cbcvebase.

Microsoft Office 2019 vulnerabilities

501 known vulnerabilities affecting microsoft/microsoft_office_2019.

Total CVEs
501
CISA KEV
9
actively exploited
Public exploits
13
Exploited in wild
12
Severity breakdown
CRITICAL6HIGH408MEDIUM80LOW7

Vulnerabilities

Page 23 of 26
CVE-2026-55142P4MEDIUMCVSS 5.5≥ 19.0.0, < https://aka.ms/OfficeSecurityReleases2026-07-14
CVE-2026-55142 [MEDIUM] CWE-197 CVE-2026-55142: Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to disclose inform Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
nvd
CVE-2026-55050P4MEDIUMCVSS 5.5≥ 19.0.0, < https://aka.ms/OfficeSecurityReleases2026-07-14
CVE-2026-55050 [MEDIUM] CWE-125 CVE-2026-55050: Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
nvd
CVE-2026-50408P4MEDIUMCVSS 5.5≥ 19.0.0, < https://aka.ms/OfficeSecurityReleases2026-07-14
CVE-2026-50408 [MEDIUM] CWE-125 CVE-2026-50408: Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
nvd
CVE-2020-1583P4MEDIUMCVSS 5.5≥ 19.0.0, < https://aka.ms/OfficeSecurityReleases2020-08-17
CVE-2020-1583 [MEDIUM] CVE-2020-1583: An information disclosure vulnerability exists when Microsoft Word improperly discloses the contents An information disclosure vulnerability exists when Microsoft Word improperly discloses the contents of its memory. An attacker who exploited the vulnerability could use the information to compromise the user’s computer or data. To exploit the vulnerability, an attacker could craft a special document file and then convince the user to open it. An attacker mus
nvd
CVE-2020-1497P4MEDIUMCVSS 5.5≥ 19.0.0, < https://aka.ms/OfficeSecurityReleases2020-08-17
CVE-2020-1497 [MEDIUM] CVE-2020-1497: An information disclosure vulnerability exists when Microsoft Excel improperly discloses the content An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory. An attacker who exploited the vulnerability could use the information to compromise the user’s computer or data. To exploit the vulnerability, an attacker could craft a special document file and then convince the user to open it. An attacker mu
nvd
CVE-2020-1502P4MEDIUMCVSS 5.5≥ 19.0.0, < https://aka.ms/OfficeSecurityReleases2020-08-17
CVE-2020-1502 [MEDIUM] CVE-2020-1502: An information disclosure vulnerability exists when Microsoft Word improperly discloses the contents An information disclosure vulnerability exists when Microsoft Word improperly discloses the contents of its memory. An attacker who exploited the vulnerability could use the information to compromise the user’s computer or data. To exploit the vulnerability, an attacker could craft a special document file and then convince the user to open it. An attacker mus
nvd
CVE-2020-1503P4MEDIUMCVSS 5.5≥ 19.0.0, < https://aka.ms/OfficeSecurityReleases2020-08-17
CVE-2020-1503 [MEDIUM] CVE-2020-1503: An information disclosure vulnerability exists when Microsoft Word improperly discloses the contents An information disclosure vulnerability exists when Microsoft Word improperly discloses the contents of its memory. An attacker who exploited the vulnerability could use the information to compromise the user’s computer or data. To exploit the vulnerability, an attacker could craft a special document file and then convince the user to open it. An attacker mus
nvd
CVE-2020-1224P4MEDIUMCVSS 5.5≥ 19.0.0, < https://aka.ms/OfficeSecurityReleases2020-09-11
