Sharepoint Server

Vendor:

First CVE: May 9, 2007 · Active for 19 years

559
Total CVEs
More Total CVEs than 100% of tracked products
27.9
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
7.1
Avg CVSS
Higher Avg CVSS than 43% of tracked products
3.4%
KEV Rate
Higher KEV Rate than 97% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Sharepoint Server over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 9, 2007
19 years ago
Most Recent CVE
Jul 16, 2026
8 days ago

CVE Severity & Scoring

Sharepoint Server559 CVEs
All CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local140 (25.0%)
Network342 (61.2%)
Unknown75 (13.4%)
Physical0 (0.0%)
Adjacent Network2 (0.4%)
Attack Complexity
Low473 (84.6%)
High11 (2.0%)
Unknown75 (13.4%)
User Interaction
None191 (34.2%)
Unknown75 (13.4%)
Required293 (52.4%)
Privileges Required
Low256 (45.8%)
High15 (2.7%)
None213 (38.1%)
Unknown75 (13.4%)

Top CVEs

Signals from CVEs in this product scope (559 CVEs).

559 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware that an exploit for
Jul 20, 20259.899YESYES
Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
Jul 8, 20256.598YESYES
Microsoft SharePoint Server Elevation of Privilege Vulnerability
Jun 14, 20239.898YESYES
A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of XML file input, aka '.
Jul 14, 20207.898YESYES
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote
Mar 5, 20199.898YESYES
Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Jul 8, 20258.897YESYES
Microsoft XML Core Services 3.0, 4.0, 5.0, and 6.0 accesses uninitialized memory locations, which allows remote attackers to execute arbitrary code or cause a denial of service (me
Jun 13, 20128.897YESYES
Microsoft Word 2003 SP3, 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT; Word Viewer; Office Compatibility Pack SP3; Office for Mac 2011; Word Automation Services on SharePoint Serv
Mar 25, 20147.896YESYES
Microsoft SharePoint Server Remote Code Execution Vulnerability
May 9, 20237.295YESYES
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word for Mac 2011, Office Compatibility Pack SP3, Word Automation Services on SharePoint S
Apr 14, 20157.894YESNO

Exploit Exposure

Signals from CVEs in this product scope (559 CVEs).

CISA KEV
19 CVEs
3.4% of CVEs· 97th percentile
Metasploit
12 CVEs
2.1% of CVEs· 96th percentile
Nuclei
6 CVEs
1.1% of CVEs· 96th percentile
ExploitDB
19 CVEs
3.4% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (559 CVEs).

Media Mentions

Signals from CVEs in this product scope (559 CVEs).

Top CNAs Publishing CVEs For Sharepoint Server

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
20193967.28.0%1413
20162127.37.7%95
2013857.116.7%33
20101287.019.8%67
2007346.726.7%07
2.014.38.0%01
16.0.19725.2043415.50.5%00