Code Execution Vulnerability

A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1200, CVE-2020-1452, CVE-2020-1453, CVE-2020-1576, CVE-2020-1595.

CWE-494Sep 11, 2020
CVSS9.9v3.1EPSS1.76%PoCs0SignalsNot listed in CISA KEVKnown ransomware useNo Nuclei templatesSTIX

Microsoft SharePoint Remote Code Execution Vulnerability

A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0594.

CWE-20Mar 6, 20191 related artifact
CVSS9.8v3.1EPSS99.8%PoCs6SignalsListed in CISA KEVKnown ransomware use1 Nuclei templateSTIX

Microsoft SharePoint Exposure of Sensitive Information to an Unauthorized Actor

An information disclosure vulnerability exists where certain modes of the search function in Microsoft SharePoint Server are vulnerable to cross-site search attacks (a variant of cross-site request forgery, CSRF), aka "Microsoft SharePoint Information Disclosure Vulnerability." This affects Microsoft SharePoint.

CWE-200Dec 12, 2018
CVSS4.3v3.1EPSS4.43%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Microsoft SharePoint Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Cross-site scripting (XSS) vulnerability in _layouts/help.aspx in Microsoft SharePoint Server 2007 12.0.0.6421 and possibly earlier, and SharePoint Services 3.0 SP1 and SP2, versions, allows remote attackers to inject arbitrary web script or HTML via the cid0 parameter.

CWE-79Apr 29, 2010
CVSS4.3v2.0EPSS28.7%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX