Microsoft Office vulnerabilities
1,005 known vulnerabilities affecting microsoft/office.
Total CVEs
1,005
CISA KEV
35
actively exploited
Public exploits
103
Exploited in wild
68
Severity breakdown
CRITICAL277HIGH567MEDIUM155LOW6
Vulnerabilities
Page 48 of 51
CVE-2026-21261P4MEDIUMCVSS 5.5v20192026-02-10
CVE-2026-21261 [MEDIUM] CWE-125 CVE-2026-21261: Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
nvd
CVE-2025-59240P4MEDIUMCVSS 5.5v20192025-11-11
CVE-2025-59240 [MEDIUM] CWE-200 CVE-2025-59240: Exposure of sensitive information to an unauthorized actor in Microsoft Office Excel allows an unaut
Exposure of sensitive information to an unauthorized actor in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
nvd
CVE-2026-35440P4MEDIUMCVSS 5.5v20192026-05-12
CVE-2026-35440 [MEDIUM] CWE-552 CVE-2026-35440: Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized
Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
nvd
CVE-2026-42832P4MEDIUMCVSS 5.5v20242026-05-12
CVE-2026-42832 [MEDIUM] CWE-284 CVE-2026-42832: Improper access control in Microsoft Office allows an unauthorized attacker to perform spoofing loca
Improper access control in Microsoft Office allows an unauthorized attacker to perform spoofing locally.
nvd
CVE-2020-1445P4MEDIUMCVSS 5.5v2010v2016+1 more2020-07-14
CVE-2020-1445 [MEDIUM] CVE-2020-1445: An information disclosure vulnerability exists when Microsoft Office improperly discloses the conten
An information disclosure vulnerability exists when Microsoft Office improperly discloses the contents of its memory, aka 'Microsoft Office Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-1342.
nvd
CVE-2022-29107P4MEDIUMCVSS 5.5v20192022-05-10
CVE-2022-29107 [MEDIUM] CVE-2022-29107: Microsoft Office Security Feature Bypass Vulnerability
Microsoft Office Security Feature Bypass Vulnerability
nvd
CVE-2002-1716P4MEDIUMCVSS 5.0vxp2002-12-31
CVE-2002-1716 [MEDIUM] CVE-2002-1716: The Host() function in the Microsoft spreadsheet component on Microsoft Office XP allows remote atta
The Host() function in the Microsoft spreadsheet component on Microsoft Office XP allows remote attackers to create arbitrary files using the SaveAs capability.
nvd
CVE-2025-54901P4MEDIUMCVSS 5.5v20192025-09-09
CVE-2025-54901 [MEDIUM] CWE-126 CVE-2025-54901: Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to disclose information l
Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
nvd
CVE-2006-0008P4HIGHCVSS 7.2v20032006-02-14
CVE-2006-0008 [HIGH] CWE-264 CVE-2006-0008: The ShellAbout API call in Korean Input Method Editor (IME) in Korean versions of Microsoft Windows
The ShellAbout API call in Korean Input Method Editor (IME) in Korean versions of Microsoft Windows XP SP1 and SP2, Windows Server 2003 up to SP1, and Office 2003, allows local users to gain privileges by launching the "shell about dialog box" and clicking the "End-User License Agreement" link, which executes Notepad with the privileges of the program th
nvd
CVE-2020-1583P4MEDIUMCVSS 5.5v2010v2016+1 more2020-08-17
CVE-2020-1583 [MEDIUM] CVE-2020-1583: An information disclosure vulnerability exists when Microsoft Word improperly discloses the contents
An information disclosure vulnerability exists when Microsoft Word improperly discloses the contents of its memory. An attacker who exploited the vulnerability could use the information to compromise the user’s computer or data.
