Microsoft Excel vulnerabilities
438 known vulnerabilities affecting microsoft/excel.
Total CVEs
438
CISA KEV
6
actively exploited
Public exploits
34
Exploited in wild
21
Severity breakdown
CRITICAL128HIGH250MEDIUM59LOW1
Vulnerabilities
Page 22 of 22
CVE-2022-22716P4MEDIUMCVSS 5.5v2013v20162022-02-09
CVE-2022-22716 [MEDIUM] CWE-119 CVE-2022-22716: Microsoft Excel Information Disclosure Vulnerability
Microsoft Excel Information Disclosure Vulnerability
nvd
CVE-2021-28456P4MEDIUMCVSS 5.5v2010v2013+1 more2021-04-13
CVE-2021-28456 [MEDIUM] CVE-2021-28456: Microsoft Excel Information Disclosure Vulnerability
Microsoft Excel Information Disclosure Vulnerability
nvd
CVE-2021-31174P4MEDIUMCVSS 5.5v2013v20162021-05-11
CVE-2021-31174 [MEDIUM] CWE-125 CVE-2021-31174: Microsoft Excel Information Disclosure Vulnerability
Microsoft Excel Information Disclosure Vulnerability
nvd
CVE-2025-48812P4MEDIUMCVSS 5.5v20162025-07-08
CVE-2025-48812 [MEDIUM] CWE-125 CVE-2025-48812: Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
nvd
CVE-2002-0617P4MEDIUMCVSS 5.1v2000v20022002-08-12
CVE-2002-0617 [MEDIUM] CVE-2002-0617: The Macro Security Model in Microsoft Excel 2000 and 2002 for Windows allows remote attackers to exe
The Macro Security Model in Microsoft Excel 2000 and 2002 for Windows allows remote attackers to execute code by creating a hyperlink on a drawing shape in a source workbook that points to a destination workbook containing an autoexecute macro, aka "Hyperlinked Excel Workbook Macro Bypass."
nvd
CVE-2022-41104P4MEDIUMCVSS 5.5v2013v20162022-11-09
CVE-2022-41104 [MEDIUM] CVE-2022-41104: Microsoft Excel Security Feature Bypass Vulnerability
Microsoft Excel Security Feature Bypass Vulnerability
nvd
CVE-2002-0615P4HIGHCVSS 7.5v2000v20022002-07-03
CVE-2002-0615 [HIGH] CVE-2002-0615: The Windows Media Active Playlist in Microsoft Windows Media Player 7.1 stores information in a well
The Windows Media Active Playlist in Microsoft Windows Media Player 7.1 stores information in a well known location on the local file system, allowing attackers to execute HTML scripts in the Local Computer zone, aka "Media Playback Script Invocation".
nvd
CVE-2026-45455P4MEDIUMCVSS 4.3v20162026-06-09
CVE-2026-45455 [MEDIUM] CWE-125 CVE-2026-45455: Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
nvd
CVE-2002-0616P4MEDIUMCVSS 5.1v2000v20022002-08-12
CVE-2002-0616 [MEDIUM] CVE-2002-0616: The Macro Security Model in Microsoft Excel 2000 and 2002 for Windows allows remote attackers to exe
The Macro Security Model in Microsoft Excel 2000 and 2002 for Windows allows remote attackers to execute code by attaching an inline macro to an object within an Excel workbook, aka the "Excel Inline Macros Vulnerability."
nvd
CVE-2023-36766P4MEDIUMCVSS 5.5v2013v20162023-09-12
CVE-2023-36766 [MEDIUM] CWE-125 CVE-2023-36766: Microsoft Excel Information Disclosure Vulnerability
Microsoft Excel Information Disclosure Vulnerability
nvd
CVE-2020-17126P4MEDIUMCVSS 5.5v2010v2013+1 more2020-12-10
CVE-2020-17126 [MEDIUM] CVE-2020-17126: Microsoft Excel Information Disclosure Vulnerability
Microsoft Excel Information Disclosure Vulnerability
nvd
CVE-2025-21383P4MEDIUMCVSS 5.5v20162025-02-11
CVE-2025-21383 [MEDIUM] CWE-125 CVE-2025-21383: Microsoft Excel Information Disclosure Vulnerability
Microsoft Excel Information Disclosure Vulnerability
nvd
CVE-2021-40472P4MEDIUMCVSS 5.5v20162021-10-13
CVE-2021-40472 [MEDIUM] CVE-2021-40472: Microsoft Excel Information Disclosure Vulnerability
Microsoft Excel Information Disclosure Vulnerability
nvd
CVE-2000-0765P4MEDIUMCVSS 5.1v20002000-10-20
CVE-2000-0765 [MEDIUM] CVE-2000-0765: Buffer overflow in the HTML interpreter in Microsoft Office 2000 allows an attacker to execute arbit
Buffer overflow in the HTML interpreter in Microsoft Office 2000 allows an attacker to execute arbitrary commands via a long embedded object tag, aka the "Microsoft Office HTML Object Tag" vulnerability.
nvd
CVE-2000-0637P4MEDIUMCVSS 4.6v97v20002000-07-26
CVE-2000-0637 [MEDIUM] CVE-2000-0637: Microsoft Excel 97 and 2000 allows an attacker to execute arbitrary commands by specifying a malicio
Microsoft Excel 97 and 2000 allows an attacker to execute arbitrary commands by specifying a malicious .dll using the Register.ID function, aka the "Excel REGISTER.ID Function" vulnerability.
nvd
CVE-2007-1239P4MEDIUMCVSS 4.3v20032007-03-03
CVE-2007-1239 [MEDIUM] CVE-2007-1239: Microsoft Excel 2003 does not properly parse .XLS files, which allows remote attackers to cause a de
Microsoft Excel 2003 does not properly parse .XLS files, which allows remote attackers to cause a denial of service (application crash) via a file with a (1) corrupted XML format or a (2) corrupted XLS format, which triggers a NULL pointer dereference.
nvd
CVE-2026-50678P4LOWCVSS 3.3v20162026-07-14
CVE-2026-50678 [LOW] CWE-122 CVE-2026-50678: Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to disclose inf
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
nvd
CVE-2000-0277P4HIGHCVSS 7.2v97v20002000-04-03
CVE-2000-0277 [HIGH] CWE-254 CVE-2000-0277: Microsoft Excel 97 and 2000 does not warn the user when executing Excel Macro Language (XLM) macros
Microsoft Excel 97 and 2000 does not warn the user when executing Excel Macro Language (XLM) macros in external text files, which could allow an attacker to execute a macro virus, aka the "XLM Text Macro" vulnerability.
nvd
← Previous22 / 22