cbcvebase.

Microsoft Excel vulnerabilities

438 known vulnerabilities affecting microsoft/excel.

Total CVEs
438
CISA KEV
6
actively exploited
Public exploits
34
Exploited in wild
21
Severity breakdown
CRITICAL128HIGH250MEDIUM59LOW1

Vulnerabilities

Page 11 of 22
CVE-2018-8379P3HIGHCVSS 7.8v2010-sp2v2013-sp1+1 more2018-08-15
CVE-2018-8379 [HIGH] CVE-2018-8379: A remote code execution vulnerability exists in Microsoft Excel software when the software fails to A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "Microsoft Excel Remote Code Execution Vulnerability." This affects Microsoft Excel. This CVE ID is unique from CVE-2018-8375.
nvd
CVE-2011-1274P3CRITICALCVSS 9.3v2002v2003+1 more2011-06-16
CVE-2011-1274 [CRITICAL] CWE-119 CVE-2011-1274: Microsoft Excel 2002 SP3, 2003 SP3, and 2007 SP2; Office 2004 and 2008 for Mac; Open XML File Format Microsoft Excel 2002 SP3, 2003 SP3, and 2007 SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Excel Viewer SP2; and Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP2 do not properly validate record information during parsing of Excel spreadsheets, which allows remote attackers to execute arbitr
nvd
CVE-2017-8632P3HIGHCVSS 7.8v2010v2013+1 more2017-09-13
CVE-2017-8632 [HIGH] CVE-2017-8632: A remote code execution vulnerability exists in Microsoft Excel 2010 Service Pack 2, Microsoft Excel A remote code execution vulnerability exists in Microsoft Excel 2010 Service Pack 2, Microsoft Excel 2013 Service Pack 1, Microsoft Excel 2013 RT Service Pack 1, Microsoft Excel 2016, Microsoft Office Web Apps 2013, Microsoft Excel for Mac 2011, Microsoft Excel 2016 for Mac, and Microsoft Office Compatibility Pack Service Pack 3, when they fail to properly hand
nvd
CVE-2008-3068P3HIGHCVSS 7.5v2003v20072008-07-07
CVE-2008-3068 [HIGH] CVE-2008-3068: Microsoft Crypto API 5.131.2600.2180 through 6.0, as used in Outlook, Windows Live Mail, and Office Microsoft Crypto API 5.131.2600.2180 through 6.0, as used in Outlook, Windows Live Mail, and Office 2007, performs Certificate Revocation List (CRL) checks by using an arbitrary URL from a certificate embedded in a (1) S/MIME e-mail message or (2) signed document, which allows remote attackers to obtain reading times and IP addresses of recipients, and port-scan
nvd
CVE-2017-8631P3HIGHCVSS 7.8v2007v2010+2 more2017-09-13
CVE-2017-8631 [HIGH] CVE-2017-8631: A remote code execution vulnerability exists in Excel Services, Microsoft Excel 2007 Service Pack 3, A remote code execution vulnerability exists in Excel Services, Microsoft Excel 2007 Service Pack 3, Microsoft Excel 2010 Service Pack 2, Microsoft Excel 2013 Service Pack 1, Microsoft Excel 2013 RT Service Pack 1, Microsoft Excel 2016, Microsoft Office Web Apps 2013, Microsoft Office Compatibility Pack Service Pack 3, Microsoft Excel Web App 2013 Service Pack
nvd
CVE-2018-8375P3HIGHCVSS 7.8v2010-sp2v2013+2 more2018-08-15
CVE-2018-8375 [HIGH] CVE-2018-8375: A remote code execution vulnerability exists in Microsoft Excel software when the software fails to A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "Microsoft Excel Remote Code Execution Vulnerability." This affects Microsoft Excel Viewer, Microsoft Office, Microsoft Excel. This CVE ID is unique from CVE-2018-8379.
nvd
CVE-2018-8636P3HIGHCVSS 7.8v2010-sp2v2013-sp1+2 more2018-12-12
CVE-2018-8636 [HIGH] CVE-2018-8636: A remote code execution vulnerability exists in Microsoft Excel software when the software fails to A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "Microsoft Excel Remote Code Execution Vulnerability." This affects Office 365 ProPlus, Microsoft Office, Microsoft Excel. This CVE ID is unique from CVE-2018-8597.
