Sharepoint Enterprise Server
Vendor:
First CVE: Jan 10, 2017 · Active for 9 years
256
Total CVEs
More Total CVEs than 100% of tracked products
32.0
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
7.1
Avg CVSS
Higher Avg CVSS than 42% of tracked products
2.0%
KEV Rate
Higher KEV Rate than 96% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Sharepoint Enterprise Server over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 10, 2017
9 years ago
Most Recent CVE
Sep 9, 2025
319 days ago
CVE Severity & Scoring
Sharepoint Enterprise Server256 CVEs
48%
50%
All CVEs352,427 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local41 (16.0%)
Network214 (83.6%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (0.4%)
Attack Complexity
Low255 (99.6%)
High1 (0.4%)
Unknown0 (0.0%)
User Interaction
None107 (41.8%)
Unknown0 (0.0%)
Required149 (58.2%)
Privileges Required
Low174 (68.0%)
High5 (2.0%)
None77 (30.1%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (256 CVEs).
256 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-49706MEDIUM Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. | Jul 8, 2025 | 6.5 | 98 | YES | YES |
CVE-2020-1147HIGH A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of XML file input, aka '. | Jul 14, 2020 | 7.8 | 98 | YES | YES |
CVE-2019-0604CRITICAL A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote | Mar 5, 2019 | 9.8 | 98 | YES | YES |
CVE-2023-24955HIGH Microsoft SharePoint Server Remote Code Execution Vulnerability | May 9, 2023 | 7.2 | 95 | YES | YES |
CVE-2017-11826HIGH Microsoft Office 2010, SharePoint Enterprise Server 2010, SharePoint Server 2010, Web Applications, Office Web Apps Server 2010 and 2013, Word Viewer, Word 2007, 2010, 2013 and 201 | Oct 13, 2017 | 7.8 | 92 | YES | NO |
CVE-2020-16952HIGH <p>A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package. An attacker who successfully e | Oct 16, 2020 | 8.6 | 80 | NO | YES |
CVE-2023-21716CRITICAL Microsoft Word Remote Code Execution Vulnerability | Feb 14, 2023 | 9.8 | 77 | NO | NO |
CVE-2022-38053HIGH Microsoft SharePoint Server Remote Code Execution Vulnerability | Oct 11, 2022 | 8.8 | 71 | NO | NO |
CVE-2020-1181HIGH A remote code execution vulnerability exists in Microsoft SharePoint Server when it fails to properly identify and filter unsafe ASP.Net web controls, aka 'Microsoft SharePoint Ser | Jun 9, 2020 | 8.8 | 61 | NO | NO |
CVE-2023-24950MEDIUM Microsoft SharePoint Server Spoofing Vulnerability | May 9, 2023 | 6.5 | 58 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (256 CVEs).
CISA KEV
5 CVEs
2.0% of CVEs· 96th percentile
Metasploit
5 CVEs
2.0% of CVEs· 96th percentile
Nuclei
3 CVEs
1.2% of CVEs· 96th percentile
ExploitDB
3 CVEs
1.2% of CVEs· 87th percentile
Social Chatter
Signals from CVEs in this product scope (256 CVEs).
Media Mentions
Signals from CVEs in this product scope (256 CVEs).
Top CNAs Publishing CVEs For Sharepoint Enterprise Server
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2019 | 3 | 5.8 | 1.9% | 0 | 0 |
| 2016 | 246 | 7.1 | 8.3% | 5 | 7 |
| 2013 | 104 | 7.0 | 7.9% | 1 | 1 |
| 2010 | 1 | 5.4 | 2.3% | 0 | 0 |