Microsoft Excel vulnerabilities
438 known vulnerabilities affecting microsoft/excel.
Total CVEs
438
CISA KEV
6
actively exploited
Public exploits
34
Exploited in wild
21
Severity breakdown
CRITICAL128HIGH250MEDIUM59LOW1
Vulnerabilities
Page 19 of 22
CVE-2024-20673P3HIGHCVSS 7.8v20162024-02-13
CVE-2024-20673 [HIGH] CWE-693 CVE-2024-20673: Microsoft Office Remote Code Execution Vulnerability
Microsoft Office Remote Code Execution Vulnerability
nvd
CVE-2006-1308P3CRITICALCVSS 9.3v2000v2002+3 more2006-07-13
CVE-2006-1308 [CRITICAL] CWE-94 CVE-2006-1308: Unspecified vulnerability in Microsoft Excel 2000 through 2004 allows user-assisted attackers to exe
Unspecified vulnerability in Microsoft Excel 2000 through 2004 allows user-assisted attackers to execute arbitrary code via a .xls file with a crafted FNGROUPCOUNT value.
nvd
CVE-2022-41063P3HIGHCVSS 7.8v2013v20162022-11-09
CVE-2022-41063 [HIGH] CVE-2022-41063: Microsoft Excel Remote Code Execution Vulnerability
Microsoft Excel Remote Code Execution Vulnerability
nvd
CVE-2023-24953P3HIGHCVSS 7.8v2013v20162023-05-09
CVE-2023-24953 [HIGH] CWE-416 CVE-2023-24953: Microsoft Excel Remote Code Execution Vulnerability
Microsoft Excel Remote Code Execution Vulnerability
nvd
CVE-2025-30381P3HIGHCVSS 7.8v20162025-05-13
CVE-2025-30381 [HIGH] CWE-125 CVE-2025-30381: Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
nvd
CVE-2018-0907P3HIGHCVSS 7.8v2007v2013+1 more2018-03-14
CVE-2018-0907 [HIGH] CVE-2018-0907: Microsoft Excel 2007 SP3, Microsoft Excel 2010 SP2, Microsoft Excel 2013 SP1, Microsoft Excel 2016,
Microsoft Excel 2007 SP3, Microsoft Excel 2010 SP2, Microsoft Excel 2013 SP1, Microsoft Excel 2016, Microsoft Office 2016 Click-to-Run and Microsoft Office 2016 for Mac allow a security feature bypass vulnerability due to how macro settings are enforced, aka "Microsoft Office Excel Security Feature Bypass".
nvd
CVE-2023-36037P3HIGHCVSS 7.8v20162023-11-14
CVE-2023-36037 [HIGH] CVE-2023-36037: Microsoft Excel Security Feature Bypass Vulnerability
Microsoft Excel Security Feature Bypass Vulnerability
nvd
CVE-2025-30379P3HIGHCVSS 7.8v20162025-05-13
CVE-2025-30379 [HIGH] CWE-763 CVE-2025-30379: Release of invalid pointer or reference in Microsoft Office Excel allows an unauthorized attacker to
Release of invalid pointer or reference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
nvd
CVE-2024-43465P3HIGHCVSS 7.8v20162024-09-10
CVE-2024-43465 [HIGH] CWE-416 CVE-2024-43465: Microsoft Excel Elevation of Privilege Vulnerability
Microsoft Excel Elevation of Privilege Vulnerability
nvd
CVE-2017-0194P3MEDIUMCVSS 5.5v2007v20102017-04-12
CVE-2017-0194 [MEDIUM] CWE-200 CVE-2017-0194: Microsoft Excel 2007 SP3, Microsoft Excel 2010 SP2, and Office Compatibility Pack SP2 allow remote a
Microsoft Excel 2007 SP3, Microsoft Excel 2010 SP2, and Office Compatibility Pack SP2 allow remote attackers to obtain sensitive information from process memory via a crafted Office document, aka "Microsoft Office Information Disclosure Vulnerability."
