VendorsMicrosoftofficeall versions
Vulnerabilities

Microsoft Office

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1034CVEs
CVE-2023-36762
Microsoft Word Remote Code Execution Vulnerability
Published 2023-09-12 · Modified
7.3EPSS 0.008
CVE-2022-33631
Microsoft Excel Security Feature Bypass Vulnerability
Published 2022-08-09 · Modified
7.3EPSS 0.008
CVE-2000-0088
Buffer overflow in the conversion utilities for Japanese, Korean and Chinese Word 5 documents allows an attacker to execute commands, aka the "Malformed Conversion Data" vulnerability.
Published 2000-03-22 · Modified
7.2EPSS 0.019
CVE-2006-0008
The ShellAbout API call in Korean Input Method Editor (IME) in Korean versions of Microsoft Windows XP SP1 and SP2, Windows Server 2003 up to SP1, and Office 2003, allows local users to gain privileges by launching the "shell about dialog box" and clicking the "End-User License Agreement" link, which executes Notepad with the privileges of the program that displays the about box.
Published 2006-02-14 · Modified
7.2EPSS 0.017
CVE-2016-7276
Microsoft Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office for Mac 2011, and Office 2016 for Mac allow remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read) via a crafted document, aka "Microsoft Office Information Disclosure Vulnerability."
Published 2016-12-20 · Modified
7.1EPSS 0.251
CVE-2016-7290
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Office Compatibility Pack SP3, Word for Mac 2011, Word Automation Services on SharePoint Server 2010 SP2, and Office Web Apps 2010 SP2 allow remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read) via a crafted document, aka "Microsoft Office Information Disclosure Vulnerability," a different vulnerability than CVE-2016-7291.
Published 2016-12-20 · Modified
7.1EPSS 0.228
CVE-2016-7291
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Office Compatibility Pack SP3, Word for Mac 2011, Word Automation Services on SharePoint Server 2010 SP2, and Office Web Apps 2010 SP2 allow remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read) via a crafted document, aka "Microsoft Office Information Disclosure Vulnerability," a different vulnerability than CVE-2016-7290.
Published 2016-12-20 · Modified
7.1EPSS 0.228
CVE-2016-7268
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Office Compatibility Pack SP3, Word Viewer, Word for Mac 2011, Word Automation Services on SharePoint Server 2010 SP2, and Office Web Apps 2010 SP2 allow remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read) via a crafted document, aka "Microsoft Office Information Disclosure Vulnerability."
Published 2016-12-20 · Modified
7.1EPSS 0.226
CVE-2019-1461
A denial of service vulnerability exists in Microsoft Word software when the software fails to properly handle objects in memory, aka 'Microsoft Word Denial of Service Vulnerability'.
Published 2019-12-10 · Modified
7.1EPSS 0.046
CVE-2023-21741
Microsoft Office Visio Information Disclosure Vulnerability
Published 2023-01-10 · Modified
7.1EPSS 0.018
CVE-2025-59235
Microsoft Excel Information Disclosure Vulnerability
Published 2025-10-14 · Analyzed
7.1EPSS 0.007
CVE-2025-54905
Microsoft Word Information Disclosure Vulnerability
Published 2025-09-09 · Analyzed
7.1EPSS 0.006
CVE-2023-23398
Microsoft Excel Spoofing Vulnerability
Published 2023-03-14 · Modified
7.1EPSS 0.006
CVE-2025-60726
Microsoft Excel Information Disclosure Vulnerability
Published 2025-11-11 · Analyzed
7.1EPSS 0.006
CVE-2026-32188
Microsoft Excel Information Disclosure Vulnerability
Published 2026-04-14 · Analyzed
7.1EPSS 0.005
CVE-2025-62202
Microsoft Excel Information Disclosure Vulnerability
Published 2025-11-11 · Analyzed
7.1EPSS 0.005
CVE-2025-59232
Microsoft Excel Information Disclosure Vulnerability
Published 2025-10-14 · Analyzed
7.1EPSS 0.005
CVE-2021-27055
Microsoft Visio Security Feature Bypass Vulnerability
Published 2021-03-11 · Modified
7.0EPSS 0.025
CVE-2026-20943
Microsoft Office Click-To-Run Remote Code Execution Vulnerability
Published 2026-01-13 · Analyzed
7.0EPSS 0.007
CVE-2025-24078
Microsoft Word Remote Code Execution Vulnerability
Published 2025-03-11 · Analyzed
7.0EPSS 0.006
CVE-2025-62555
Microsoft Word Remote Code Execution Vulnerability
Published 2025-12-09 · Analyzed
7.0EPSS 0.005
CVE-2023-36568
Microsoft Office Click-To-Run Elevation of Privilege Vulnerability
Published 2023-10-10 · Modified
7.0EPSS 0.004
CVE-2024-49059
Microsoft Office Elevation of Privilege Vulnerability
Published 2024-12-10 · Analyzed
7.0EPSS 0.004
CVE-2023-36565
Microsoft Office Graphics Elevation of Privilege Vulnerability
Published 2023-10-10 · Modified
7.0EPSS 0.004
CVE-2025-59221
Microsoft Word Remote Code Execution Vulnerability
Published 2025-10-14 · Analyzed
7.0EPSS 0.004
CVE-2025-49699
Microsoft Office Remote Code Execution Vulnerability
Published 2025-07-08 · Analyzed
7.0EPSS 0.003
CVE-2026-47293
Microsoft Office Click-To-Run Elevation of Privilege Vulnerability
Published 2026-06-09 · Analyzed
7.0EPSS 0.003
CVE-2013-3859
Microsoft Pinyin IME 2010, when used in conjunction with Microsoft Office 2010 SP1, does not properly restrict configuration options, which allows local users to gain privileges by starting Internet Explorer from the IME toolbar, aka "Chinese IME Vulnerability."
