Vulnerabilities (CVE)

Filtered by vendor Microsoft Subscribe
Filtered by product Office
Total 976 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-60727 1 Microsoft 5 365 Apps, Excel, Office and 2 more 2025-11-17 N/A 7.8 HIGH
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-62199 1 Microsoft 4 365 Apps, Excel, Office and 1 more 2025-11-17 N/A 7.8 HIGH
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2025-62200 1 Microsoft 5 365 Apps, Excel, Office and 2 more 2025-11-17 N/A 7.8 HIGH
Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-62201 1 Microsoft 5 365 Apps, Excel, Office and 2 more 2025-11-17 N/A 7.8 HIGH
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-62202 1 Microsoft 5 365 Apps, Excel, Office and 2 more 2025-11-17 N/A 7.1 HIGH
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2025-62203 1 Microsoft 5 365 Apps, Excel, Office and 2 more 2025-11-17 N/A 7.8 HIGH
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-60726 1 Microsoft 5 365 Apps, Excel, Office and 2 more 2025-11-17 N/A 7.1 HIGH
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2025-60724 1 Microsoft 16 Office, Office Long Term Servicing Channel, Windows 10 1607 and 13 more 2025-11-17 N/A 9.8 CRITICAL
Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.
CVE-2025-59240 1 Microsoft 4 365 Apps, Excel, Office and 1 more 2025-11-17 N/A 5.5 MEDIUM
Exposure of sensitive information to an unauthorized actor in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2021-27059 1 Microsoft 1 Office 2025-10-30 8.5 HIGH 7.6 HIGH
Microsoft Office Remote Code Execution Vulnerability
CVE-2021-42292 1 Microsoft 4 365 Apps, Excel, Office and 1 more 2025-10-30 6.8 MEDIUM 7.8 HIGH
Microsoft Excel Security Feature Bypass Vulnerability
CVE-2021-38646 1 Microsoft 2 365 Apps, Office 2025-10-30 6.8 MEDIUM 7.8 HIGH
Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability
CVE-2019-0541 1 Microsoft 18 Excel Viewer, Internet Explorer, Office and 15 more 2025-10-29 9.3 HIGH 8.8 HIGH
A remote code execution vulnerability exists in the way that the MSHTML engine inproperly validates input, aka "MSHTML Engine Remote Code Execution Vulnerability." This affects Microsoft Office, Microsoft Office Word Viewer, Internet Explorer 9, Internet Explorer 11, Microsoft Excel Viewer, Internet Explorer 10, Office 365 ProPlus.
CVE-2019-1297 1 Microsoft 3 Excel, Office, Office 365 Proplus 2025-10-29 9.3 HIGH 8.8 HIGH
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'.
CVE-2025-59231 1 Microsoft 5 365 Apps, Excel, Office and 2 more 2025-10-28 N/A 7.8 HIGH
Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-59233 1 Microsoft 5 365 Apps, Excel, Office and 2 more 2025-10-28 N/A 7.8 HIGH
Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-59234 1 Microsoft 3 365 Apps, Office, Office Long Term Servicing Channel 2025-10-28 N/A 7.8 HIGH
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2025-59236 1 Microsoft 4 365 Apps, Office, Office Long Term Servicing Channel and 1 more 2025-10-28 N/A 8.4 HIGH
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2018-0798 1 Microsoft 3 Office, Office Compatibility Pack, Word 2025-10-28 9.3 HIGH 8.8 HIGH
Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Office Memory Corruption Vulnerability".
CVE-2018-0802 1 Microsoft 3 Office, Office Compatibility Pack, Word 2025-10-28 9.3 HIGH 7.8 HIGH
Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Office Memory Corruption Vulnerability". This CVE is unique from CVE-2018-0797 and CVE-2018-0812.