CVEs (252)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Microsoft 4Excel OfficeOffice Long Term Servicing Channel+1 moreMay 19, 2026 May 12, 2026 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Improper access control in Microsoft Office allows an unauthorized attacker to perform spoofing locally. |
Improper access control in Microsoft Office Word allows an authorized attacker to perform spoofing locally. |
1Microsoft 4365 Apps OfficeOffice Long Term Servicing Channel+1 moreJun 1, 2026 May 12, 2026 N/A· v4 4.3 MEDIUM· v3 N/A· v2 Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose information locally. |
1Microsoft 5365 Apps OfficeOffice Long Term Servicing Channel+2 moreJun 1, 2026 May 12, 2026 N/A· v4 8.4 HIGH· v3 N/A· v2 Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
1Microsoft 4365 Apps OfficeOffice Long Term Servicing Channel+1 moreJun 1, 2026 May 12, 2026 N/A· v4 8.4 HIGH· v3 N/A· v2 Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
1Microsoft 4365 Apps OfficeOffice Long Term Servicing Channel+1 moreMay 19, 2026 May 12, 2026 N/A· v4 8.4 HIGH· v3 N/A· v2 Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
1Microsoft 4365 Apps OfficeOffice Long Term Servicing Channel+1 moreJun 3, 2026 May 12, 2026 N/A· v4 8.4 HIGH· v3 N/A· v2 Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. |
1Microsoft 4365 Apps OfficeOffice Long Term Servicing Channel+1 moreMay 19, 2026 May 12, 2026 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose information locally. |
1Microsoft 10365 Copilot EdgeExcel+7 moreApr 9, 2026 Mar 16, 2026 N/A· v4 7.1 HIGH· v3 N/A· v2 AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network. |
1Microsoft 5365 Apps OfficeOffice Long Term Servicing Channel+2 moreFeb 11, 2026 Feb 10, 2026 N/A· v4 7.5 HIGH· v3 N/A· v2 Deserialization of untrusted data in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network. |
1Microsoft 5365 Apps OfficeOffice Long Term Servicing Channel+2 moreJan 16, 2026 Jan 13, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
1Microsoft 5365 Apps OfficeOffice Long Term Servicing Channel+2 moreDec 9, 2025 Dec 9, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Use after free in Microsoft Office Outlook allows an unauthorized attacker to execute code locally. |
1Microsoft 5365 Apps OfficeOffice Long Term Servicing Channel+2 moreDec 10, 2025 Dec 9, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
1Microsoft 5365 Apps OfficeOffice Long Term Servicing Channel+2 moreDec 10, 2025 Dec 9, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
1Microsoft 5365 Apps OfficeOffice Long Term Servicing Channel+2 moreDec 10, 2025 Dec 9, 2025 N/A· v4 7.0 HIGH· v3 N/A· v2 Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
1Microsoft 5365 Apps OfficeOffice Long Term Servicing Channel+2 moreOct 16, 2025 Oct 14, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
1Microsoft 5365 Apps OfficeOffice Long Term Servicing Channel+2 moreOct 16, 2025 Oct 14, 2025 N/A· v4 7.0 HIGH· v3 N/A· v2 Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
1Microsoft 6365 Apps OfficeOffice Long Term Servicing Channel+3 moreSep 12, 2025 Sep 9, 2025 N/A· v4 7.1 HIGH· v3 N/A· v2 Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to disclose information locally. |
1Microsoft 4365 Apps OfficeOffice Long Term Servicing Channel+1 moreAug 18, 2025 Aug 12, 2025 N/A· v4 7.8 HIGH· v3 N/A· v2 Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
1Microsoft 6365 Apps OfficeOffice Long Term Servicing Channel+3 moreAug 18, 2025 Aug 12, 2025 N/A· v4 6.2 MEDIUM· v3 N/A· v2 Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. |