Vulnerabilities (CVE)

Filtered by vendor Microsoft Subscribe
Filtered by product Teams
Total 23 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-42835 1 Microsoft 1 Teams 2026-06-17 N/A 8.1 HIGH
Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Teams for Android allows an authorized attacker to disclose information over a network.
CVE-2026-33823 1 Microsoft 1 Teams 2026-06-17 N/A 9.6 CRITICAL
Improper authorization in Microsoft Teams allows an authorized attacker to disclose information over a network.
CVE-2026-32185 1 Microsoft 1 Teams 2026-06-17 N/A 5.5 MEDIUM
Files or directories accessible to external parties in Microsoft Teams allows an unauthorized attacker to perform spoofing locally.
CVE-2026-26133 1 Microsoft 10 365 Copilot, Edge, Excel and 7 more 2026-06-17 N/A 7.1 HIGH
AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network.
CVE-2026-21535 1 Microsoft 1 Teams 2026-06-17 N/A 8.2 HIGH
Improper access control in Microsoft Teams allows an unauthorized attacker to disclose information over a network.
CVE-2025-53783 1 Microsoft 5 Dynamics 365 Guides, Dynamics 365 Remote Assist, Teams and 2 more 2026-06-17 N/A 7.5 HIGH
Heap-based buffer overflow in Microsoft Teams allows an unauthorized attacker to execute code over a network.
CVE-2025-49737 1 Microsoft 1 Teams 2026-06-17 N/A 7.0 HIGH
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Teams allows an authorized attacker to elevate privileges locally.
CVE-2025-49731 1 Microsoft 1 Teams 2026-06-17 N/A 3.1 LOW
Improper handling of insufficient permissions or privileges in Microsoft Teams allows an authorized attacker to elevate privileges over a network.
CVE-2024-42004 1 Microsoft 1 Teams 2026-06-17 N/A 7.1 HIGH
A library injection vulnerability exists in Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A specially crafted library can leverage Teams's access privileges, leading to a permission bypass. A malicious application could inject a library and start the program to trigger this vulnerability and then make use of the vulnerable application's permissions.
CVE-2024-41145 1 Microsoft 1 Teams 2026-06-17 N/A 7.1 HIGH
A library injection vulnerability exists in the WebView.app helper app of Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A specially crafted library can leverage Teams's access privileges, leading to a permission bypass. A malicious application could inject a library and start the program to trigger this vulnerability and then make use of the vulnerable application's permissions.
CVE-2024-41138 1 Microsoft 1 Teams 2026-06-17 N/A 7.1 HIGH
A library injection vulnerability exists in the com.microsoft.teams2.modulehost.app helper app of Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A specially crafted library can leverage Teams's access privileges, leading to a permission bypass. A malicious application could inject a library and start the program to trigger this vulnerability and then make use of the vulnerable application's permissions.
CVE-2024-38197 1 Microsoft 1 Teams 2026-06-17 N/A 6.5 MEDIUM
Microsoft Teams for iOS Spoofing Vulnerability
CVE-2024-21448 1 Microsoft 1 Teams 2026-06-17 N/A 5.0 MEDIUM
Microsoft Teams for Android Information Disclosure Vulnerability
CVE-2024-21374 1 Microsoft 1 Teams 2026-06-17 N/A 5.0 MEDIUM
Microsoft Teams for Android Information Disclosure Vulnerability
CVE-2023-4863 9 Bandisoft, Bentley, Debian and 6 more 12 Honeyview, Seequent Leapfrog, Debian Linux and 9 more 2026-06-17 N/A 8.8 HIGH
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)
CVE-2023-29330 1 Microsoft 1 Teams 2026-06-17 N/A 8.8 HIGH
Microsoft Teams Remote Code Execution Vulnerability
CVE-2023-29328 1 Microsoft 1 Teams 2026-06-17 N/A 8.8 HIGH
Microsoft Teams Remote Code Execution Vulnerability
CVE-2023-24881 1 Microsoft 1 Teams 2026-06-17 N/A 6.5 MEDIUM
Microsoft Teams Information Disclosure Vulnerability
CVE-2022-21965 1 Microsoft 1 Teams 2026-06-17 5.0 MEDIUM 7.5 HIGH
Microsoft Teams Denial of Service Vulnerability
CVE-2021-24114 1 Microsoft 1 Teams 2026-06-17 3.5 LOW 5.7 MEDIUM
Microsoft Teams iOS Information Disclosure Vulnerability