cbcvebase.

Microsoft Office vulnerabilities

1,005 known vulnerabilities affecting microsoft/office.

Total CVEs
1,005
CISA KEV
35
actively exploited
Public exploits
103
Exploited in wild
68
Severity breakdown
CRITICAL277HIGH567MEDIUM155LOW6

Vulnerabilities

Page 40 of 51
CVE-2024-49030P3HIGHCVSS 7.8v20192024-11-12
CVE-2024-49030 [HIGH] CWE-122 CVE-2024-49030: Microsoft Excel Remote Code Execution Vulnerability Microsoft Excel Remote Code Execution Vulnerability
nvd
CVE-2024-49029P3HIGHCVSS 7.8v20192024-11-12
CVE-2024-49029 [HIGH] CWE-908 CVE-2024-49029: Microsoft Excel Remote Code Execution Vulnerability Microsoft Excel Remote Code Execution Vulnerability
nvd
CVE-2025-21356P3HIGHCVSS 7.8v20192025-01-14
CVE-2025-21356 [HIGH] CWE-122 CVE-2025-21356: Microsoft Office Visio Remote Code Execution Vulnerability Microsoft Office Visio Remote Code Execution Vulnerability
nvd
CVE-2017-0105P3MEDIUMCVSS 5.5v20102017-03-17
CVE-2017-0105 [MEDIUM] CWE-200 CVE-2017-0105: Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word for Mac 2011, Office Compatibility Pac Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word for Mac 2011, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2010 SP2, and Office Web Apps 2010 SP2 allow remote attackers to obtain sensitive information from out-of-bound memory via a crafted Office document, aka "Microsoft Office Information Disclosure Vulne
nvd
CVE-2025-30375P3HIGHCVSS 7.8v20192025-05-13
CVE-2025-30375 [HIGH] CWE-843 CVE-2025-30375: Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an un Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
nvd
CVE-2025-30383P3HIGHCVSS 7.8v20192025-05-13
CVE-2025-30383 [HIGH] CWE-843 CVE-2025-30383: Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an un Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
nvd
CVE-2026-40360P3HIGHCVSS 7.8v20192026-05-12
CVE-2026-40360 [HIGH] CWE-125 CVE-2026-40360: Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
nvd
CVE-2016-7276P3HIGHCVSS 7.1v2007v2010+1 more2016-12-20
CVE-2016-7276 [HIGH] CWE-125 CVE-2016-7276: Microsoft Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office for Mac 2011, and Office 2016 fo Microsoft Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office for Mac 2011, and Office 2016 for Mac allow remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read) via a crafted document, aka "Microsoft Office Information Disclosure Vulnerability."
nvd
CVE-2013-3160P3MEDIUMCVSS 5.0v2003v20072013-09-11
CVE-2013-3160 [MEDIUM] CWE-200 CVE-2013-3160: Microsoft Office 2003 SP3 and 2007 SP3, Word 2003 SP3 and 2007 SP3, and Word Viewer allow remote att Microsoft Office 2003 SP3 and 2007 SP3, Word 2003 SP3 and 2007 SP3, and Word Viewer allow remote attackers to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, aka "XML External Entities Resolution Vulnerability."
nvd
CVE-2020-1581P3HIGHCVSS 7.8v2013v20192020-08-17
CVE-2020-1581 [HIGH] CVE-2020-1581: An elevation of privilege vulnerability exists in the way that Microsoft Office Click-to-Run (C2R) c An elevation of privilege vulnerability exists in the way that Microsoft Office Click-to-Run (C2R) components handle objects in memory. An attacker who successfully exploited the vulnerability could elevate privileges. The attacker would need to already have the ability to execute code on the system. An attacker could exploit this vulnerability by running a spe
nvd
CVE-2020-16955P3HIGHCVSS 7.8v2013v20192020-10-16
CVE-2020-16955 [HIGH] CVE-2020-16955: <p>An elevation of privilege vulnerability exists in the way that Microsoft Office Click-to-Run (C2R An elevation of privilege vulnerability exists in the way that Microsoft Office Click-to-Run (C2R) AppVLP handles certain files. An attacker who successfully exploited the vulnerability could elevate privileges. To exploit this vulnerability, an attacker would need to convince a user to open a specially crafted file. The security update addresses the vulnerab
nvd
CVE-2020-16928P3HIGHCVSS 7.8v2013v20192020-10-16
CVE-2020-16928 [HIGH] CVE-2020-16928: <p>An elevation of privilege vulnerability exists in the way that Microsoft Office Click-to-Run (C2R An elevation of privilege vulnerability exists in the way that Microsoft Office Click-to-Run (C2R) AppVLP handles certain files. An attacker who successfully exploited the vulnerability could elevate privileges. To exploit this vulnerability, an attacker would need to convince a user to open a specially crafted file. The security update addresses the vulnerab
nvd
CVE-2020-17067P3HIGHCVSS 7.8v20192020-11-11
CVE-2020-17067 [HIGH] CVE-2020-17067: Microsoft Excel Security Feature Bypass Vulnerability Microsoft Excel Security Feature Bypass Vulnerability
nvd
CVE-2022-22003P3HIGHCVSS 7.8v2013v2013_rt+2 more2022-02-09
CVE-2022-22003 [HIGH] CVE-2022-22003: Microsoft Office Graphics Remote Code Execution Vulnerability Microsoft Office Graphics Remote Code Execution Vulnerability
nvd
CVE-2021-28449P3HIGHCVSS 7.8v2010v2013+2 more2021-04-13
CVE-2021-28449 [HIGH] CVE-2021-28449: Microsoft Office Remote Code Execution Vulnerability Microsoft Office Remote Code Execution Vulnerability
nvd
CVE-2021-31180P3HIGHCVSS 7.8v2013v20192021-05-11
CVE-2021-31180 [HIGH] CVE-2021-31180: Microsoft Office Graphics Remote Code Execution Vulnerability Microsoft Office Graphics Remote Code Execution Vulnerability
nvd
CVE-2021-24108P3HIGHCVSS 7.8v2010v2013+2 more2021-03-11
CVE-2021-24108 [HIGH] CVE-2021-24108: Microsoft Office Remote Code Execution Vulnerability Microsoft Office Remote Code Execution Vulnerability
nvd
CVE-2021-31940P3HIGHCVSS 7.8v2013v2016+1 more2021-06-08
CVE-2021-31940 [HIGH] CVE-2021-31940: Microsoft Office Graphics Remote Code Execution Vulnerability Microsoft Office Graphics Remote Code Execution Vulnerability
nvd
CVE-2022-38048P3HIGHCVSS 7.8v2013v2016+1 more2022-10-11
CVE-2022-38048 [HIGH] CVE-2022-38048: Microsoft Office Remote Code Execution Vulnerability Microsoft Office Remote Code Execution Vulnerability
nvd
CVE-2022-37962P3HIGHCVSS 7.8v2013v2016+1 more2022-09-13
CVE-2022-37962 [HIGH] CVE-2022-37962: Microsoft PowerPoint Remote Code Execution Vulnerability Microsoft PowerPoint Remote Code Execution Vulnerability
nvd
Microsoft Office vulnerabilities | cvebase