CVE-2020-1224 [MEDIUM] CVE-2020-1224: <p>An information disclosure vulnerability exists when Microsoft Excel improperly discloses the cont An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory. An attacker who exploited the vulnerability could use the information to compromise the user’s computer or data. To exploit the vulnerability, an attacker could craft a special document file and then convince the user to open it. An attacker mu
nvd
CVE-2026-54988P4MEDIUMCVSS 6.1≥ 19.0.0, < https://aka.ms/OfficeSecurityReleases2026-07-14
CVE-2026-54988 [MEDIUM] CWE-125 CVE-2026-54988: Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
nvd
CVE-2026-48580P4MEDIUMCVSS 5.5≥ 19.0.0, < https://aka.ms/OfficeSecurityReleases2026-07-14
CVE-2026-48580 [MEDIUM] CWE-822 CVE-2026-48580: Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
nvd
CVE-2026-44821P4MEDIUMCVSS 5.5≥ 19.0.0, < https://aka.ms/OfficeSecurityReleases2026-06-09
CVE-2026-44821 [MEDIUM] CWE-125 CVE-2026-44821: Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information local Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
nvd
CVE-2026-55138P4MEDIUMCVSS 5.5≥ 19.0.0, < https://aka.ms/OfficeSecurityReleases2026-07-14
CVE-2026-55138 [MEDIUM] CWE-822 CVE-2026-55138: Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
nvd
CVE-2022-22716P4MEDIUMCVSS 5.5≥ 19.0.0, < https://aka.ms/OfficeSecurityReleases2022-02-09
CVE-2022-22716 [MEDIUM] CWE-119 CVE-2022-22716: Microsoft Excel Information Disclosure Vulnerability Microsoft Excel Information Disclosure Vulnerability
nvd
CVE-2021-28456P4MEDIUMCVSS 5.5≥ 19.0.0, < https://aka.ms/OfficeSecurityReleases2021-04-13
CVE-2021-28456 [MEDIUM] CVE-2021-28456: Microsoft Excel Information Disclosure Vulnerability Microsoft Excel Information Disclosure Vulnerability
nvd
CVE-2021-31174P4MEDIUMCVSS 5.5≥ 19.0.0, < https://aka.ms/OfficeSecurityReleases2021-05-11
CVE-2021-31174 [MEDIUM] CWE-125 CVE-2021-31174: Microsoft Excel Information Disclosure Vulnerability Microsoft Excel Information Disclosure Vulnerability
nvd
CVE-2022-24462P4MEDIUMCVSS 5.5≥ 19.0.0, < https://aka.ms/OfficeSecurityReleases2022-03-09
CVE-2022-24462 [MEDIUM] CVE-2022-24462: Microsoft Word Security Feature Bypass Vulnerability Microsoft Word Security Feature Bypass Vulnerability
nvd
CVE-2020-17020P4MEDIUMCVSS 5.5≥ 19.0.0, < https://aka.ms/OfficeSecurityReleases2020-11-11
CVE-2020-17020 [MEDIUM] CVE-2020-17020: Microsoft Word Security Feature Bypass Vulnerability Microsoft Word Security Feature Bypass Vulnerability
nvd
CVE-2025-48812P4MEDIUMCVSS 5.5≥ 19.0.0, < https://aka.ms/OfficeSecurityReleases2025-07-08
CVE-2025-48812 [MEDIUM] CWE-125 CVE-2025-48812: Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
nvd
CVE-2024-38200MEDIUMCVSS 6.5PoC≥ 19.0.0, < https://aka.ms/OfficeSecurityReleases2024-08-08
CVE-2024-38200 [MEDIUM] CWE-200 Microsoft Office Spoofing Vulnerability Microsoft Office Spoofing Vulnerability Microsoft Office Spoofing Vulnerability
cvelistv5
CVE-2019-1204P4MEDIUMCVSS 4.3≥ 19.0.0, < https://aka.ms/OfficeSecurityReleases2019-08-14
CVE-2019-1204 [MEDIUM] CWE-20 CVE-2019-1204: An elevation of privilege vulnerability exists when Microsoft Outlook initiates processing of incomi An elevation of privilege vulnerability exists when Microsoft Outlook initiates processing of incoming messages without sufficient validation of the formatting of the messages. An attacker who successfully exploited the vulnerability could attempt to force Outlook to load a local or remote message store (over SMB). To exploit the vulnerability, the att
nvd
Microsoft Office 2019 vulnerabilities | cvebase