CVEs (120)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to perform tampering over a network. |
1Microsoft 10365 Copilot EdgeExcel+7 moreApr 9, 2026 Mar 16, 2026 N/A· v4 7.1 HIGH· v3 N/A· v2 AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network. |
1Microsoft 5365 Apps OfficeOffice Long Term Servicing Channel+2 moreFeb 11, 2026 Feb 10, 2026 N/A· v4 7.5 HIGH· v3 N/A· v2 Exposure of sensitive information to an unauthorized actor in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network. |
1Microsoft 6365 Apps OfficeOffice Long Term Servicing Channel+3 moreJul 15, 2025 Jul 8, 2025 N/A· v4 7.0 HIGH· v3 N/A· v2 Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. |
1Microsoft 4365 Apps OfficeOffice Long Term Servicing Channel+1 moreJul 9, 2025 Jun 10, 2025 N/A· v4 6.7 MEDIUM· v3 N/A· v2 Improper input validation in Microsoft Office Outlook allows an authorized attacker to execute code locally. |
Exposure of sensitive information to an unauthorized actor in Outlook for Android allows an unauthorized attacker to disclose information over a network. |
Microsoft Outlook Spoofing Vulnerability |
1Microsoft 3Office Office Long Term Servicing ChannelOutlookMay 19, 2026 Jan 14, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Microsoft Outlook Remote Code Execution Vulnerability |
1Microsoft 4365 Apps OfficeOffice Long Term Servicing Channel+1 moreJul 1, 2025 Jan 14, 2025 N/A· v4 6.7 MEDIUM· v3 N/A· v2 Microsoft Outlook Remote Code Execution Vulnerability |
A library injection vulnerability exists in Microsoft Outlook 16.83.3 for macOS. A specially crafted library can leverage Outlook's access privileges, leading to a permission bypass. A malicious application could inject...Show more |
Outlook for Android Elevation of Privilege Vulnerability |
Microsoft Outlook for iOS Information Disclosure Vulnerability |
1Microsoft 4365 Apps OfficeOffice Long Term Servicing Channel+1 moreAug 16, 2024 Aug 13, 2024 N/A· v4 6.7 MEDIUM· v3 N/A· v2 Microsoft Outlook Remote Code Execution Vulnerability |
1Microsoft 4365 Apps OfficeOffice Long Term Servicing Channel+1 moreNov 21, 2024 Jul 9, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Microsoft Outlook Spoofing Vulnerability |
1Microsoft 4365 Apps OfficeOffice Long Term Servicing Channel+1 moreMay 19, 2026 Jun 11, 2024 N/A· v4 8.8 HIGH· v3 N/A· v2 Microsoft Outlook Remote Code Execution Vulnerability |
Outlook for Windows Spoofing Vulnerability |
Outlook for Android Information Disclosure Vulnerability |
1Microsoft 4365 Apps OfficeOffice Long Term Servicing Channel+1 moreNov 21, 2024 Feb 13, 2024 N/A· v4 8.8 HIGH· v3 N/A· v2 Microsoft Outlook Remote Code Execution Vulnerability |
1Microsoft 4365 Apps OfficeOffice Long Term Servicing Channel+1 moreNov 21, 2024 Sep 12, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Microsoft Outlook Information Disclosure Vulnerability |
1Microsoft 4365 Apps OfficeOffice Long Term Servicing Channel+1 moreNov 21, 2024 Aug 8, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Microsoft Outlook Spoofing Vulnerability |