About “Microsoft SharePoint”

A curated feed of “Microsoft SharePoint”-related CVEs appears below. We currently track 536 CVEs for this tag (all time). In the last 365 days, 36 were published. Average CVSS is 7.0 (all time; 8.2 over 365d), and 55% are rated High/Critical (all time). Top CWEs (last 365 days): CWE-502 - Deserialization of Untrusted Data, CWE-20 - Improper Input Validation, CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').

In our taxonomy this topic maps to a MODERATE impact class. Identity providers govern authentication across the estate. Upgrade, enforce phishing resistant MFA, review audit logs, rotate admin keys, and tighten policies. Use the filters below to sort by CVSS, risk and CWE. Each detail page highlights vendor advisories and mitigation tips.

CVEs tagged with this topic. Filters apply to the whole list (loaded from JSON).

CVSS ≥ 0.0
2022-06-15
High

CVE-2022-30157

Microsoft SharePoint Server Remote Code Execution Vulnerability

2022-05-11
High

CVE-2021-37851

Local privilege escalation in Windows products of ESET allows user who is logged into the system to exploit repair feature of the installer to run malicious code with higher privileges. This issue af…

2022-05-10
High

CVE-2022-29108

Microsoft SharePoint Server Remote Code Execution Vulnerability

High

CVE-2022-27167

Privilege escalation vulnerability in Windows products of ESET, spol. s r.o. allows attacker to exploit "Repair" and "Uninstall" features what may lead to arbitrary file deletion. This issue affects:…

2022-04-15
High

CVE-2022-24472

Microsoft SharePoint Server Spoofing Vulnerability

2022-03-02
Critical

CVE-2022-24306

Zoho ManageEngine SharePoint Manager Plus before 4329 allows account takeover because authorization is mishandled.

Critical

CVE-2022-24305

Zoho ManageEngine SharePoint Manager Plus before 4329 is vulnerable to a sensitive data leak that leads to privilege escalation.

