← Back

Sharepoint Server

sharepoint_server

Vendor: Microsoft • 549 CVEs

CVEs (549)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microsoft
1Sharepoint Server
Jun 17, 2026
Oct 14, 2025
N/A· v4
8.8 HIGH· v3
N/A· v2
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
1Microsoft
7365 Apps
AccessExcel+4 more
Jun 17, 2026
Oct 14, 2025
N/A· v4
7.1 HIGH· v3
N/A· v2
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
1Microsoft
7365 Apps
AccessExcel+4 more
Jun 17, 2026
Oct 14, 2025
N/A· v4
7.1 HIGH· v3
N/A· v2
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
1Microsoft
1Sharepoint Server
Jun 17, 2026
Oct 14, 2025
N/A· v4
8.8 HIGH· v3
N/A· v2
Improper input validation in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
1Microsoft
5365 Apps
OfficeOffice Long Term Servicing Channel+2 more
Jun 17, 2026
Oct 14, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
1Microsoft
5365 Apps
OfficeOffice Long Term Servicing Channel+2 more
Jun 17, 2026
Oct 14, 2025
N/A· v4
7.0 HIGH· v3
N/A· v2
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
1Microsoft
4365 Apps
OfficeOffice Long Term Servicing Channel+1 more
Jun 17, 2026
Sep 9, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
Free of memory not on the heap in Microsoft Office allows an unauthorized attacker to execute code locally.
1Microsoft
6365 Apps
OfficeOffice Long Term Servicing Channel+3 more
Jun 17, 2026
Sep 9, 2025
N/A· v4
7.1 HIGH· v3
N/A· v2
Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
1Microsoft
1Sharepoint Server
Jun 17, 2026
Sep 9, 2025
N/A· v4
8.8 HIGH· v3
N/A· v2
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
1Microsoft
1Sharepoint Server
Jun 17, 2026
Aug 12, 2025
N/A· v4
7.1 HIGH· v3
N/A· v2
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
1Microsoft
6365 Apps
OfficeOffice Long Term Servicing Channel+3 more
Jun 17, 2026
Aug 12, 2025
N/A· v4
6.2 MEDIUM· v3
N/A· v2
Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
1Microsoft
6365 Apps
OfficeOffice Long Term Servicing Channel+3 more
Jun 17, 2026
Aug 12, 2025
N/A· v4
8.4 HIGH· v3
N/A· v2
Incorrect conversion between numeric types in Microsoft Office Word allows an unauthorized attacker to execute code locally.
1Microsoft
1Sharepoint Server
Jun 17, 2026
Aug 12, 2025
N/A· v4
8.8 HIGH· v3
N/A· v2
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
1Microsoft
1Sharepoint Server
Jun 17, 2026
Jul 20, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
1Microsoft
1Sharepoint Server
Jun 17, 2026
Jul 20, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware that an exploit for CVE-2025-53770 exists in the wild. Micro...Show more
Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware that an exploit for CVE-2025-53770 exists in the wild. Microsoft is preparing and fully testing a comprehensive update to address this vulnerability. In the meantime, please make sure that the mitigation provided in this CVE documentation is in place so that you are protected from exploitation.Show less
1Microsoft
2Sharepoint Enterprise Server
Sharepoint Server
Jun 17, 2026
Jul 8, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
1Microsoft
1Sharepoint Server
Jun 17, 2026
Jul 8, 2025
N/A· v4
8.8 HIGH· v3
N/A· v2
Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
1Microsoft
5365 Apps
OfficeOffice Long Term Servicing Channel+2 more
Jun 17, 2026
Jul 8, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
1Microsoft
1Sharepoint Server
Jun 17, 2026
Jul 8, 2025
N/A· v4
8.8 HIGH· v3
N/A· v2
Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
1Microsoft
2Sharepoint Enterprise Server
Sharepoint Server
Jun 17, 2026
Jun 10, 2025
N/A· v4
8.8 HIGH· v3
N/A· v2
Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.