VendorsMicrosoftwordall versions
Vulnerabilities

Microsoft Word

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

320CVEs
CVE-2022-29107
Microsoft Office Security Feature Bypass Vulnerability
Published 2022-05-10 · Modified
5.5EPSS 0.029
CVE-2020-17020
Microsoft Word Security Feature Bypass Vulnerability
Published 2020-11-11 · Modified
5.5EPSS 0.013
CVE-2024-49065
Microsoft Office Remote Code Execution Vulnerability
Published 2024-12-10 · Analyzed
5.5EPSS 0.011
CVE-2022-24511
Microsoft Office Word Tampering Vulnerability
Published 2022-03-09 · Modified
5.5EPSS 0.011
CVE-2022-41103
Microsoft Word Information Disclosure Vulnerability
Published 2022-11-09 · Modified
5.5EPSS 0.009
CVE-2022-41060
Microsoft Word Information Disclosure Vulnerability
Published 2022-11-09 · Modified
5.5EPSS 0.008
CVE-2026-55050
Microsoft Word Information Disclosure Vulnerability
Published 2026-07-14 · Analyzed
5.5EPSS 0.006
CVE-2026-55124
Microsoft Word Information Disclosure Vulnerability
Published 2026-07-14 · Analyzed
5.5EPSS 0.006
CVE-2026-55142
Microsoft Word Information Disclosure Vulnerability
Published 2026-07-14 · Analyzed
5.5EPSS 0.006
CVE-2026-35440
Microsoft Word Information Disclosure Vulnerability
Published 2026-05-12 · Analyzed
5.5EPSS 0.005
CVE-2026-63528
Microsoft Office Word Information Disclosure Vulnerability
Published 2026-08-11 · Analyzed
5.5EPSS 0.005
CVE-2026-63530
Microsoft Office Word Information Disclosure Vulnerability
Published 2026-08-11 · Analyzed
5.5EPSS 0.005
CVE-2026-63531
Microsoft Office Word Information Disclosure Vulnerability
Published 2026-08-11 · Analyzed
5.5EPSS 0.005
CVE-2026-64917
Microsoft Office Word Information Disclosure Vulnerability
Published 2026-08-11 · Analyzed
5.5EPSS 0.005
CVE-2026-70318
Microsoft Excel Information Disclosure Vulnerability
Published 2026-08-11 · Analyzed
5.5EPSS 0.005
CVE-2026-78506
Microsoft Office Word Information Disclosure Vulnerability
Published 2026-09-08 · Analyzed
5.5EPSS 0.005
CVE-2026-83949
Microsoft Office Word Information Disclosure Vulnerability
Published 2026-09-08 · Analyzed
5.5EPSS 0.005
CVE-2026-83951
Microsoft Office Word Information Disclosure Vulnerability
Published 2026-09-08 · Analyzed
5.5EPSS 0.005
CVE-2026-63521
Microsoft Office Word Information Disclosure Vulnerability
Published 2026-08-11 · Analyzed
5.5EPSS 0.004
CVE-2026-66806
Microsoft Office Word Information Disclosure Vulnerability
Published 2026-08-11 · Analyzed
5.5EPSS 0.004
CVE-2026-66809
Microsoft Office Graphics Component Information Disclosure Vulnerability
Published 2026-08-11 · Analyzed
5.5EPSS 0.004
CVE-2026-66810
Microsoft Office Word Information Disclosure Vulnerability
Published 2026-08-11 · Analyzed
5.5EPSS 0.004
CVE-2026-70310
Microsoft Word Information Disclosure Vulnerability
Published 2026-08-11 · Analyzed
5.5EPSS 0.004
CVE-2005-0558
Buffer overflow in Microsoft Word 2000, Word 2002, and Word 2003 allows remote attackers to execute arbitrary code via a crafted document.
Published 2005-04-13 · Modified
5.1EPSS 0.152
CVE-2000-0765
Buffer overflow in the HTML interpreter in Microsoft Office 2000 allows an attacker to execute arbitrary commands via a long embedded object tag, aka the "Microsoft Office HTML Object Tag" vulnerability.
Published 2000-10-13 · Modified
5.1EPSS 0.040
CVE-2002-1143
Microsoft Word and Excel allow remote attackers to steal sensitive information via certain field codes that insert the information when the document is returned to the attacker, as demonstrated in Word using (1) INCLUDETEXT or (2) INCLUDEPICTURE, aka "Flaw in Word Fields and Excel External Updates Could Lead to Information Disclosure."
Published 2003-04-03 · Modified
5.02 PoCEPSS 0.536
CVE-2013-3160
Microsoft Office 2003 SP3 and 2007 SP3, Word 2003 SP3 and 2007 SP3, and Word Viewer allow remote attackers to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, aka "XML External Entities Resolution Vulnerability."
Published 2013-09-11 · Modified
5.0EPSS 0.233
CVE-2026-72976
Microsoft Office Word Information Disclosure Vulnerability
Published 2026-09-08 · Analyzed
5.0EPSS 0.005
CVE-2001-0501