Published 2013-09-11 · Modified
6.9EPSS 0.017
CVE-2012-1894
Microsoft Office for Mac 2011 uses world-writable permissions for the "Applications/Microsoft Office 2011/" directory and certain other directories, which allows local users to gain privileges by placing a Trojan horse executable file in one of these directories, aka "Office for Mac Improper Folder Permissions Vulnerability."
Published 2012-07-10 · Modified
6.9EPSS 0.016
CVE-2008-1455
A "memory calculation error" in Microsoft Office PowerPoint 2000 SP3, 2002 SP3, 2003 SP2, and 2007 through SP1; Office Compatibility Pack for Word, Excel, and PowerPoint 2007 through SP1; and Office 2004 for Mac allows remote attackers to execute arbitrary code via a PowerPoint file with crafted list values that trigger memory corruption, aka "Parsing Overflow Vulnerability."
Published 2008-08-13 · Modified
6.8EPSS 0.255
CVE-2002-0862
The (1) CertGetCertificateChain, (2) CertVerifyCertificateChainPolicy, and (3) WinVerifyTrust APIs within the CryptoAPI for Microsoft products including Microsoft Windows 98 through XP, Office for Mac, Internet Explorer for Mac, and Outlook Express for Mac, do not properly verify the Basic Constraints of intermediate CA-signed X.509 certificates, which allows remote attackers to spoof the certificates of trusted sites via a man-in-the-middle attack for SSL sessions, as originally reported for Internet Explorer and IIS.
Published 2002-09-10 · Modified
6.81 PoCEPSS 0.158
CVE-2014-1809
The MSCOMCTL library in Microsoft Office 2007 SP3, 2010 SP1 and SP2, and 2013 Gold, SP1, RT, and RT SP1 makes it easier for remote attackers to bypass the ASLR protection mechanism via a crafted web site, as exploited in the wild in May 2014, aka "MSCOMCTL ASLR Vulnerability."
Published 2014-05-14 · Modified
6.8EPSS 0.101
CVE-2020-17063
Microsoft Office Online Spoofing Vulnerability
Published 2020-11-11 · Modified
6.8EPSS 0.016
CVE-2025-53736
Microsoft Word Information Disclosure Vulnerability
Published 2025-08-12 · Analyzed
6.8EPSS 0.005
CVE-2025-47171
Microsoft Outlook Remote Code Execution Vulnerability
Published 2025-06-10 · Analyzed
6.71 PoCEPSS 0.017
CVE-2024-38173
Microsoft Outlook Remote Code Execution Vulnerability
Published 2024-08-13 · Analyzed
6.7EPSS 0.007
CVE-2025-21357
Microsoft Outlook Remote Code Execution Vulnerability
Published 2025-01-14 · Analyzed
6.7EPSS 0.006
CVE-2008-3003
Microsoft Office Excel 2007 Gold and SP1 does not properly delete the PWD (password) string from connections.xml when a .xlsx file is configured not to save the remote data session password, which allows local users to obtain sensitive information and obtain access to a remote data source, aka the "Excel Credential Caching Vulnerability."
Published 2008-08-12 · Modified
6.6EPSS 0.017
CVE-2023-36413
Microsoft Office Security Feature Bypass Vulnerability
Published 2023-11-14 · Modified
6.5EPSS 0.300
CVE-2016-7233
Microsoft Word 2007, Office 2010 SP2, Word 2010 SP2, Word for Mac 2011, Excel for Mac 2011, Word Viewer, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2013 SP1, and Office Web Apps 2010 SP2 allow remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read) via a crafted Office document, aka "Microsoft Office Information Disclosure Vulnerability."
Published 2016-11-10 · Modified
6.5EPSS 0.224
← Prev22 / 26Next →