cbcvebase.

Microsoft Excel vulnerabilities

438 known vulnerabilities affecting microsoft/excel.

Total CVEs
438
CISA KEV
6
actively exploited
Public exploits
34
Exploited in wild
21
Severity breakdown
CRITICAL128HIGH250MEDIUM59LOW1

Vulnerabilities

Page 21 of 22
CVE-2020-17130P4MEDIUMCVSS 6.5v20162020-12-10
CVE-2020-17130 [MEDIUM] CVE-2020-17130: Microsoft Excel Security Feature Bypass Vulnerability Microsoft Excel Security Feature Bypass Vulnerability
nvd
CVE-2000-0597P4HIGHCVSS 7.5v20002000-06-27
CVE-2000-0597 [HIGH] CVE-2000-0597: Microsoft Office 2000 (Excel and PowerPoint) and PowerPoint 97 are marked as safe for scripting, whi Microsoft Office 2000 (Excel and PowerPoint) and PowerPoint 97 are marked as safe for scripting, which allows remote attackers to force Internet Explorer or some email clients to save files to arbitrary locations via the Visual Basic for Applications (VBA) SaveAs function, aka the "Office HTML Script" vulnerability.
nvd
CVE-2015-2375P4MEDIUMCVSS 4.3v2010v20132015-07-14
CVE-2015-2375 [MEDIUM] CWE-200 CVE-2015-2375: Microsoft Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel Viewer 2007 SP3, Excel Services o Microsoft Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel Viewer 2007 SP3, Excel Services on SharePoint Server 2010 SP2, and Excel Services on SharePoint Server 2013 SP1 allow remote attackers to bypass the ASLR protection mechanism via a crafted spreadsheet, aka "Microsoft Excel ASLR Bypass Vulnerability."
nvd
CVE-2019-1446P4MEDIUMCVSS 5.5v2010v2013+1 more2019-11-12
CVE-2019-1446 [MEDIUM] CWE-200 CVE-2019-1446: An information disclosure vulnerability exists when Microsoft Excel improperly discloses the content An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka 'Microsoft Excel Information Disclosure Vulnerability'.
nvd
CVE-2016-0012P4MEDIUMCVSS 4.3v2007v2010+2 more2016-01-13
CVE-2016-0012 [MEDIUM] CWE-200 CVE-2016-0012: Microsoft Office 2007 SP3, Excel 2007 SP3, PowerPoint 2007 SP3, Visio 2007 SP3, Word 2007 SP3, Offic Microsoft Office 2007 SP3, Excel 2007 SP3, PowerPoint 2007 SP3, Visio 2007 SP3, Word 2007 SP3, Office 2010 SP2, Excel 2010 SP2, PowerPoint 2010 SP2, Visio 2010 SP2, Word 2010 SP2, Office 2013 SP1, Excel 2013 SP1, PowerPoint 2013 SP1, Visio 2013 SP1, Word 2013 SP1, Excel 2013 RT SP1, PowerPoint 2013 RT SP1, Word 2013 RT SP1, Office 2016, Excel 2016, Po
nvd
CVE-2019-1464P4MEDIUMCVSS 5.5v2010v2013+1 more2019-12-10
CVE-2019-1464 [MEDIUM] CWE-200 CVE-2019-1464: An information disclosure vulnerability exists when Microsoft Excel improperly discloses the content An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka 'Microsoft Excel Information Disclosure Vulnerability'.
nvd
CVE-2019-1263P4MEDIUMCVSS 5.5v2010v2013+2 more2019-09-11
CVE-2019-1263 [MEDIUM] CWE-200 CVE-2019-1263: An information disclosure vulnerability exists when Microsoft Excel improperly discloses the content An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka 'Microsoft Excel Information Disclosure Vulnerability'.
nvd
CVE-2026-21258P4MEDIUMCVSS 5.5v20162026-02-10
CVE-2026-21258 [MEDIUM] CWE-20 CVE-2026-21258: Improper input validation in Microsoft Office Excel allows an unauthorized attacker to disclose info Improper input validation in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
nvd
CVE-2026-21261P4MEDIUMCVSS 5.5v20162026-02-10
