cbcvebase.

Microsoft Office vulnerabilities

1,005 known vulnerabilities affecting microsoft/office.

Total CVEs
1,005
CISA KEV
35
actively exploited
Public exploits
103
Exploited in wild
68
Severity breakdown
CRITICAL277HIGH567MEDIUM155LOW6

Vulnerabilities

Page 30 of 51
CVE-2025-54904P3HIGHCVSS 7.8v20192025-09-09
CVE-2025-54904 [HIGH] CWE-416 CVE-2025-54904: Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-54896P3HIGHCVSS 7.8v20192025-09-09
CVE-2025-54896 [HIGH] CWE-416 CVE-2025-54896: Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-54903P3HIGHCVSS 7.8v20192025-09-09
CVE-2025-54903 [HIGH] CWE-416 CVE-2025-54903: Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-54900P3HIGHCVSS 7.8v20192025-09-09
CVE-2025-54900 [HIGH] CWE-122 CVE-2025-54900: Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-53761P3HIGHCVSS 7.8v20192025-08-12
CVE-2025-53761 [HIGH] CWE-416 CVE-2025-53761: Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locall Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-53732P3HIGHCVSS 7.8fixed in 16.0.14326.226182025-08-12
CVE-2025-53732 [HIGH] CWE-122 CVE-2025-53732: Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code local Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-54907P3HIGHCVSS 7.8v20192025-09-09
CVE-2025-54907 [HIGH] CWE-122 CVE-2025-54907: Heap-based buffer overflow in Microsoft Office Visio allows an unauthorized attacker to execute code Heap-based buffer overflow in Microsoft Office Visio allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-59225P3HIGHCVSS 7.8v20192025-10-14
CVE-2025-59225 [HIGH] CWE-416 CVE-2025-59225: Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-59224P3HIGHCVSS 7.8v20192025-10-14
CVE-2025-59224 [HIGH] CWE-416 CVE-2025-59224: Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-59222P3HIGHCVSS 7.8v20192025-10-14
CVE-2025-59222 [HIGH] CWE-416 CVE-2025-59222: Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-59223P3HIGHCVSS 7.8v20192025-10-14
CVE-2025-59223 [HIGH] CWE-416 CVE-2025-59223: Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-40419P3HIGHCVSS 7.8v20192026-05-12
CVE-2026-40419 [HIGH] CWE-416 CVE-2026-40419: Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally. Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.
nvd
CVE-2016-3279P3MEDIUMCVSS 5.5v20102016-07-13
CVE-2016-3279 [MEDIUM] CWE-254 CVE-2016-3279: Microsoft Office 2010 SP2, Excel 2010 SP2, PowerPoint 2010 SP2, Word 2010 SP2, Excel 2013 SP1, Power Microsoft Office 2010 SP2, Excel 2010 SP2, PowerPoint 2010 SP2, Word 2010 SP2, Excel 2013 SP1, PowerPoint 2013 SP1, Word 2013 SP1, Excel 2013 RT SP1, PowerPoint 2013 RT SP1, Word 2013 RT SP1, Excel 2016, Word 2016, Word Automation Services on SharePoint Server 2010 SP2, and Office Web Apps 2010 SP2 allow remote attackers to execute arbitrary code via
nvd
CVE-2019-0825P3HIGHCVSS 7.8v2010v2016+1 more2019-04-09
CVE-2019-0825 [HIGH] CVE-2019-0825: A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine im A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory, aka 'Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0823, CVE-2019-0824, CVE-2019-0826, CVE-2019-0827.
nvd
CVE-2019-0824P3HIGHCVSS 7.8v2010v2013+2 more2019-04-09
CVE-2019-0824 [HIGH] CVE-2019-0824: A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine im A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory, aka 'Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0823, CVE-2019-0825, CVE-2019-0826, CVE-2019-0827.
nvd
CVE-2019-0827P3HIGHCVSS 7.8v2010v2013+2 more2019-04-09
CVE-2019-0827 [HIGH] CVE-2019-0827: A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine im A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory, aka 'Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0823, CVE-2019-0824, CVE-2019-0825, CVE-2019-0826.
nvd
CVE-2019-0823P3HIGHCVSS 7.8v20102019-04-09
CVE-2019-0823 [HIGH] CVE-2019-0823: A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine im A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory, aka 'Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0824, CVE-2019-0825, CVE-2019-0826, CVE-2019-0827.
nvd
CVE-2019-0826P3HIGHCVSS 7.8v2010v2013+2 more2019-04-09
CVE-2019-0826 [HIGH] CVE-2019-0826: A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine im A remote code execution vulnerability exists when the Microsoft Office Access Connectivity Engine improperly handles objects in memory, aka 'Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0823, CVE-2019-0824, CVE-2019-0825, CVE-2019-0827.
nvd
CVE-2025-49696P3HIGHCVSS 8.4v2016v20192025-07-08
CVE-2025-49696 [HIGH] CWE-122 CVE-2025-49696: Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally. Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.
nvd
CVE-2024-49033P3HIGHCVSS 7.5v20192024-11-12
CVE-2024-49033 [HIGH] CWE-20 CVE-2024-49033: Microsoft Word Security Feature Bypass Vulnerability Microsoft Word Security Feature Bypass Vulnerability
nvd
Microsoft Office vulnerabilities | cvebase