Sharepoint Server
Vendor:
First CVE: May 9, 2007 · Active for 19 years
559
Total CVEs
More Total CVEs than 100% of tracked products
27.9
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
7.1
Avg CVSS
Higher Avg CVSS than 43% of tracked products
3.4%
KEV Rate
Higher KEV Rate than 97% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Sharepoint Server over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 9, 2007
19 years ago
Most Recent CVE
Jul 16, 2026
8 days ago
CVE Severity & Scoring
Sharepoint Server559 CVEs
40%
56%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local140 (25.0%)
Network342 (61.2%)
Unknown75 (13.4%)
Physical0 (0.0%)
Adjacent Network2 (0.4%)
Attack Complexity
Low473 (84.6%)
High11 (2.0%)
Unknown75 (13.4%)
User Interaction
None191 (34.2%)
Unknown75 (13.4%)
Required293 (52.4%)
Privileges Required
Low256 (45.8%)
High15 (2.7%)
None213 (38.1%)
Unknown75 (13.4%)
Top CVEs
Signals from CVEs in this product scope (559 CVEs).
559 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-53770CRITICAL Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network.
Microsoft is aware that an exploit for | Jul 20, 2025 | 9.8 | 99 | YES | YES |
CVE-2025-49706MEDIUM Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. | Jul 8, 2025 | 6.5 | 98 | YES | YES |
CVE-2023-29357CRITICAL Microsoft SharePoint Server Elevation of Privilege Vulnerability | Jun 14, 2023 | 9.8 | 98 | YES | YES |
CVE-2020-1147HIGH A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of XML file input, aka '. | Jul 14, 2020 | 7.8 | 98 | YES | YES |
CVE-2019-0604CRITICAL A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote | Mar 5, 2019 | 9.8 | 98 | YES | YES |
CVE-2025-49704HIGH Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | Jul 8, 2025 | 8.8 | 97 | YES | YES |
CVE-2012-1889HIGH Microsoft XML Core Services 3.0, 4.0, 5.0, and 6.0 accesses uninitialized memory locations, which allows remote attackers to execute arbitrary code or cause a denial of service (me | Jun 13, 2012 | 8.8 | 97 | YES | YES |
CVE-2014-1761HIGH Microsoft Word 2003 SP3, 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT; Word Viewer; Office Compatibility Pack SP3; Office for Mac 2011; Word Automation Services on SharePoint Serv | Mar 25, 2014 | 7.8 | 96 | YES | YES |
CVE-2023-24955HIGH Microsoft SharePoint Server Remote Code Execution Vulnerability | May 9, 2023 | 7.2 | 95 | YES | YES |
CVE-2015-1641HIGH Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word for Mac 2011, Office Compatibility Pack SP3, Word Automation Services on SharePoint S | Apr 14, 2015 | 7.8 | 94 | YES | NO |
Exploit Exposure
Signals from CVEs in this product scope (559 CVEs).
CISA KEV
19 CVEs
3.4% of CVEs· 97th percentile
Metasploit
12 CVEs
2.1% of CVEs· 96th percentile
Nuclei
6 CVEs
1.1% of CVEs· 96th percentile
ExploitDB
19 CVEs
3.4% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (559 CVEs).
Media Mentions
Signals from CVEs in this product scope (559 CVEs).
Top CNAs Publishing CVEs For Sharepoint Server
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2019 | 396 | 7.2 | 8.0% | 14 | 13 |
| 2016 | 212 | 7.3 | 7.7% | 9 | 5 |
| 2013 | 85 | 7.1 | 16.7% | 3 | 3 |
| 2010 | 128 | 7.0 | 19.8% | 6 | 7 |
| 2007 | 34 | 6.7 | 26.7% | 0 | 7 |
| 2.0 | 1 | 4.3 | 8.0% | 0 | 1 |
| 16.0.19725.20434 | 1 | 5.5 | 0.5% | 0 | 0 |