cbcvebase.

Microsoft Excel vulnerabilities

438 known vulnerabilities affecting microsoft/excel.

Total CVEs
438
CISA KEV
6
actively exploited
Public exploits
34
Exploited in wild
21
Severity breakdown
CRITICAL128HIGH250MEDIUM59LOW1

Vulnerabilities

Page 1 of 22
CVE-2009-3129P1HIGHCVSS 7.8KEVPoCv2002v2003+1 more2009-11-11
CVE-2009-3129 [HIGH] CWE-787 CVE-2009-3129: Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Office 2004 and 2008 for Mac; Open Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Excel Viewer 2003 SP3; Office Excel Viewer SP1 and SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allows remote attackers to execute arbitrary code via a spreadshee
nvd
CVE-2016-7262P1HIGHCVSS 7.8KEVv2007v2010+2 more2016-12-20
CVE-2016-7262 [HIGH] CVE-2016-7262: Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Office Comp Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Office Compatibility Pack SP3, and Excel Viewer allow user-assisted remote attackers to execute arbitrary commands via a crafted cell that is mishandled upon a click, aka "Microsoft Office Security Feature Bypass Vulnerability."
nvd
CVE-2009-0238P1HIGHCVSS 8.8KEVv2000v2002+2 more2009-02-25
CVE-2009-0238 [HIGH] CWE-94 CVE-2009-0238: Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1; Excel Viewer 2003 Gold and SP3; E Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1; Excel Viewer 2003 Gold and SP3; Excel Viewer; Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1; and Excel in Microsoft Office 2004 and 2008 for Mac allow remote attackers to execute arbitrary code via a crafted Excel document that triggers an access attempt on an i
nvd
CVE-2019-1297P1HIGHCVSS 8.8KEVv2010v2013+1 more2019-09-11
CVE-2019-1297 [HIGH] CVE-2019-1297: A remote code execution vulnerability exists in Microsoft Excel software when the software fails to A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'.
nvd
CVE-2021-42292P1HIGHCVSS 7.8KEVv20132021-11-10
CVE-2021-42292 [HIGH] CVE-2021-42292: Microsoft Excel Security Feature Bypass Vulnerability Microsoft Excel Security Feature Bypass Vulnerability
nvd
CVE-2007-0671P2HIGHCVSS 8.8KEVv2000v2002+1 more2007-02-03
CVE-2007-0671 [HIGH] CVE-2007-0671: Unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Of Unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, allows remote user-assisted attackers to execute arbitrary code via unknown attack vectors, as demonstrated by Exploit-MSExcel.h in targeted zero-day attacks.
nvd
CVE-2011-0105P2CRITICALCVSS 9.3ExploitedPoCv20022011-04-13
CVE-2011-0105 [CRITICAL] CWE-119 CVE-2011-0105: Microsoft Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac o Microsoft Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac obtain a certain length value from an uninitialized memory location, which allows remote attackers to trigger a buffer overflow and execute arbitrary code via a crafted Excel file, aka "Excel Data Initialization Vulnerability."
nvd
CVE-2008-0081P2CRITICALCVSS 9.8ExploitedPoCv2000v2002+1 more2008-01-16
CVE-2008-0081 [CRITICAL] CVE-2008-0081: Unspecified vulnerability in Microsoft Excel 2000 SP3 through 2003 SP2, Viewer 2003, and Office 2004 Unspecified vulnerability in Microsoft Excel 2000 SP3 through 2003 SP2, Viewer 2003, and Office 2004 for Mac allows user-assisted remote attackers to execute arbitrary code via crafted macros, aka "Macro Validation Vulnerability," a different vulnerability than CVE-2007-3490.
nvd
CVE-2025-47165P1HIGHCVSS 7.8ExploitedPoCv20162025-06-10
CVE-2025-47165 [HIGH] CWE-416 CVE-2025-47165: Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
nvd
CVE-2006-3059P2CRITICALCVSS 9.3ExploitedPoCv2000v2002+2 more2006-06-17
CVE-2006-3059 [CRITICAL] CVE-2006-3059: Unspecified vulnerability in Microsoft Excel 2000 through 2004 allows remote user-assisted attackers Unspecified vulnerability in Microsoft Excel 2000 through 2004 allows remote user-assisted attackers to execute arbitrary code via unspecified vectors. NOTE: this is a different vulnerability than CVE-2006-3086.
nvd
CVE-2020-0652P1HIGHCVSS 7.8ExploitedRansomwarev2010v2013+2 more2020-01-14
