365 Apps
by Microsoft
CVEs (654)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-47165 | Hig | 0.54 | 7.8 | 0.02 | Jun 10, 2025 | Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | ||
| CVE-2025-27751 | Hig | 0.54 | 7.8 | 0.02 | Apr 8, 2025 | Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | ||
| CVE-2023-33148 | Hig | 0.54 | 7.8 | 0.02 | Jul 11, 2023 | Microsoft Office Elevation of Privilege Vulnerability | ||
| CVE-2023-33133 | Hig | 0.54 | 7.8 | 0.44 | Jun 14, 2023 | Microsoft Excel Remote Code Execution Vulnerability | ||
| CVE-2023-28311 | Hig | 0.54 | 7.8 | 0.03 | Apr 11, 2023 | Microsoft Word Remote Code Execution Vulnerability | ||
| CVE-2023-28285 | Hig | 0.54 | 7.8 | 0.03 | Apr 11, 2023 | Microsoft Office Remote Code Execution Vulnerability | ||
| CVE-2023-23399 | Hig | 0.54 | 7.8 | 0.03 | Mar 14, 2023 | Microsoft Excel Remote Code Execution Vulnerability | ||
| CVE-2021-34469 | Hig | 0.54 | 8.2 | 0.04 | Jul 14, 2021 | Microsoft Office Security Feature Bypass Vulnerability | ||
| CVE-2026-44822 | Hig | 0.53 | 8.2 | 0.01 | Jun 9, 2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2023-36897 | Hig | 0.53 | 8.1 | 0.02 | Aug 8, 2023 | Visual Studio Tools for Office Runtime Spoofing Vulnerability | ||
| CVE-2020-1349 | Hig | 0.53 | 7.8 | 0.23 | Jul 14, 2020 | A remote code execution vulnerability exists in Microsoft Outlook software when it fails to properly handle objects in memory, aka 'Microsoft Outlook Remote Code Execution Vulnerability'. | ||
| CVE-2021-31939 | Hig | 0.52 | 7.8 | 0.13 | Jun 8, 2021 | Microsoft Excel Remote Code Execution Vulnerability | ||
| CVE-2021-31179 | Hig | 0.52 | 7.8 | 0.13 | May 11, 2021 | Microsoft Office Remote Code Execution Vulnerability | ||
| CVE-2020-1458 | Hig | 0.52 | 7.8 | 0.11 | Jul 14, 2020 | A remote code execution vulnerability exists when Microsoft Office improperly validates input before loading dynamic link library (DLL) files, aka 'Microsoft Office Remote Code Execution Vulnerability'. | ||
| CVE-2026-70313 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally. | ||
| CVE-2026-70311 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-68817 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-68816 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-68815 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | ||
| CVE-2026-68814 | Hig | 0.51 | 7.8 | 0.00 | Aug 11, 2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally. |
- risk 0.54cvss 7.8epss 0.02
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- risk 0.54cvss 7.8epss 0.02
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- risk 0.54cvss 7.8epss 0.02
Microsoft Office Elevation of Privilege Vulnerability
- risk 0.54cvss 7.8epss 0.44
Microsoft Excel Remote Code Execution Vulnerability
- risk 0.54cvss 7.8epss 0.03
Microsoft Word Remote Code Execution Vulnerability
- risk 0.54cvss 7.8epss 0.03
Microsoft Office Remote Code Execution Vulnerability
- risk 0.54cvss 7.8epss 0.03
Microsoft Excel Remote Code Execution Vulnerability
- risk 0.54cvss 8.2epss 0.04
Microsoft Office Security Feature Bypass Vulnerability
- risk 0.53cvss 8.2epss 0.01
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.
- risk 0.53cvss 8.1epss 0.02
Visual Studio Tools for Office Runtime Spoofing Vulnerability
- risk 0.53cvss 7.8epss 0.23
A remote code execution vulnerability exists in Microsoft Outlook software when it fails to properly handle objects in memory, aka 'Microsoft Outlook Remote Code Execution Vulnerability'.
- risk 0.52cvss 7.8epss 0.13
Microsoft Excel Remote Code Execution Vulnerability
- risk 0.52cvss 7.8epss 0.13
Microsoft Office Remote Code Execution Vulnerability
- risk 0.52cvss 7.8epss 0.11
A remote code execution vulnerability exists when Microsoft Office improperly validates input before loading dynamic link library (DLL) files, aka 'Microsoft Office Remote Code Execution Vulnerability'.
- risk 0.51cvss 7.8epss 0.00
Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.
- risk 0.51cvss 7.8epss 0.00
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.00
Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.00
Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.00
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- risk 0.51cvss 7.8epss 0.00
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
Page 5 of 33