Microsoft Word 2002 and earlier allows attackers to automatically execute macros without warning the user by embedding the macros in a manner that escapes detection by the security scanner.
Published 2002-03-09 · Modified
4.6EPSS 0.017
CVE-2001-0240
Microsoft Word before Word 2002 allows attackers to automatically execute macros without warning the user via a Rich Text Format (RTF) document that links to a template with the embedded macro.
Published 2001-09-18 · Modified
4.6EPSS 0.014
CVE-2015-2423
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, Windows 10, Excel 2007 SP3, PowerPoint 2007 SP3, Visio 2007 SP3, Word 2007 SP3, Office 2010 SP2, Excel 2010 SP2, PowerPoint 2010 SP2, Visio 2010 SP2, Word 2010 SP2, Excel 2013 SP1, PowerPoint 2013 SP1, Visio 2013 SP1, Word 2013 SP1, Excel 2013 RT SP1, PowerPoint 2013 RT SP1, Visio 2013 RT SP1, Word 2013 RT SP1, and Internet Explorer 7 through 11 allow remote attackers to gain privileges and obtain sensitive information via a crafted command-line parameter to an Office application or Notepad, as demonstrated by a transition from Low Integrity to Medium Integrity, aka "Unsafe Command Line Parameter Passing Vulnerability."
Published 2015-08-15 · Modified
4.3EPSS 0.199
CVE-2018-0919
Microsoft Office 2010 SP2, 2013 SP1, and 2016, Microsoft Office 2016 Click-to-Run Microsoft Office 2016 for Mac, Microsoft Office Web Apps 2010 SP2, Microsoft Office Web Apps 2013 SP1, Microsoft SharePoint Enterprise Server 2013 SP1, Microsoft SharePoint Enterprise Server 2016, Microsoft SharePoint Server 2010 SP2, Microsoft Word 2010 SP2, Word 2013 SP1 and Microsoft Word 2016 allow an information disclosure vulnerability due to how variables are initialized, aka "Microsoft Office Information Disclosure Vulnerability".
Published 2018-03-14 · Modified
4.3EPSS 0.117
CVE-2016-0012
Microsoft Office 2007 SP3, Excel 2007 SP3, PowerPoint 2007 SP3, Visio 2007 SP3, Word 2007 SP3, Office 2010 SP2, Excel 2010 SP2, PowerPoint 2010 SP2, Visio 2010 SP2, Word 2010 SP2, Office 2013 SP1, Excel 2013 SP1, PowerPoint 2013 SP1, Visio 2013 SP1, Word 2013 SP1, Excel 2013 RT SP1, PowerPoint 2013 RT SP1, Word 2013 RT SP1, Office 2016, Excel 2016, PowerPoint 2016, Visio 2016, Word 2016, and Visual Basic 6.0 Runtime allow remote attackers to bypass the ASLR protection mechanism via unspecified vectors, aka "Microsoft Office ASLR Bypass."
Published 2016-01-13 · Modified
4.3EPSS 0.109
CVE-2010-3200
MSO.dll in Microsoft Word 2003 SP3 11.8326.11.8324 allows remote attackers to cause a denial of service (NULL pointer dereference and multiple-instance application crash) via a crafted buffer in a Word document, as demonstrated by word_crash_11.8326.8324_poc.doc.
Published 2010-09-20 · Modified
4.3EPSS 0.106
CVE-2008-6063
Microsoft Word 2007, when the "Save as PDF" add-on is enabled, places an absolute pathname in the Subject field during an "Email as PDF" operation, which allows remote attackers to obtain sensitive information such as the sender's account name and a Temporary Internet Files subdirectory name.
Published 2009-02-05 · Modified
4.3EPSS 0.103
CVE-2020-1229
A security feature bypass vulnerability exists in Microsoft Outlook when Office fails to enforce security settings configured on a system, aka 'Microsoft Outlook Security Feature Bypass Vulnerability'.
Published 2020-06-09 · Modified
4.3EPSS 0.038
CVE-2012-0765
Multiple cross-site scripting (XSS) vulnerabilities in Adobe RoboHelp 8 and 9 for Word allow remote attackers to inject arbitrary web script or HTML via a crafted URL, related to certain .htm files in (1) template_stock and (2) template_csh directories.
Published 2012-02-15 · Modified
4.3EPSS 0.026
CVE-2026-40421
Microsoft Word Information Disclosure Vulnerability
Published 2026-05-12 · Modified
4.3EPSS 0.007
CVE-2005-1683
Buffer overflow in winword.exe 10.2627.6714 and earlier in Microsoft Word for the Macintosh, before SP3 for Word 2002, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted mcw file.
Published 2005-05-25 · Modified
2.6EPSS 0.146
CVE-2006-0935
Microsoft Word 2003 allows remote attackers to cause a denial of service (application crash) via a crafted file, as demonstrated by 101_filefuzz.
Published 2006-02-28 · Modified
2.6EPSS 0.064
← Prev8 / 8