2022-02-09
High

CVE-2022-22005

Microsoft SharePoint Server Remote Code Execution Vulnerability

High

CVE-2022-21987

Microsoft SharePoint Server Spoofing Vulnerability

Medium

CVE-2022-21968

Microsoft SharePoint Server Security Feature Bypass Vulnerability

2022-01-11
High

CVE-2022-21837

Microsoft SharePoint Server Remote Code Execution Vulnerability

2021-12-29
High

CVE-2021-43876

Microsoft SharePoint Elevation of Privilege Vulnerability

2021-12-15
High

CVE-2021-43242

Microsoft SharePoint Server Spoofing Vulnerability

High

CVE-2021-42320

Microsoft SharePoint Server Spoofing Vulnerability

High

CVE-2021-42309

Microsoft SharePoint Server Remote Code Execution Vulnerability

High

CVE-2021-42294

Microsoft SharePoint Server Remote Code Execution Vulnerability

2021-10-13
High

CVE-2021-41344

Microsoft SharePoint Server Remote Code Execution Vulnerability

High

CVE-2021-40487

Microsoft SharePoint Server Remote Code Execution Vulnerability

High

CVE-2021-40484

Microsoft SharePoint Server Spoofing Vulnerability

High

CVE-2021-40483

Microsoft SharePoint Server Spoofing Vulnerability

Medium

CVE-2021-40482

Microsoft SharePoint Server Information Disclosure Vulnerability

2021-09-15
High

CVE-2021-38652

Microsoft SharePoint Server Spoofing Vulnerability

High

CVE-2021-38651

Microsoft SharePoint Server Spoofing Vulnerability

2021-08-12
High

CVE-2021-36940

Microsoft SharePoint Server Spoofing Vulnerability

2021-07-16
High

CVE-2021-34467

Microsoft SharePoint Server Remote Code Execution Vulnerability

2021-07-14
High

CVE-2021-34520

Microsoft SharePoint Server Remote Code Execution Vulnerability

Medium

CVE-2021-34519

Microsoft SharePoint Server Information Disclosure Vulnerability

Medium

CVE-2021-34517

Microsoft SharePoint Server Spoofing Vulnerability

High

CVE-2021-34468

Microsoft SharePoint Server Remote Code Execution Vulnerability

2021-06-08
High

CVE-2021-31966

Microsoft SharePoint Server Remote Code Execution Vulnerability

Medium

CVE-2021-31965

Microsoft SharePoint Server Information Disclosure Vulnerability

High

CVE-2021-31964

Microsoft SharePoint Server Spoofing Vulnerability

High

CVE-2021-31963

Microsoft SharePoint Server Remote Code Execution Vulnerability

High

CVE-2021-31950

Microsoft SharePoint Server Spoofing Vulnerability

High

CVE-2021-31948

Microsoft SharePoint Server Spoofing Vulnerability

High

CVE-2021-26420

Microsoft SharePoint Server Remote Code Execution Vulnerability

2021-05-11
High

CVE-2021-31181

Microsoft SharePoint Remote Code Execution Vulnerability

Medium

CVE-2021-31173

Microsoft SharePoint Server Information Disclosure Vulnerability

High

CVE-2021-31172

Microsoft SharePoint Server Spoofing Vulnerability

Medium

CVE-2021-31171

Microsoft SharePoint Information Disclosure Vulnerability

High

CVE-2021-28478

Microsoft SharePoint Server Spoofing Vulnerability

High

CVE-2021-28474

Microsoft SharePoint Server Remote Code Execution Vulnerability

Medium

CVE-2021-26418

Microsoft SharePoint Server Spoofing Vulnerability

2021-04-13
Medium

CVE-2021-28450

Microsoft SharePoint Denial of Service Vulnerability

2021-03-11
High

CVE-2021-27076

Microsoft SharePoint Server Remote Code Execution Vulnerability

Medium

CVE-2021-27052

Microsoft SharePoint Server Information Disclosure Vulnerability

Medium

CVE-2021-24104

Microsoft SharePoint Server Spoofing Vulnerability

2021-02-25
High

CVE-2021-24072

Microsoft SharePoint Server Remote Code Execution Vulnerability

Medium

CVE-2021-24071

Microsoft SharePoint Information Disclosure Vulnerability

High

CVE-2021-24066

Microsoft SharePoint Remote Code Execution Vulnerability

High

CVE-2021-1726

Microsoft SharePoint Server Spoofing Vulnerability

2021-01-26
Medium

CVE-2020-26941

A local (authenticated) low-privileged user can exploit a behavior in an ESET installer to achieve arbitrary file overwrite (deletion) of any file via a symlink, due to insecure permissions. The poss…

2021-01-12
High

CVE-2021-1719

Microsoft SharePoint Elevation of Privilege Vulnerability

High

CVE-2021-1718

Microsoft SharePoint Server Tampering Vulnerability

Medium

CVE-2021-1717

Microsoft SharePoint Server Spoofing Vulnerability

High

CVE-2021-1712

Microsoft SharePoint Elevation of Privilege Vulnerability

High

CVE-2021-1707

Microsoft SharePoint Server Remote Code Execution Vulnerability

Medium

CVE-2021-1641

Microsoft SharePoint Server Spoofing Vulnerability

2020-12-10
High

CVE-2020-17121

Microsoft SharePoint Remote Code Execution Vulnerability

Medium

CVE-2020-17120

Microsoft SharePoint Information Disclosure Vulnerability

High

CVE-2020-17118

Microsoft SharePoint Remote Code Execution Vulnerability

High

CVE-2020-17115

Microsoft SharePoint Server Spoofing Vulnerability

High

CVE-2020-17089

Microsoft SharePoint Elevation of Privilege Vulnerability

2020-11-11
High

CVE-2020-17061

Microsoft SharePoint Remote Code Execution Vulnerability

Medium

CVE-2020-17060

Microsoft SharePoint Server Spoofing Vulnerability

Medium

CVE-2020-17017

Microsoft SharePoint Information Disclosure Vulnerability

High

CVE-2020-17016

Microsoft SharePoint Server Spoofing Vulnerability

Medium

CVE-2020-17015

Microsoft SharePoint Server Spoofing Vulnerability

Medium

CVE-2020-16979

Microsoft SharePoint Information Disclosure Vulnerability

2020-10-16
Medium

CVE-2020-16953

<p>An information disclosure vulnerability exists when Microsoft SharePoint Server fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could obtain i…

High

CVE-2020-16952

<p>A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package. An attacker who successfully exploited the vulner…

High

CVE-2020-16951

<p>A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package. An attacker who successfully exploited the vulner…

Medium

CVE-2020-16950

<p>An information disclosure vulnerability exists when Microsoft SharePoint Server fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could obtain i…

Medium

CVE-2020-16948

<p>An information disclosure vulnerability exists when Microsoft SharePoint Server fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could obtain i…

High

CVE-2020-16946

<p>A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated att…

High

CVE-2020-16945

<p>A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated att…

High

CVE-2020-16944

<p>This vulnerability is caused when SharePoint Server does not properly sanitize a specially crafted request to an affected SharePoint server.</p> <p>An authenticated attacker could exploit this vul…