nvd
CVE-2006-1309P3CRITICALCVSS 9.3v2000v2002+3 more2006-07-13
CVE-2006-1309 [CRITICAL] CWE-94 CVE-2006-1309: Microsoft Excel 2000 through 2004 allows user-assisted attackers to execute arbitrary code via a .xl
Microsoft Excel 2000 through 2004 allows user-assisted attackers to execute arbitrary code via a .xls file with a crafted LABEL record that triggers memory corruption.
nvd
CVE-2006-0028P3MEDIUMCVSS 5.1v2000v2002+3 more2006-03-14
CVE-2006-0028 [MEDIUM] CVE-2006-0028: Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and
Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via a BIFF parsing format file containing malformed BOOLERR records that lead to memory corruption, probably involving invalid pointers.
nvd
CVE-2026-55054P3MEDIUMCVSS 6.5v20162026-07-14
CVE-2026-55054 [MEDIUM] CWE-125 CVE-2026-55054: Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2000-0419P4HIGHCVSS 7.5v20002000-05-11
CVE-2000-0419 [HIGH] CVE-2000-0419: The Office 2000 UA ActiveX Control is marked as "safe for scripting," which allows remote attackers
The Office 2000 UA ActiveX Control is marked as "safe for scripting," which allows remote attackers to conduct unauthorized activities via the "Show Me" function in Office Help, aka the "Office 2000 UA Control" vulnerability.
nvd
CVE-2022-33631P3HIGHCVSS 7.3v2013v20162022-08-09
CVE-2022-33631 [HIGH] CWE-693 CVE-2022-33631: Microsoft Excel Security Feature Bypass Vulnerability
Microsoft Excel Security Feature Bypass Vulnerability
nvd
CVE-2001-0718P4HIGHCVSS 7.5≤ 20022001-10-30
CVE-2001-0718 [HIGH] CVE-2001-0718: Vulnerability in (1) Microsoft Excel 2002 and earlier and (2) Microsoft PowerPoint 2002 and earlier
Vulnerability in (1) Microsoft Excel 2002 and earlier and (2) Microsoft PowerPoint 2002 and earlier allows attackers to bypass macro restrictions and execute arbitrary commands by modifying the data stream in the document.
nvd
CVE-2026-44818P3HIGHCVSS 7.0v20162026-06-09
CVE-2026-44818 [HIGH] CWE-362 CVE-2026-44818: Concurrent execution using shared resource with improper synchronization ('race condition') in Micro
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
nvd
CVE-2013-3159P3MEDIUMCVSS 4.3v2003v2007+1 more2013-09-11
CVE-2013-3159 [MEDIUM] CWE-20 CVE-2013-3159: Microsoft Excel 2003 SP3, 2007 SP3, and 2010 SP1 and SP2; Excel Viewer; and Microsoft Office Compati
Microsoft Excel 2003 SP3, 2007 SP3, and 2010 SP1 and SP2; Excel Viewer; and Microsoft Office Compatibility Pack SP3 allow remote attackers to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, aka "XML External Entities Resolution Vul
nvd
CVE-2015-2423P4MEDIUMCVSS 4.3v2007v2010+1 more2015-08-15
CVE-2015-2423 [MEDIUM] CWE-200 CVE-2015-2423: Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, Windows 10, Excel 2007 SP3, PowerPoint 2007 SP3, Visio 2007 SP3, Word 2007 SP3, Office 2010 SP2, Excel 2010 SP2, PowerPoint 2010 SP2, Visio 2010 SP2, Word 2010 SP2, Excel 2013 SP1, PowerPoint
nvd
CVE-2006-0029P3MEDIUMCVSS 5.1v2000v2002+3 more2006-03-14
CVE-2006-0029 [MEDIUM] CVE-2006-0029: Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and
Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via an Excel file with a malformed description, which leads to memory corruption.
nvd