To exploit the vulnerability, an attacker could craft a special document file and then convince the user to open it. An attacker mus
nvd
CVE-2020-1497P4MEDIUMCVSS 5.5v2010v2013+2 more2020-08-17
CVE-2020-1497 [MEDIUM] CVE-2020-1497: An information disclosure vulnerability exists when Microsoft Excel improperly discloses the content
An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory. An attacker who exploited the vulnerability could use the information to compromise the user’s computer or data.
To exploit the vulnerability, an attacker could craft a special document file and then convince the user to open it. An attacker mu
nvd
CVE-2020-1502P4MEDIUMCVSS 5.5v20192020-08-17
CVE-2020-1502 [MEDIUM] CVE-2020-1502: An information disclosure vulnerability exists when Microsoft Word improperly discloses the contents
An information disclosure vulnerability exists when Microsoft Word improperly discloses the contents of its memory. An attacker who exploited the vulnerability could use the information to compromise the user’s computer or data.
To exploit the vulnerability, an attacker could craft a special document file and then convince the user to open it. An attacker mus
nvd
CVE-2020-1503P4MEDIUMCVSS 5.5v2010v2016+1 more2020-08-17
CVE-2020-1503 [MEDIUM] CVE-2020-1503: An information disclosure vulnerability exists when Microsoft Word improperly discloses the contents
An information disclosure vulnerability exists when Microsoft Word improperly discloses the contents of its memory. An attacker who exploited the vulnerability could use the information to compromise the user’s computer or data.
To exploit the vulnerability, an attacker could craft a special document file and then convince the user to open it. An attacker mus
nvd
CVE-2020-1224P4MEDIUMCVSS 5.5v2016v20192020-09-11
CVE-2020-1224 [MEDIUM] CVE-2020-1224: <p>An information disclosure vulnerability exists when Microsoft Excel improperly discloses the cont
An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory. An attacker who exploited the vulnerability could use the information to compromise the user’s computer or data.
To exploit the vulnerability, an attacker could craft a special document file and then convince the user to open it. An attacker mu
nvd
CVE-2022-22716P4MEDIUMCVSS 5.5v20192022-02-09
CVE-2022-22716 [MEDIUM] CWE-119 CVE-2022-22716: Microsoft Excel Information Disclosure Vulnerability
Microsoft Excel Information Disclosure Vulnerability
nvd
CVE-2006-1305P4MEDIUMCVSS 4.3v2000vxp+1 more2006-12-31
CVE-2006-1305 [MEDIUM] CWE-399 CVE-2006-1305: Microsoft Outlook 2000, 2002, and 2003 allows user-assisted remote attackers to cause a denial of se
Microsoft Outlook 2000, 2002, and 2003 allows user-assisted remote attackers to cause a denial of service (memory exhaustion and interrupted mail recovery) via malformed e-mail header information, possibly related to (1) long subject lines or (2) large numbers of recipients in To or CC headers.
nvd
CVE-2021-28456P4MEDIUMCVSS 5.5v20192021-04-13
CVE-2021-28456 [MEDIUM] CVE-2021-28456: Microsoft Excel Information Disclosure Vulnerability
Microsoft Excel Information Disclosure Vulnerability
nvd
CVE-2021-31174P4MEDIUMCVSS 5.5v2013v2016+1 more2021-05-11
CVE-2021-31174 [MEDIUM] CWE-125 CVE-2021-31174: Microsoft Excel Information Disclosure Vulnerability
Microsoft Excel Information Disclosure Vulnerability
nvd
CVE-2022-24462P4MEDIUMCVSS 5.5v20192022-03-09
CVE-2022-24462 [MEDIUM] CVE-2022-24462: Microsoft Word Security Feature Bypass Vulnerability
Microsoft Word Security Feature Bypass Vulnerability
nvd
CVE-2020-17020P4MEDIUMCVSS 5.5v2010v20192020-11-11
CVE-2020-17020 [MEDIUM] CVE-2020-17020: Microsoft Word Security Feature Bypass Vulnerability
Microsoft Word Security Feature Bypass Vulnerability
nvd