cbcvebase.

Microsoft Office 2019 vulnerabilities

696 known vulnerabilities affecting microsoft/microsoft_office_2019.

Total CVEs
696
CISA KEV
9
actively exploited
Public exploits
13
Exploited in wild
12
Severity breakdown
CRITICAL9HIGH522MEDIUM158LOW7

Vulnerabilities

Page 32 of 35
CVE-2026-81400P4MEDIUMCVSS 5.5≥ 19.0.0, < 16.0.10417.202072026-09-08
CVE-2026-81400 [MEDIUM] CWE-125 CVE-2026-81400: Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
nvd
CVE-2026-81391P4MEDIUMCVSS 5.5≥ 19.0.0, < 16.0.10417.202072026-09-08
CVE-2026-81391 [MEDIUM] CWE-908 CVE-2026-81391: Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
nvd
CVE-2026-85875P4MEDIUMCVSS 5.5≥ 19.0.0, < 16.0.10417.202072026-09-08
CVE-2026-85875 [MEDIUM] CWE-125 CVE-2026-85875: Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
nvd
CVE-2026-70318P4MEDIUMCVSS 5.5≥ 19.0.0, < https://aka.ms/OfficeSecurityReleases2026-08-11
CVE-2026-70318 [MEDIUM] CWE-20 CVE-2026-70318: Improper input validation in Microsoft Office Excel allows an unauthorized attacker to disclose info Improper input validation in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
nvd
CVE-2026-63531P4MEDIUMCVSS 5.5≥ 19.0.0, < https://aka.ms/OfficeSecurityReleases2026-08-11
CVE-2026-63531 [MEDIUM] CWE-125 CVE-2026-63531: Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
nvd
CVE-2026-64917P4MEDIUMCVSS 5.5≥ 19.0.0, < https://aka.ms/OfficeSecurityReleases2026-08-11
CVE-2026-64917 [MEDIUM] CWE-125 CVE-2026-64917: Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
nvd
CVE-2026-63528P4MEDIUMCVSS 5.5≥ 19.0.0, < https://aka.ms/OfficeSecurityReleases2026-08-11
CVE-2026-63528 [MEDIUM] CWE-125 CVE-2026-63528: Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
nvd
CVE-2026-68799P4MEDIUMCVSS 5.5≥ 19.0.0, < https://aka.ms/OfficeSecurityReleases2026-08-11
CVE-2026-68799 [MEDIUM] CWE-908 CVE-2026-68799: Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
nvd
CVE-2026-63521P4MEDIUMCVSS 5.5≥ 19.0.0, < https://aka.ms/OfficeSecurityReleases2026-08-11
CVE-2026-63521 [MEDIUM] CWE-125 CVE-2026-63521: Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
nvd
CVE-2026-70310P4MEDIUMCVSS 5.5≥ 19.0.0, < https://aka.ms/OfficeSecurityReleases2026-08-11
CVE-2026-70310 [MEDIUM] CWE-125 CVE-2026-70310: Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
nvd
CVE-2026-66809P4MEDIUMCVSS 5.5≥ 19.0.0, < https://aka.ms/OfficeSecurityReleases2026-08-11
CVE-2026-66809 [MEDIUM] CWE-125 CVE-2026-66809: Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information local Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
nvd
CVE-2020-1583P4MEDIUMCVSS 5.5≥ 19.0.0, < https://aka.ms/OfficeSecurityReleases2020-08-17
CVE-2020-1583 [MEDIUM] CVE-2020-1583: An information disclosure vulnerability exists when Microsoft Word improperly discloses the contents An information disclosure vulnerability exists when Microsoft Word improperly discloses the contents of its memory. An attacker who exploited the vulnerability could use the information to compromise the user’s computer or data. To exploit the vulnerability, an attacker could craft a special document file and then convince the user to open it. An attacker mus
nvd
CVE-2020-1497P4MEDIUMCVSS 5.5≥ 19.0.0, < https://aka.ms/OfficeSecurityReleases2020-08-17
CVE-2020-1497 [MEDIUM] CVE-2020-1497: An information disclosure vulnerability exists when Microsoft Excel improperly discloses the content An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory. An attacker who exploited the vulnerability could use the information to compromise the user’s computer or data. To exploit the vulnerability, an attacker could craft a special document file and then convince the user to open it. An attacker mu
nvd
CVE-2020-1502P4MEDIUMCVSS 5.5≥ 19.0.0, < https://aka.ms/OfficeSecurityReleases2020-08-17
CVE-2020-1502 [MEDIUM] CVE-2020-1502: An information disclosure vulnerability exists when Microsoft Word improperly discloses the contents An information disclosure vulnerability exists when Microsoft Word improperly discloses the contents of its memory. An attacker who exploited the vulnerability could use the information to compromise the user’s computer or data. To exploit the vulnerability, an attacker could craft a special document file and then convince the user to open it. An attacker mus
nvd
CVE-2020-1503P4MEDIUMCVSS 5.5≥ 19.0.0, < https://aka.ms/OfficeSecurityReleases2020-08-17
CVE-2020-1503 [MEDIUM] CVE-2020-1503: An information disclosure vulnerability exists when Microsoft Word improperly discloses the contents An information disclosure vulnerability exists when Microsoft Word improperly discloses the contents of its memory. An attacker who exploited the vulnerability could use the information to compromise the user’s computer or data. To exploit the vulnerability, an attacker could craft a special document file and then convince the user to open it. An attacker mus
nvd
CVE-2020-1224P4MEDIUMCVSS 5.5≥ 19.0.0, < https://aka.ms/OfficeSecurityReleases2020-09-11
CVE-2020-1224 [MEDIUM] CVE-2020-1224: <p>An information disclosure vulnerability exists when Microsoft Excel improperly discloses the cont An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory. An attacker who exploited the vulnerability could use the information to compromise the user’s computer or data. To exploit the vulnerability, an attacker could craft a special document file and then convince the user to open it. An attacker mu
nvd
CVE-2022-24462P4MEDIUMCVSS 5.5≥ 19.0.0, < https://aka.ms/OfficeSecurityReleases2022-03-09
CVE-2022-24462 [MEDIUM] CVE-2022-24462: Microsoft Word Security Feature Bypass Vulnerability Microsoft Word Security Feature Bypass Vulnerability
nvd
CVE-2025-54901P4MEDIUMCVSS 5.5≥ 19.0.0, < https://aka.ms/OfficeSecurityReleases2025-09-09
CVE-2025-54901 [MEDIUM] CWE-126 CVE-2025-54901: Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to disclose information l Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
nvd
CVE-2026-62842P4MEDIUMCVSS 5.5≥ 19.0.0, < https://aka.ms/OfficeSecurityReleases2026-08-11
CVE-2026-62842 [MEDIUM] CWE-125 CVE-2026-62842: Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information local Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
nvd
CVE-2026-63517P4MEDIUMCVSS 5.5≥ 19.0.0, < https://aka.ms/OfficeSecurityReleases2026-08-11
CVE-2026-63517 [MEDIUM] CWE-125 CVE-2026-63517: Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information local Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
nvd
Microsoft Office 2019 vulnerabilities | cvebase