Microsoft
Microsoft Sharepoint Enterprise Server: vulnerabilidades y CVE
Microsoft Sharepoint Enterprise Server tiene 256 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 3 son críticas y 5 figuran en el catálogo de explotación activa de CISA.
CVE256
Últimos 12 meses0
Críticas3
Explotadas activamente5
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-49706 | Media (6.5) | 99% | ⚠ Explotación activa | 8 jul 2025 | Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. |
| CVE-2023-24955 | Alta (7.2) | 85% | ⚠ Explotación activa | 9 may 2023 | Microsoft SharePoint Server Remote Code Execution Vulnerability |
| CVE-2017-11826 | Alta (7.8) | 81% | ⚠ Explotación activa | 13 oct 2017 | Microsoft Office 2010, SharePoint Enterprise Server 2010, SharePoint Server 2010, Web Applications, Office Web Apps Server 2010 and 2013, Word Viewer, Word 2007, 2010, 2013 and 2016, Word Automation Services, and Office… |
| CVE-2019-0604 | Crítica (9.8) | 100% | ⚠ Explotación activa | 5 mar 2019 | A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package, aka 'Microsoft SharePoint Remote Code Execution Vulnerability'. This CVE… |
| CVE-2020-1147 | Alta (7.8) | 94% | ⚠ Explotación activa | 14 jul 2020 | A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the software fails to check the source markup of XML file input, aka '.NET Framework, SharePoint Server, and… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-54905 | Alta (7.1) | 0.63% | — | 9 sept 2025 | Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to disclose information locally. |
| CVE-2025-53736 | Media (6.2) | 0.50% | — | 12 ago 2025 | Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. |
| CVE-2025-53733 | Alta (8.4) | 0.55% | — | 12 ago 2025 | Incorrect conversion between numeric types in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
| CVE-2025-49706 | Media (6.5) | 99% | ⚠ Explotación activa | 8 jul 2025 | Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. |
| CVE-2025-47994 | Alta (8.6) | 3.0% | — | 8 jul 2025 | Deserialization of untrusted data in Microsoft Office allows an unauthorized attacker to elevate privileges locally. |
| CVE-2025-47172 | Alta (8.8) | 1.7% | — | 10 jun 2025 | Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. |
| CVE-2025-47169 | Alta (7.8) | 0.65% | — | 10 jun 2025 | Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
| CVE-2025-47168 | Alta (7.8) | 0.64% | — | 10 jun 2025 | Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
| CVE-2025-47166 | Alta (8.8) | 21% | — | 10 jun 2025 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. |
| CVE-2025-47163 | Alta (8.8) | 20% | — | 10 jun 2025 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. |
| CVE-2025-29820 | Alta (7.8) | 0.77% | — | 8 abr 2025 | Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
| CVE-2025-29794 | Alta (8.8) | 5.1% | — | 8 abr 2025 | Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. |
| CVE-2025-29793 | Alta (7.2) | 24% | — | 8 abr 2025 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. |
| CVE-2025-27747 | Alta (7.8) | 0.82% | — | 8 abr 2025 | Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
| CVE-2023-38177 | Media (6.8) | 3.4% | — | 14 nov 2023 | Microsoft SharePoint Server Remote Code Execution Vulnerability |
| CVE-2023-24955 | Alta (7.2) | 85% | ⚠ Explotación activa | 9 may 2023 | Microsoft SharePoint Server Remote Code Execution Vulnerability |
| CVE-2023-24954 | Media (6.5) | 1.8% | — | 9 may 2023 | Microsoft SharePoint Server Information Disclosure Vulnerability |
| CVE-2023-24950 | Media (6.5) | 67% | — | 9 may 2023 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2023-21717 | Alta (8.8) | 1.1% | — | 14 feb 2023 | Microsoft SharePoint Server Elevation of Privilege Vulnerability |
| CVE-2023-21716 | Crítica (9.8) | 85% | — | 14 feb 2023 | Microsoft Word Remote Code Execution Vulnerability |
| CVE-2022-44693 | Alta (8.8) | 2.0% | — | 13 dic 2022 | Microsoft SharePoint Server Remote Code Execution Vulnerability |
| CVE-2022-41122 | Media (6.5) | 1.6% | — | 9 nov 2022 | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2022-41103 | Media (5.5) | 0.92% | — | 9 nov 2022 | Microsoft Word Information Disclosure Vulnerability |
| CVE-2022-41062 | Alta (8.8) | 1.6% | — | 9 nov 2022 | Microsoft SharePoint Server Remote Code Execution Vulnerability |
| CVE-2022-41061 | Alta (7.8) | 1.2% | — | 9 nov 2022 | Microsoft Word Remote Code Execution Vulnerability |
| CVE-2022-41060 | Media (5.5) | 0.79% | — | 9 nov 2022 | Microsoft Word Information Disclosure Vulnerability |
| CVE-2022-38053 | Alta (8.8) | 76% | — | 11 oct 2022 | Microsoft SharePoint Server Remote Code Execution Vulnerability |
| CVE-2022-38009 | Alta (8.8) | 2.1% | — | 13 sept 2022 | Microsoft SharePoint Server Remote Code Execution Vulnerability |
| CVE-2022-38008 | Alta (8.8) | 2.0% | — | 13 sept 2022 | Microsoft SharePoint Server Remote Code Execution Vulnerability |
| CVE-2022-37961 | Alta (8.8) | 51% | — | 13 sept 2022 | Microsoft SharePoint Server Remote Code Execution Vulnerability |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.