CVE-2026-21261 [MEDIUM] CWE-125 CVE-2026-21261: Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
nvd
CVE-2025-59240P4MEDIUMCVSS 5.5v20162025-11-11
CVE-2025-59240 [MEDIUM] CWE-200 CVE-2025-59240: Exposure of sensitive information to an unauthorized actor in Microsoft Office Excel allows an unaut Exposure of sensitive information to an unauthorized actor in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
nvd
CVE-2026-42832P4MEDIUMCVSS 5.5fixed in 16.0.19822.201902026-05-12
CVE-2026-42832 [MEDIUM] CWE-284 CVE-2026-42832: Improper access control in Microsoft Office allows an unauthorized attacker to perform spoofing loca Improper access control in Microsoft Office allows an unauthorized attacker to perform spoofing locally.
nvd
CVE-2017-11877P4MEDIUMCVSS 5.5v2007v2010+2 more2017-11-15
CVE-2017-11877 [MEDIUM] CVE-2017-11877: Microsoft Excel 2007 Service Pack 3, Microsoft Excel 2010 Service Pack 2, Microsoft Excel 2013 Servi Microsoft Excel 2007 Service Pack 3, Microsoft Excel 2010 Service Pack 2, Microsoft Excel 2013 Service Pack 1, Microsoft Excel 2013 RT Service Pack 1, Microsoft Excel 2016, Microsoft Office Compatibility Pack Service Pack 3, Microsoft Excel Viewer 2007 Service Pack 3, and Microsoft Excel 2016 for Mac allow a security feature bypass by not enforcing macro se
nvd
CVE-2025-54901P4MEDIUMCVSS 5.5v20162025-09-09
CVE-2025-54901 [MEDIUM] CWE-126 CVE-2025-54901: Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to disclose information l Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
nvd
CVE-2026-55046P4MEDIUMCVSS 5.5v20162026-07-14
CVE-2026-55046 [MEDIUM] CWE-125 CVE-2026-55046: Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
nvd
CVE-2026-50408P4MEDIUMCVSS 5.5v20162026-07-14
CVE-2026-50408 [MEDIUM] CWE-125 CVE-2026-50408: Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
nvd
CVE-2020-1497P4MEDIUMCVSS 5.5v2010v2013+1 more2020-08-17
CVE-2020-1497 [MEDIUM] CVE-2020-1497: An information disclosure vulnerability exists when Microsoft Excel improperly discloses the content An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory. An attacker who exploited the vulnerability could use the information to compromise the user’s computer or data. To exploit the vulnerability, an attacker could craft a special document file and then convince the user to open it. An attacker mu
nvd
CVE-2020-1224P4MEDIUMCVSS 5.5v2010v2013+1 more2020-09-11
CVE-2020-1224 [MEDIUM] CVE-2020-1224: <p>An information disclosure vulnerability exists when Microsoft Excel improperly discloses the cont An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory. An attacker who exploited the vulnerability could use the information to compromise the user’s computer or data. To exploit the vulnerability, an attacker could craft a special document file and then convince the user to open it. An attacker mu
nvd
CVE-2026-54988P4MEDIUMCVSS 6.1v20162026-07-14
CVE-2026-54988 [MEDIUM] CWE-125 CVE-2026-54988: Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
nvd
CVE-2026-48580P4MEDIUMCVSS 5.5v20162026-07-14
CVE-2026-48580 [MEDIUM] CWE-822 CVE-2026-48580: Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
nvd
CVE-2026-55138P4MEDIUMCVSS 5.5v20162026-07-14
CVE-2026-55138 [MEDIUM] CWE-822 CVE-2026-55138: Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
nvd
Microsoft Excel vulnerabilities | cvebase