VYPR

365 Copilot

by Microsoft

CVEs (48)

  • CVE-2026-54130CriJun 18, 2026
    risk 0.64cvss 9.8epss 0.01

    Missing authentication for critical function in M365 Copilot allows an unauthorized attacker to disclose information over a network.

  • CVE-2025-60724CriNov 11, 2025
    risk 0.64cvss 9.8epss 0.06

    Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.

  • CVE-2025-53766CriAug 12, 2025
    risk 0.64cvss 9.8epss 0.07

    Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network.

  • CVE-2021-43905CriDec 15, 2021
    risk 0.63cvss 9.6epss 0.03

    Microsoft Office app Remote Code Execution Vulnerability

  • CVE-2026-24307CriJan 22, 2026
    risk 0.61cvss 9.3epss 0.01

    Improper validation of specified type of input in M365 Copilot allows an unauthorized attacker to disclose information over a network.

  • CVE-2025-32711CriJun 11, 2025
    risk 0.61cvss 9.3epss 0.08

    Ai command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-41090CriMay 22, 2026
    risk 0.60cvss 9.3epss 0.00

    Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform tampering over a network.

  • CVE-2026-33102CriApr 23, 2026
    risk 0.60cvss 9.3epss 0.00

    Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-47645HigJun 19, 2026
    risk 0.57cvss 8.8epss 0.01

    Url redirection to untrusted site ('open redirect') in Microsoft 365 Copilot's Business Chat allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-40363HigMay 12, 2026
    risk 0.55cvss 8.4epss 0.00

    Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

  • CVE-2026-26110HigMar 10, 2026
    risk 0.55cvss 8.4epss 0.00

    Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.

  • CVE-2025-62557HigDec 9, 2025
    risk 0.55cvss 8.4epss 0.00

    Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

  • CVE-2025-62554HigDec 9, 2025
    risk 0.55cvss 8.4epss 0.00

    Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.

  • CVE-2025-49697HigJul 8, 2025
    risk 0.55cvss 8.4epss 0.00

    Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

  • CVE-2025-49696HigJul 8, 2025
    risk 0.55cvss 8.4epss 0.01

    Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.

  • CVE-2025-49695HigJul 8, 2025
    risk 0.55cvss 8.4epss 0.01

    Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

  • CVE-2025-47953HigJun 10, 2025
    risk 0.55cvss 8.4epss 0.01

    Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

  • CVE-2025-47167HigJun 10, 2025
    risk 0.55cvss 8.4epss 0.01

    Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.

  • CVE-2025-47164HigJun 10, 2025
    risk 0.55cvss 8.4epss 0.01

    Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

  • CVE-2025-47162HigJun 10, 2025
    risk 0.55cvss 8.4epss 0.01

    Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.

Page 1 of 3