VendorsMicrosoftexcelall versions
Vulnerabilities

Microsoft Excel

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

502CVEs
CVE-2000-0419
The Office 2000 UA ActiveX Control is marked as "safe for scripting," which allows remote attackers to conduct unauthorized activities via the "Show Me" function in Office Help, aka the "Office 2000 UA Control" vulnerability.
Published 2000-07-12 · Modified
7.5EPSS 0.214
CVE-2008-3068
Microsoft Crypto API 5.131.2600.2180 through 6.0, as used in Outlook, Windows Live Mail, and Office 2007, performs Certificate Revocation List (CRL) checks by using an arbitrary URL from a certificate embedded in a (1) S/MIME e-mail message or (2) signed document, which allows remote attackers to obtain reading times and IP addresses of recipients, and port-scan results, via a crafted certificate with an Authority Information Access (AIA) extension.
Published 2008-07-07 · Modified
7.5EPSS 0.174
CVE-2002-0152
Buffer overflow in various Microsoft applications for Macintosh allows remote attackers to cause a denial of service (crash) or execute arbitrary code by invoking the file:// directive with a large number of / characters, which affects Internet Explorer 5.1, Outlook Express 5.0 through 5.0.2, Entourage v. X and 2001, PowerPoint v. X, 2001, and 98, and Excel v. X and 2001 for Macintosh.
Published 2002-06-25 · Modified
7.5EPSS 0.174
CVE-2002-0618
The Macro Security Model in Microsoft Excel 2000 and 2002 for Windows allows remote attackers to execute code in the Local Computer zone by embedding HTML scripts within an Excel workbook that contains an XSL stylesheet, aka "Excel XSL Stylesheet Script Execution".
Published 2003-04-02 · Modified
7.5EPSS 0.145
CVE-2000-0597
Microsoft Office 2000 (Excel and PowerPoint) and PowerPoint 97 are marked as safe for scripting, which allows remote attackers to force Internet Explorer or some email clients to save files to arbitrary locations via the Visual Basic for Applications (VBA) SaveAs function, aka the "Office HTML Script" vulnerability.
Published 2000-10-13 · Modified
7.5EPSS 0.121
CVE-2001-0718
Vulnerability in (1) Microsoft Excel 2002 and earlier and (2) Microsoft PowerPoint 2002 and earlier allows attackers to bypass macro restrictions and execute arbitrary commands by modifying the data stream in the document.
Published 2002-03-09 · Modified
7.5EPSS 0.111
CVE-1999-1055
Microsoft Excel 97 does not warn the user before executing worksheet functions, which could allow attackers to execute arbitrary commands by using the CALL function to execute a malicious DLL, aka the Excel "CALL Vulnerability."
Published 2002-03-09 · Modified
7.5EPSS 0.070
CVE-2002-0615
The Windows Media Active Playlist in Microsoft Windows Media Player 7.1 stores information in a well known location on the local file system, allowing attackers to execute HTML scripts in the Local Computer zone, aka "Media Playback Script Invocation".
Published 2004-09-01 · Modified
7.5EPSS 0.056
CVE-2022-33631
Microsoft Excel Security Feature Bypass Vulnerability
Published 2022-08-09 · Modified
7.3EPSS 0.008
CVE-2000-0277
Microsoft Excel 97 and 2000 does not warn the user when executing Excel Macro Language (XLM) macros in external text files, which could allow an attacker to execute a macro virus, aka the "XLM Text Macro" vulnerability.
Published 2000-06-02 · Modified
7.2EPSS 0.016
CVE-2016-7264
Microsoft Excel 2007 SP3, Office Compatibility Pack SP3, Excel Viewer, Excel for Mac 2011, and Excel 2016 for Mac allow remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read) via a crafted document, aka "Microsoft Office Information Disclosure Vulnerability."
Published 2016-12-20 · Modified
7.1EPSS 0.232
CVE-2016-7265
Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Office Compatibility Pack SP3, Excel Viewer, Excel Services on SharePoint Server 2007 SP3, and Excel Services on SharePoint Server 2010 SP2 allow remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read) via a crafted document, aka "Microsoft Office Information Disclosure Vulnerability."
Published 2016-12-20 · Modified
7.1EPSS 0.226
CVE-2025-59235
Microsoft Excel Information Disclosure Vulnerability
Published 2025-10-14 · Analyzed
7.1EPSS 0.007
CVE-2023-23398
Microsoft Excel Spoofing Vulnerability
Published 2023-03-14 · Modified
7.1EPSS 0.006
CVE-2025-60726
Microsoft Excel Information Disclosure Vulnerability
Published 2025-11-11 · Analyzed
7.1EPSS 0.006
CVE-2026-26133
M365 Copilot Information Disclosure Vulnerability