Medium

CVE-2020-16942

<p>An information disclosure vulnerability exists when Microsoft SharePoint Server improperly discloses its folder structure when rendering specific web pages. An attacker who took advantage of this…

Medium

CVE-2020-16941

<p>An information disclosure vulnerability exists when Microsoft SharePoint Server improperly discloses its folder structure when rendering specific web pages. An attacker who took advantage of this…

2020-09-11
Critical

CVE-2020-1595

<p>A remote code execution vulnerability exists in Microsoft SharePoint where APIs aren't properly protected from unsafe data input. An attacker who successfully exploited the vulnerability could run…

High

CVE-2020-1576

<p>A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package. An attacker who successfully exploited the vulner…

Medium

CVE-2020-1575

<p>A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated att…

High

CVE-2020-1523

<p>A tampering vulnerability exists when Microsoft SharePoint Server fails to properly handle profile data. An attacker who successfully exploited this vulnerability could modify a targeted user's pr…

Medium

CVE-2020-1514

<p>A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated att…

Medium

CVE-2020-1482

<p>A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated att…

High

CVE-2020-1460

<p>A remote code execution vulnerability exists in Microsoft SharePoint Server when it fails to properly identify and filter unsafe ASP.Net web controls. An authenticated attacker who successfully ex…

High

CVE-2020-1453

<p>A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package. An attacker who successfully exploited the vulner…

High

CVE-2020-1452

<p>A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package. An attacker who successfully exploited the vulner…

Medium

CVE-2020-1440

<p>A tampering vulnerability exists when Microsoft SharePoint Server fails to properly handle profile data. An attacker who successfully exploited this vulnerability could modify a targeted user's pr…

High

CVE-2020-1345

<p>A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated att…

Medium

CVE-2020-1227

<p>A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated att…

Critical

CVE-2020-1210

<p>A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package. An attacker who successfully exploited the vulner…

Medium

CVE-2020-1205

<p>A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploi…

High

CVE-2020-1200

<p>A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package. An attacker who successfully exploited the vulner…

High

CVE-2020-1198

<p>A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated att…

2020-08-17
Medium

CVE-2020-1580

A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attack…

Medium

CVE-2020-1573

A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attack…

Medium

CVE-2020-1505

An information disclosure vulnerability exists when Microsoft SharePoint Server fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could obtain info…

Medium

CVE-2020-1501

A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit t…

Medium

CVE-2020-1500

A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit t…

Medium

CVE-2020-1499

A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit t…

2020-07-14
Medium

CVE-2020-1456

A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office S…

Medium

CVE-2020-1454

This vulnerability is caused when SharePoint Server does not properly sanitize a specially crafted request to an affected SharePoint server.An authenticated attacker could exploit this vulnerability…

Medium

CVE-2020-1451

A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office S…

Medium

CVE-2020-1450

A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office S…

Medium

CVE-2020-1444

A remote code execution vulnerability exists in the way Microsoft SharePoint software parses specially crafted email messages, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'.

Medium

CVE-2020-1443

A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Spoofing Vulner…

High

CVE-2020-1439

A remote code execution vulnerability exists in PerformancePoint Services for SharePoint Server when the software fails to check the source markup of XML file input, aka 'PerformancePoint Services Re…

High

CVE-2020-1147

A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of XML file input, aka '.NET Framework, Shar…

Critical

CVE-2020-1025

An elevation of privilege vulnerability exists when Microsoft SharePoint Server and Skype for Business Server improperly handle OAuth token validation. An attacker who successfully exploited the vuln…

2020-06-09
Medium

CVE-2020-1323

An open redirect vulnerability exists in Microsoft SharePoint that could lead to spoofing.To exploit the vulnerability, an attacker could send a link that has a specially crafted URL and convince the…

Medium

CVE-2020-1320

A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office S…

Medium

CVE-2020-1318

A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office S…

Medium

CVE-2020-1298

A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office S…

Medium

CVE-2020-1297

A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office S…

High

CVE-2020-1295

An elevation of privilege vulnerability exists in Microsoft SharePoint, aka 'Microsoft SharePoint Elevation of Privilege Vulnerability'.

Medium

CVE-2020-1289

A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Spoofing Vulner…

Medium

CVE-2020-1183

A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office S…

High

CVE-2020-1181

A remote code execution vulnerability exists in Microsoft SharePoint Server when it fails to properly identify and filter unsafe ASP.Net web controls, aka 'Microsoft SharePoint Server Remote Code Exe…

High

CVE-2020-1178

An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted authentication request to an affected SharePoint server, aka 'Microsoft…