Exploited Vulnerabilities Daily
🌐 English

Home › Microsoft

CVE-2019-0604: Microsoft SharePoint

EPSS99.9%No. 119 of 1739 in KEV
CVE year2019~2 yrs before listing
Same vendor in KEV389
Same product10
FieldValue
VendorMicrosoft
ProductSharePoint
NameMicrosoft SharePoint Remote Code Execution Vulnerability
Added to KEV2021-11-03
US federal due date2022-05-03
Ransomware useKnown
CWECWE-20

CISA description

Microsoft SharePoint fails to check the source markup of an application package. An attacker who successfully exploits the vulnerability could run remote code in the context of the SharePoint application pool and the SharePoint server farm account.

Other entries for this product

CVEVendor / productAddedEPSSRansomware
CVE-2026-65660Microsoft SharePoint2026-09-252.1%Unknown
CVE-2026-55040Microsoft SharePoint2026-08-1869.5%Unknown
CVE-2026-50522Microsoft SharePoint2026-07-223.0%Unknown
CVE-2026-58644Microsoft SharePoint2026-07-1615.8%Unknown
CVE-2026-20963Microsoft SharePoint2026-03-1829.5%Unknown
CVE-2025-49706Microsoft SharePoint2025-07-2299.0%Known
CVE-2025-49704Microsoft SharePoint2025-07-2299.9%Known
CVE-2025-53770Microsoft SharePoint2025-07-2099.9%Known
CVE-2024-38094Microsoft SharePoint2024-10-2250.8%Known

NVD — CVE-2019-0604

Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.
About this page

A Microsoft SharePoint vulnerability added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03.