Vulnerabilities (CVE)

Filtered by vendor Microsoft Subscribe
Filtered by product Sharepoint Server
Total 604 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-69615 1 Microsoft 1 Sharepoint Server 2026-09-10 N/A 3.5 LOW
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
CVE-2026-69402 1 Microsoft 1 Sharepoint Server 2026-09-10 N/A 7.3 HIGH
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
CVE-2026-69690 1 Microsoft 1 Sharepoint Server 2026-09-09 N/A 4.6 MEDIUM
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
CVE-2026-69268 1 Microsoft 1 Sharepoint Server 2026-09-09 N/A 8.8 HIGH
Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
CVE-2026-69273 1 Microsoft 1 Sharepoint Server 2026-09-09 N/A 8.8 HIGH
Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
CVE-2026-69282 1 Microsoft 1 Sharepoint Server 2026-09-09 N/A 8.8 HIGH
Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
CVE-2026-69409 1 Microsoft 1 Sharepoint Server 2026-09-09 N/A 6.5 MEDIUM
Execution with unnecessary privileges in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.
CVE-2026-69417 1 Microsoft 1 Sharepoint Server 2026-09-09 N/A 7.3 HIGH
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
CVE-2026-69464 1 Microsoft 1 Sharepoint Server 2026-09-09 N/A 8.8 HIGH
Execution with unnecessary privileges in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
CVE-2026-69465 1 Microsoft 1 Sharepoint Server 2026-09-09 N/A 8.8 HIGH
Missing authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
CVE-2026-69636 1 Microsoft 1 Sharepoint Server 2026-09-09 N/A 6.5 MEDIUM
Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.
CVE-2026-69683 1 Microsoft 1 Sharepoint Server 2026-09-09 N/A 6.5 MEDIUM
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.
CVE-2026-69716 1 Microsoft 1 Sharepoint Server 2026-09-09 N/A 8.8 HIGH
Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
CVE-2026-69724 1 Microsoft 1 Sharepoint Server 2026-09-09 N/A 8.8 HIGH
Missing authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
CVE-2026-69804 1 Microsoft 1 Sharepoint Server 2026-09-09 N/A 7.5 HIGH
Time-of-check time-of-use (toctou) race condition in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
CVE-2026-69904 1 Microsoft 1 Sharepoint Server 2026-09-09 N/A 3.5 LOW
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.
CVE-2026-65660 1 Microsoft 1 Sharepoint Server 2026-08-27 N/A 8.8 HIGH
Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
CVE-2023-21717 1 Microsoft 3 Sharepoint Enterprise Server, Sharepoint Foundation, Sharepoint Server 2026-08-19 N/A 8.8 HIGH
Microsoft SharePoint Server Elevation of Privilege Vulnerability
CVE-2023-21716 1 Microsoft 8 Office, Office Long Term Servicing Channel, Office Online Server and 5 more 2026-08-19 N/A 9.8 CRITICAL
Microsoft Word Remote Code Execution Vulnerability
CVE-2021-27076 1 Microsoft 3 Business Productivity Servers, Sharepoint Foundation, Sharepoint Server 2026-08-19 6.5 MEDIUM 8.8 HIGH
Microsoft SharePoint Server Remote Code Execution Vulnerability