High
CVSS: 8.8
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
High
CVSS: 8.8
Improper input validation in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
High
CVSS: 8.1
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
Critical
KEV CVSS: 9.8
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
Medium
CVSS: 4.6
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Medium
CVSS: 5.4
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.
High
CVSS: 7.8
Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally.
High
CVSS: 8.8
Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
High
CVSS: 8.8
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
High
CVSS: 8.0
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
High
CVSS: 8.8
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
High
CVSS: 8.8
Improper input validation in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
High
CVSS: 8.8
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
High
CVSS: 7.1
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
High
CVSS: 8.8
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
Medium
CVSS: 6.5
Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
Critical
KEV CVSS: 9.8
Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network.
Microsoft is aware that an exploit for CVE-2025-53770 exists in the wild.
Microsoft is preparing an…
High
KEV CVSS: 8.8
Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
High
CVSS: 8.8
Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
High
CVSS: 7.4
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally.