cbcvebase.

Microsoft Office vulnerabilities

1,005 known vulnerabilities affecting microsoft/office.

Total CVEs
1,005
CISA KEV
35
actively exploited
Public exploits
103
Exploited in wild
68
Severity breakdown
CRITICAL277HIGH567MEDIUM155LOW6

Vulnerabilities

Page 43 of 51
CVE-2025-21346P3HIGHCVSS 7.8v2016v20192025-01-14
CVE-2025-21346 [HIGH] CWE-693 CVE-2025-21346: Microsoft Office Security Feature Bypass Vulnerability Microsoft Office Security Feature Bypass Vulnerability
nvd
CVE-2023-33149P3HIGHCVSS 7.8v2013v2016+1 more2023-07-11
CVE-2023-33149 [HIGH] CWE-416 CVE-2023-33149: Microsoft Office Graphics Remote Code Execution Vulnerability Microsoft Office Graphics Remote Code Execution Vulnerability
nvd
CVE-2023-33152P3HIGHCVSS 7.8v2013v2016+1 more2023-07-11
CVE-2023-33152 [HIGH] CWE-122 CVE-2023-33152: Microsoft ActiveX Remote Code Execution Vulnerability Microsoft ActiveX Remote Code Execution Vulnerability
nvd
CVE-2025-30379P3HIGHCVSS 7.8v20192025-05-13
CVE-2025-30379 [HIGH] CWE-763 CVE-2025-30379: Release of invalid pointer or reference in Microsoft Office Excel allows an unauthorized attacker to Release of invalid pointer or reference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
nvd
CVE-2016-3234P3MEDIUMCVSS 5.5v20102016-06-16
CVE-2016-3234 [MEDIUM] CWE-200 CVE-2016-3234: Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Office Compatibility Pack SP3, Word Viewer, Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Office Compatibility Pack SP3, Word Viewer, Word Automation Services on SharePoint Server 2010 SP2, Word Automation Services on SharePoint Server 2013 SP1, Office Web Apps 2010 SP2, and Office Web Apps Server 2013 SP1 allow remote attackers to obtain sensitive information from process memory via
nvd
CVE-2023-36762P3HIGHCVSS 7.3v20192023-09-12
CVE-2023-36762 [HIGH] CWE-20 CVE-2023-36762: Microsoft Word Remote Code Execution Vulnerability Microsoft Word Remote Code Execution Vulnerability
nvd
CVE-2019-1457P3HIGHCVSS 7.8v2016v20192019-11-12
CVE-2019-1457 [HIGH] CWE-732 CVE-2019-1457: A security feature bypass vulnerability exists in Microsoft Office software by not enforcing macro s A security feature bypass vulnerability exists in Microsoft Office software by not enforcing macro settings on an Excel document, aka 'Microsoft Office Excel Security Feature Bypass'.
nvd
CVE-2022-38049P3HIGHCVSS 7.8v20192022-10-11
CVE-2022-38049 [HIGH] CVE-2022-38049: Microsoft Office Graphics Remote Code Execution Vulnerability Microsoft Office Graphics Remote Code Execution Vulnerability
nvd
CVE-2022-41107P3HIGHCVSS 7.8v20192022-11-09
CVE-2022-41107 [HIGH] CVE-2022-41107: Microsoft Office Graphics Remote Code Execution Vulnerability Microsoft Office Graphics Remote Code Execution Vulnerability
nvd
CVE-2024-43465P3HIGHCVSS 7.8v20192024-09-10
CVE-2024-43465 [HIGH] CWE-416 CVE-2024-43465: Microsoft Excel Elevation of Privilege Vulnerability Microsoft Excel Elevation of Privilege Vulnerability
nvd
CVE-2022-44692P3HIGHCVSS 7.8v20192022-12-13
CVE-2022-44692 [HIGH] CVE-2022-44692: Microsoft Office Graphics Remote Code Execution Vulnerability Microsoft Office Graphics Remote Code Execution Vulnerability
nvd
CVE-2023-24910P3HIGHCVSS 7.8v20192023-03-14
CVE-2023-24910 [HIGH] CWE-476 CVE-2023-24910: Windows Graphics Component Elevation of Privilege Vulnerability Windows Graphics Component Elevation of Privilege Vulnerability
nvd
CVE-2006-3868P3MEDIUMCVSS 5.1v2003vxp2006-10-10
CVE-2006-3868 [MEDIUM] CVE-2006-3868: Unspecified vulnerability in Microsoft Office XP and 2003 allows remote user-assisted attackers to e Unspecified vulnerability in Microsoft Office XP and 2003 allows remote user-assisted attackers to execute arbitrary code via a malformed Smart Tag.
nvd
CVE-2025-62555P3HIGHCVSS 7.0v20192025-12-09
CVE-2025-62555 [HIGH] CWE-416 CVE-2025-62555: Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
nvd
CVE-2019-1084P3MEDIUMCVSS 6.5v2010v2013+2 more2019-07-15
CVE-2019-1084 [MEDIUM] CWE-200 CVE-2019-1084: An information disclosure vulnerability exists when Exchange allows creation of entities with Displa An information disclosure vulnerability exists when Exchange allows creation of entities with Display Names having non-printable characters. An authenticated attacker could exploit this vulnerability by creating entities with invalid display names, which, when added to conversations, remain invisible. This security update addresses the issue by valida
nvd
CVE-2017-0073P4MEDIUMCVSS 4.3v2007v20102017-03-17
CVE-2017-0073 [MEDIUM] CVE-2017-0073: The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 S The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Windows GDI+ Information Disclosure Vul
nvd
CVE-2025-59221P3HIGHCVSS 7.0v20192025-10-14
CVE-2025-59221 [HIGH] CWE-416 CVE-2025-59221: Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
nvd
CVE-2006-0028P3MEDIUMCVSS 5.1v2000v2003+3 more2006-03-14
CVE-2006-0028 [MEDIUM] CVE-2006-0028: Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and Unspecified vulnerability in Microsoft Excel 2000, 2002, and 2003, in Microsoft Office 2000 SP3 and other packages, allows user-assisted attackers to execute arbitrary code via a BIFF parsing format file containing malformed BOOLERR records that lead to memory corruption, probably involving invalid pointers.
nvd
CVE-2026-55054P3MEDIUMCVSS 6.5v20192026-07-14
CVE-2026-55054 [MEDIUM] CWE-125 CVE-2026-55054: Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2000-0419P4HIGHCVSS 7.5v20002000-05-11
CVE-2000-0419 [HIGH] CVE-2000-0419: The Office 2000 UA ActiveX Control is marked as "safe for scripting," which allows remote attackers The Office 2000 UA ActiveX Control is marked as "safe for scripting," which allows remote attackers to conduct unauthorized activities via the "Show Me" function in Office Help, aka the "Office 2000 UA Control" vulnerability.
nvd
Microsoft Office vulnerabilities | cvebase