Vulnerabilities (CVE)

Filtered by vendor Microsoft Subscribe
Filtered by product Outlook
Total 121 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-30103 1 Microsoft 4 365 Apps, Office, Office Long Term Servicing Channel and 1 more 2026-07-20 N/A 8.8 HIGH
Microsoft Outlook Remote Code Execution Vulnerability
CVE-2026-42893 1 Microsoft 1 Outlook 2026-06-17 N/A 7.4 HIGH
Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to perform tampering over a network.
CVE-2026-26133 1 Microsoft 10 365 Copilot, Edge, Excel and 7 more 2026-06-17 N/A 7.1 HIGH
AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.
CVE-2026-21260 1 Microsoft 5 365 Apps, Office, Office Long Term Servicing Channel and 2 more 2026-06-17 N/A 7.5 HIGH
Exposure of sensitive information to an unauthorized actor in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network.
CVE-2025-49699 1 Microsoft 6 365 Apps, Office, Office Long Term Servicing Channel and 3 more 2026-06-17 N/A 7.0 HIGH
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2025-47171 1 Microsoft 4 365 Apps, Office, Office Long Term Servicing Channel and 1 more 2026-06-17 N/A 6.7 MEDIUM
Improper input validation in Microsoft Office Outlook allows an authorized attacker to execute code locally.
CVE-2025-29805 1 Microsoft 1 Outlook 2026-06-17 N/A 7.5 HIGH
Exposure of sensitive information to an unauthorized actor in Outlook for Android allows an unauthorized attacker to disclose information over a network.
CVE-2025-21361 1 Microsoft 3 Office, Office Long Term Servicing Channel, Outlook 2026-06-17 N/A 7.8 HIGH
Microsoft Outlook Remote Code Execution Vulnerability
CVE-2025-21357 1 Microsoft 4 365 Apps, Office, Office Long Term Servicing Channel and 1 more 2026-06-17 N/A 6.7 MEDIUM
Microsoft Outlook Remote Code Execution Vulnerability
CVE-2025-21259 1 Microsoft 1 Outlook 2026-06-17 N/A 5.3 MEDIUM
Microsoft Outlook Spoofing Vulnerability
CVE-2024-43604 1 Microsoft 1 Outlook 2026-06-17 N/A 5.7 MEDIUM
Outlook for Android Elevation of Privilege Vulnerability
CVE-2024-43482 1 Microsoft 1 Outlook 2026-06-17 N/A 6.5 MEDIUM
Microsoft Outlook for iOS Information Disclosure Vulnerability
CVE-2024-42220 1 Microsoft 1 Outlook 2026-06-17 N/A 7.1 HIGH
A library injection vulnerability exists in Microsoft Outlook 16.83.3 for macOS. A specially crafted library can leverage Outlook's access privileges, leading to a permission bypass. A malicious application could inject a library and start the program to trigger this vulnerability and then make use of the vulnerable application's permissions.
CVE-2024-38173 1 Microsoft 4 365 Apps, Office, Office Long Term Servicing Channel and 1 more 2026-06-17 N/A 6.7 MEDIUM
Microsoft Outlook Remote Code Execution Vulnerability
CVE-2024-38020 1 Microsoft 4 365 Apps, Office, Office Long Term Servicing Channel and 1 more 2026-06-17 N/A 6.5 MEDIUM
Microsoft Outlook Spoofing Vulnerability
CVE-2024-26204 1 Microsoft 1 Outlook 2026-06-17 N/A 7.5 HIGH
Outlook for Android Information Disclosure Vulnerability
CVE-2024-21378 1 Microsoft 4 365 Apps, Office, Office Long Term Servicing Channel and 1 more 2026-06-17 N/A 8.8 HIGH
Microsoft Outlook Remote Code Execution Vulnerability
CVE-2024-20670 1 Microsoft 2 Outlook, Windows 2026-06-17 N/A 8.1 HIGH
Outlook for Windows Spoofing Vulnerability
CVE-2023-36893 1 Microsoft 4 365 Apps, Office, Office Long Term Servicing Channel and 1 more 2026-06-17 N/A 6.5 MEDIUM
Microsoft Outlook Spoofing Vulnerability
CVE-2023-36763 1 Microsoft 4 365 Apps, Office, Office Long Term Servicing Channel and 1 more 2026-06-17 N/A 7.5 HIGH
Microsoft Outlook Information Disclosure Vulnerability