Vulnerabilities (CVE)

Filtered by vendor Microsoft Subscribe
Filtered by product 365 Apps
Total 576 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-50675 1 Microsoft 7 365 Apps, Excel, Microsoft 365 and 4 more 2026-07-15 N/A 7.8 HIGH
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-50678 1 Microsoft 7 365 Apps, Excel, Microsoft 365 and 4 more 2026-07-15 N/A 6.6 MEDIUM
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-55136 1 Microsoft 7 365 Apps, Excel, Microsoft 365 and 4 more 2026-07-15 N/A 7.8 HIGH
Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-55137 1 Microsoft 7 365 Apps, Excel, Microsoft 365 and 4 more 2026-07-15 N/A 7.8 HIGH
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-55138 1 Microsoft 7 365 Apps, Excel, Microsoft 365 and 4 more 2026-07-15 N/A 5.5 MEDIUM
Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-55141 1 Microsoft 7 365 Apps, Excel, Microsoft 365 and 4 more 2026-07-15 N/A 7.8 HIGH
Stack-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-55898 1 Microsoft 7 365 Apps, Excel, Microsoft 365 and 4 more 2026-07-15 N/A 6.1 MEDIUM
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-55947 1 Microsoft 7 365 Apps, Excel, Microsoft 365 and 4 more 2026-07-15 N/A 7.8 HIGH
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-55949 1 Microsoft 7 365 Apps, Excel, Microsoft 365 and 4 more 2026-07-15 N/A 7.8 HIGH
Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-56156 1 Microsoft 4 365 Apps, Microsoft 365, Office 2021 and 1 more 2026-07-15 N/A 7.8 HIGH
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-55054 2 Apple, Microsoft 8 Macos, 365 Apps, Excel and 5 more 2026-07-15 N/A 6.5 MEDIUM
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.
CVE-2026-21509 1 Microsoft 3 365 Apps, Office, Office Long Term Servicing Channel 2026-06-25 N/A 7.8 HIGH
Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.
CVE-2026-40421 1 Microsoft 4 365 Apps, Office, Office Long Term Servicing Channel and 1 more 2026-06-17 N/A 4.3 MEDIUM
Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
CVE-2026-40420 1 Microsoft 3 365 Apps, Office, Office Long Term Servicing Channel 2026-06-17 N/A 8.8 HIGH
Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.
CVE-2026-40419 1 Microsoft 3 365 Apps, Office, Office Long Term Servicing Channel 2026-06-17 N/A 7.8 HIGH
Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.
CVE-2026-40418 1 Microsoft 3 365 Apps, Office, Office Long Term Servicing Channel 2026-06-17 N/A 7.8 HIGH
Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.
CVE-2026-40367 1 Microsoft 5 365 Apps, Office, Office Long Term Servicing Channel and 2 more 2026-06-17 N/A 8.4 HIGH
Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-40366 1 Microsoft 4 365 Apps, Office, Office Long Term Servicing Channel and 1 more 2026-06-17 N/A 8.4 HIGH
Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-40364 1 Microsoft 4 365 Apps, Office, Office Long Term Servicing Channel and 1 more 2026-06-17 N/A 8.4 HIGH
Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-40363 1 Microsoft 4 365 Apps, 365 Copilot, Office and 1 more 2026-06-17 N/A 8.4 HIGH
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.