CVE-2020-0652 [HIGH] CWE-787 CVE-2020-0652: A remote code execution vulnerability exists in Microsoft Office software when the software fails to A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory, aka 'Microsoft Office Memory Corruption Vulnerability'.
nvd
CVE-2020-0651P1HIGHCVSS 7.8ExploitedRansomwarev2010v2013+2 more2020-01-14
CVE-2020-0651 [HIGH] CVE-2020-0651: A remote code execution vulnerability exists in Microsoft Excel software when the software fails to A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0650, CVE-2020-0653.
nvd
CVE-2020-0650P1HIGHCVSS 7.8ExploitedRansomwarev2010v2013+2 more2020-01-14
CVE-2020-0650 [HIGH] CVE-2020-0650: A remote code execution vulnerability exists in Microsoft Excel software when the software fails to A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0651, CVE-2020-0653.
nvd
CVE-2011-0097P2CRITICALCVSS 9.3Exploitedv2002v2003+2 more2011-04-13
CVE-2011-0097 [CRITICAL] CWE-189 CVE-2011-0097: Integer underflow in Microsoft Excel 2002 SP3, 2003 SP3, 2007 SP2, and 2010; Office 2004 and 2008 fo Integer underflow in Microsoft Excel 2002 SP3, 2003 SP3, 2007 SP2, and 2010; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Excel Viewer SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2 allows remote attackers to execute arbitrary code via a crafted 400h substream in an Excel file, which
nvd
CVE-2011-0101P2CRITICALCVSS 9.3Exploitedv20022011-04-13
CVE-2011-0101 [CRITICAL] CWE-119 CVE-2011-0101: Microsoft Excel 2002 SP3 allows remote attackers to execute arbitrary code or cause a denial of serv Microsoft Excel 2002 SP3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted RealTimeData record, related to a stTopic field, double-byte characters, and an incorrect pointer calculation, aka "Excel Record Parsing WriteAV Vulnerability."
nvd
CVE-2018-8627P2MEDIUMCVSS 5.5Exploitedv2010-sp2v2013-sp1+1 more2018-12-12
CVE-2018-8627 [MEDIUM] CVE-2018-8627: An information disclosure vulnerability exists when Microsoft Excel software reads out of bound memo An information disclosure vulnerability exists when Microsoft Excel software reads out of bound memory due to an uninitialized variable, which could disclose the contents of memory, aka "Microsoft Excel Information Disclosure Vulnerability." This affects Microsoft Office, Office 365 ProPlus, Microsoft Excel, Microsoft Excel Viewer, Excel. This CVE ID is uniqu
nvd
CVE-2017-11884P2HIGHCVSS 7.8Exploitedv20162017-11-15
CVE-2017-11884 [HIGH] CVE-2017-11884: Microsoft Excel 2016 Click-to-Run (C2R) allows an attacker to run arbitrary code in the context of t Microsoft Excel 2016 Click-to-Run (C2R) allows an attacker to run arbitrary code in the context of the current user by failing to properly handle objects in memory, aka "Microsoft Office Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-11882.
nvd
CVE-2018-8598P2MEDIUMCVSS 4.7Exploitedv2010-sp2v2013-sp1+2 more2018-12-12
CVE-2018-8598 [MEDIUM] CVE-2018-8598: An information disclosure vulnerability exists when Microsoft Excel improperly discloses the content An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka "Microsoft Excel Information Disclosure Vulnerability." This affects Office 365 ProPlus, Microsoft Office, Microsoft Excel. This CVE ID is unique from CVE-2018-8627.
nvd
CVE-2006-1301P2CRITICALCVSS 9.3Exploitedv2000v2002+3 more2006-07-13
CVE-2006-1301 [CRITICAL] CWE-94 CVE-2006-1301: Microsoft Excel 2000 through 2004 allows user-assisted attackers to execute arbitrary code via a .xl Microsoft Excel 2000 through 2004 allows user-assisted attackers to execute arbitrary code via a .xls file with a crafted SELECTION record that triggers memory corruption, a different vulnerability than CVE-2006-1302.
nvd
CVE-2018-0796P3HIGHCVSS 8.8Exploitedv2007v2010+2 more2018-01-10
CVE-2018-0796 [HIGH] CVE-2018-0796: Microsoft Excel in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsof Microsoft Excel in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Excel Remote Code Execution Vulnerability".
nvd
1 / 22Next →
Microsoft Excel vulnerabilities | cvebase