microsoft word CVE Vulnerabilities (257)

CVEs: 257 CPE versions: View versions table

Summary

This page lists publicly disclosed CVE vulnerabilities affecting microsoft word (linked via NVD CPE). Each row includes severity scores, summaries, and publication dates to help identify and analyze security issues.

Showing 120 of 257 CVEs
«« First « Prev Page 1 / 13 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2026-45649 Improper access control in Office for Android allows an unauthorized attacker to perform spoofing locally. [email protected] 7.1 0.34% 2026-06-09 2026-06-19
CVE-2026-45471 Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally. [email protected] 7.8 0.30% 2026-06-09 2026-06-19
CVE-2026-45458 Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally. [email protected] 8.4 0.35% 2026-06-09 2026-06-19
CVE-2026-44812 Integer overflow or wraparound in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally. [email protected] 7.8 0.34% 2026-06-09 2026-06-19
CVE-2026-44803 Integer overflow or wraparound in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally. [email protected] 7.8 0.34% 2026-06-09 2026-06-19
CVE-2026-42832 Improper access control in Microsoft Office allows an unauthorized attacker to perform spoofing locally. [email protected] 7.7 0.22% 2026-05-12 2026-06-17
CVE-2026-41101 Improper access control in Microsoft Office Word allows an authorized attacker to perform spoofing locally. [email protected] 7.1 0.29% 2026-05-12 2026-06-17
CVE-2026-40421 Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose information locally. [email protected] 4.3 0.62% 2026-05-12 2026-06-17
CVE-2026-40367 Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally. [email protected] 8.4 0.44% 2026-05-12 2026-06-17
CVE-2026-40366 Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally. [email protected] 8.4 0.38% 2026-05-12 2026-06-17
CVE-2026-40364 Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code locally. [email protected] 8.4 4.42% 2026-05-12 2026-06-17
CVE-2026-40361 Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. [email protected] 8.4 0.58% 2026-05-12 2026-06-17
CVE-2026-35440 Files or directories accessible to external parties in Microsoft Office Word allows an unauthorized attacker to disclose information locally. [email protected] 5.5 0.47% 2026-05-12 2026-06-17
CVE-2026-26133 AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network. [email protected] 7.1 0.43% 2026-03-16 2026-06-17
CVE-2026-21511 Deserialization of untrusted data in Microsoft Office Outlook allows an unauthorized attacker to perform spoofing over a network. [email protected] 7.5 3.64% 2026-02-10 2026-06-17
CVE-2026-20948 Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally. [email protected] 7.8 0.52% 2026-01-13 2026-06-17
CVE-2025-62562 Use after free in Microsoft Office Outlook allows an unauthorized attacker to execute code locally. [email protected] 7.8 0.75% 2025-12-09 2026-06-17
CVE-2025-62559 Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. [email protected] 7.8 0.58% 2025-12-09 2026-06-17
CVE-2025-62558 Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. [email protected] 7.8 0.58% 2025-12-09 2026-06-17
CVE-2025-62555 Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. [email protected] 7.0 0.47% 2025-12-09 2026-06-17
«« First « Prev Page 1 / 13 Next »
cvelogic Threat Intelligence