Published 2026-03-13 · Modified
7.1EPSS 0.005
CVE-2026-32188
Microsoft Excel Information Disclosure Vulnerability
Published 2026-04-14 · Analyzed
7.1EPSS 0.005
CVE-2026-55122
Microsoft Excel Information Disclosure Vulnerability
Published 2026-07-14 · Analyzed
7.1EPSS 0.005
CVE-2025-62202
Microsoft Excel Information Disclosure Vulnerability
Published 2025-11-11 · Analyzed
7.1EPSS 0.005
CVE-2025-59232
Microsoft Excel Information Disclosure Vulnerability
Published 2025-10-14 · Analyzed
7.1EPSS 0.005
CVE-2026-55898
Microsoft Excel Information Disclosure Vulnerability
Published 2026-07-14 · Analyzed
7.1EPSS 0.005
CVE-2026-45649
Office for Android Spoofing Vulnerability
Published 2026-06-09 · Analyzed
7.1EPSS 0.004
CVE-2026-81389
Microsoft Excel Remote Code Execution Vulnerability
Published 2026-09-08 · Analyzed
7.0EPSS 0.004
CVE-2026-44818
Microsoft Excel Remote Code Execution Vulnerability
Published 2026-06-09 · Modified
7.0EPSS 0.003
CVE-2015-2378
Untrusted search path vulnerability in Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel Viewer 2007 SP3, and Office Compatibility Pack SP3 allows local users to gain privileges via a Trojan horse DLL in the current working directory, aka "Microsoft Excel DLL Remote Code Execution Vulnerability."
Published 2015-07-14 · Modified
6.9EPSS 0.061
CVE-2005-4131
Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via an Excel file with a malformed range, which could lead to memory corruption involving an argument to the msvcrt.memmove function, aka "Brand new Microsoft Excel Vulnerability," as originally placed for sale on eBay as item number 7203336538.
Published 2005-12-09 · Modified
6.81 PoCEPSS 0.311
CVE-2007-1214
Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2003 Viewer, and 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via a crafted AutoFilter filter record in an Excel BIFF8 format XLS file, which triggers memory corruption.
Published 2007-05-08 · Modified
6.8EPSS 0.285
CVE-2026-50678
Microsoft Excel Information Disclosure Vulnerability
Published 2026-07-14 · Analyzed
6.6EPSS 0.005
CVE-2019-0669
An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka 'Microsoft Excel Information Disclosure Vulnerability'.
Published 2019-03-06 · Modified
6.5EPSS 0.064
CVE-2020-17130
Microsoft Excel Security Feature Bypass Vulnerability
Published 2020-12-09 · Modified
6.5EPSS 0.023
CVE-2026-70328
Microsoft Excel Information Disclosure Vulnerability
Published 2026-08-11 · Analyzed
6.5EPSS 0.009
CVE-2026-70327
Microsoft Excel Information Disclosure Vulnerability
Published 2026-08-11 · Analyzed
6.5EPSS 0.009
CVE-2026-55054
Microsoft Excel Information Disclosure Vulnerability
Published 2026-07-14 · Analyzed
6.5EPSS 0.009
CVE-2026-54988
Microsoft Excel Information Disclosure Vulnerability
Published 2026-07-14 · Analyzed
6.1EPSS 0.005
CVE-2017-0194
Microsoft Excel 2007 SP3, Microsoft Excel 2010 SP2, and Office Compatibility Pack SP2 allow remote attackers to obtain sensitive information from process memory via a crafted Office document, aka "Microsoft Office Information Disclosure Vulnerability."
Published 2017-04-12 · Modified
5.5EPSS 0.255
CVE-2016-7267
Microsoft Excel 2010 SP2, 2013 SP1, 2013 RT SP1, and 2016 misparses file formats, which makes it easier for remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office Security Feature Bypass Vulnerability."
Published 2016-12-20 · Modified
5.5EPSS 0.194
CVE-2018-8246
An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka "Microsoft Excel Information Disclosure Vulnerability." This affects Microsoft Excel Viewer, Microsoft Office, Microsoft Excel.
Published 2018-06-14 · Modified
5.5EPSS 0.190
CVE-2016-3279
Microsoft Office 2010 SP2, Excel 2010 SP2, PowerPoint 2010 SP2, Word 2010 SP2, Excel 2013 SP1, PowerPoint 2013 SP1, Word 2013 SP1, Excel 2013 RT SP1, PowerPoint 2013 RT SP1, Word 2013 RT SP1, Excel 2016, Word 2016, Word Automation Services on SharePoint Server 2010 SP2, and Office Web Apps 2010 SP2 allow remote attackers to execute arbitrary code via a crafted XLA file, aka "Microsoft Office Remote Code Execution Vulnerability."
Published 2016-07-13 · Modified
5.5EPSS 0.164
CVE-2021-31178
Microsoft Office Information Disclosure Vulnerability
Published 2021-05-11 · Modified
5.5EPSS 0.160
CVE-2018-8163
An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka "Microsoft Excel Information Disclosure Vulnerability." This affects Microsoft Office, Microsoft Excel.
Published 2018-05-09 · Modified
5.5EPSS 0.132
← Prev11 / 13Next →