nvd
CVE-2018-8597P3HIGHCVSS 7.8v2010-sp2v2013-sp1+1 more2018-12-12
CVE-2018-8597 [HIGH] CVE-2018-8597: A remote code execution vulnerability exists in Microsoft Excel software when the software fails to A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka "Microsoft Excel Remote Code Execution Vulnerability." This affects Office 365 ProPlus, Microsoft Office, Microsoft Excel. This CVE ID is unique from CVE-2018-8636.
nvd
CVE-2016-3381P3HIGHCVSS 7.8v2007v2010+2 more2016-09-14
CVE-2016-3381 [HIGH] CVE-2016-3381: Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Office Comp Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Office Compatibility Pack SP3, and Excel Viewer allow remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability," a different vulnerability than CVE-2016-3363.
nvd
CVE-2011-1277P3CRITICALCVSS 9.3v20022011-06-16
CVE-2011-1277 [CRITICAL] CWE-119 CVE-2011-1277: Microsoft Excel 2002 SP3, Office 2008 for Mac, and Open XML File Format Converter for Mac do not pro Microsoft Excel 2002 SP3, Office 2008 for Mac, and Open XML File Format Converter for Mac do not properly validate record information during parsing of Excel spreadsheets, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted spreadsheet, aka "Excel Memory Corruption Vulnerability."
nvd
CVE-2021-31179P3HIGHCVSS 7.8v2013v20162021-05-11
CVE-2021-31179 [HIGH] CVE-2021-31179: Microsoft Office Remote Code Execution Vulnerability Microsoft Office Remote Code Execution Vulnerability
nvd
CVE-2007-0215P3HIGHCVSS 7.6v2000v2002+2 more2007-05-08
CVE-2007-0215 [HIGH] CVE-2007-0215: Stack-based buffer overflow in Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, and 2003 Viewer allows Stack-based buffer overflow in Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, and 2003 Viewer allows user-assisted remote attackers to execute arbitrary code via a .XLS BIFF file with a malformed Named Graph record, which results in memory corruption.
nvd
CVE-2019-0828P3HIGHCVSS 7.8v2010v2013+2 more2019-04-09
CVE-2019-0828 [HIGH] CVE-2019-0828: A remote code execution vulnerability exists in Microsoft Excel software when the software fails to A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka 'Microsoft Excel Remote Code Execution Vulnerability'.
nvd
CVE-2026-44822P3HIGHCVSS 8.2v20162026-06-09
CVE-2026-44822 [HIGH] CWE-125 CVE-2026-44822: Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2025-62199P3HIGHCVSS 7.8v20162025-11-11
CVE-2025-62199 [HIGH] CWE-416 CVE-2025-62199: Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-62553P3HIGHCVSS 7.8v20162025-12-09
CVE-2025-62553 [HIGH] CWE-416 CVE-2025-62553: Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-62563P3HIGHCVSS 7.8v20162025-12-09
CVE-2025-62563 [HIGH] CWE-416 CVE-2025-62563: Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-21259P3HIGHCVSS 7.8v20162026-02-10
CVE-2026-21259 [HIGH] CWE-122 CVE-2026-21259: Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to elevate priv Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to elevate privileges locally.
nvd
CVE-2024-43504P3HIGHCVSS 7.8v20162024-10-08
CVE-2024-43504 [HIGH] CWE-416 CVE-2024-43504: Microsoft Excel Remote Code Execution Vulnerability Microsoft Excel Remote Code Execution Vulnerability
nvd
CVE-2025-21362P3HIGHCVSS 8.4v20162025-01-14
CVE-2025-21362 [HIGH] CWE-416 CVE-2025-21362: Microsoft Excel Remote Code Execution Vulnerability Microsoft Excel Remote Code Execution Vulnerability
nvd
Microsoft Excel vulnerabilities | cvebase