Vulnerabilities (CVE)

Filtered by vendor Microsoft Subscribe
Filtered by product Office
Total 1033 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-47293 1 Microsoft 4 365 Apps, Office, Office 2021 and 1 more 2026-07-23 N/A 7.0 HIGH
Use after free in Microsoft Office Click-To-Run allows an authorized attacker to elevate privileges locally.
CVE-2024-30104 1 Microsoft 3 365 Apps, Office, Office Long Term Servicing Channel 2026-07-20 N/A 7.8 HIGH
Microsoft Office Remote Code Execution Vulnerability
CVE-2024-30103 1 Microsoft 4 365 Apps, Office, Office Long Term Servicing Channel and 1 more 2026-07-20 N/A 8.8 HIGH
Microsoft Outlook Remote Code Execution Vulnerability
CVE-2024-30101 1 Microsoft 3 365 Apps, Office, Office Long Term Servicing Channel 2026-07-20 N/A 7.5 HIGH
Microsoft Office Remote Code Execution Vulnerability
CVE-2026-55054 2 Apple, Microsoft 8 Macos, 365 Apps, Excel and 5 more 2026-07-15 N/A 6.5 MEDIUM
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.
CVE-2026-21509 1 Microsoft 3 365 Apps, Office, Office Long Term Servicing Channel 2026-06-25 N/A 7.8 HIGH
Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.
CVE-2026-42832 1 Microsoft 4 Excel, Office, Office Long Term Servicing Channel and 1 more 2026-06-17 N/A 7.7 HIGH
Improper access control in Microsoft Office allows an unauthorized attacker to perform spoofing locally.
CVE-2026-42831 1 Microsoft 3 365 Copilot, Office, Office Long Term Servicing Channel 2026-06-17 N/A 7.8 HIGH
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-40421 1 Microsoft 4 365 Apps, Office, Office Long Term Servicing Channel and 1 more 2026-06-17 N/A 4.3 MEDIUM
Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
CVE-2026-40420 1 Microsoft 3 365 Apps, Office, Office Long Term Servicing Channel 2026-06-17 N/A 8.8 HIGH
Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.
CVE-2026-40419 1 Microsoft 3 365 Apps, Office, Office Long Term Servicing Channel 2026-06-17 N/A 7.8 HIGH
Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.
CVE-2026-40418 1 Microsoft 3 365 Apps, Office, Office Long Term Servicing Channel 2026-06-17 N/A 7.8 HIGH
Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.
CVE-2026-40367 1 Microsoft 5 365 Apps, Office, Office Long Term Servicing Channel and 2 more 2026-06-17 N/A 8.4 HIGH
Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-40366 1 Microsoft 4 365 Apps, Office, Office Long Term Servicing Channel and 1 more 2026-06-17 N/A 8.4 HIGH
Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-40364 1 Microsoft 4 365 Apps, Office, Office Long Term Servicing Channel and 1 more 2026-06-17 N/A 8.4 HIGH
Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-40363 1 Microsoft 4 365 Apps, 365 Copilot, Office and 1 more 2026-06-17 N/A 8.4 HIGH
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-40362 1 Microsoft 5 365 Apps, Excel, Office and 2 more 2026-06-17 N/A 7.8 HIGH
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2026-40361 1 Microsoft 4 365 Apps, Office, Office Long Term Servicing Channel and 1 more 2026-06-17 N/A 8.4 HIGH
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-40360 1 Microsoft 5 365 Apps, Excel, Office and 2 more 2026-06-17 N/A 7.8 HIGH
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2026-40359 1 Microsoft 5 365 Apps, Excel, Office and 2 more 2026-06-17 N/A 7.8 HIGH
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.