CVE-2026-78509 — CVSS 9.8 (critical): Heap-based buffer overflow in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.
CVE-2020-0901 — CVSS 9.8 (critical): A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An…
CVE-2026-78504 — CVSS 8.8 (high): Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
CVE-2020-1495 — CVSS 8.8 (high): A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An…
CVE-2026-69767 — CVSS 8.8 (high): Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code over a network.
CVE-2026-78514 — CVSS 8.8 (high): Use after free in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
CVE-2026-69764 — CVSS 8.8 (high): Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
CVE-2026-78512 — CVSS 8.8 (high): Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
CVE-2026-69759 — CVSS 8.8 (high): Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
CVE-2026-72973 — CVSS 8.8 (high): Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
CVE-2026-69742 — CVSS 8.8 (high): Integer overflow or wraparound in Microsoft Office Publisher allows an unauthorized attacker to execute code over a network.
CVE-2020-1321 — CVSS 8.8 (high): A remote code execution vulnerability exists in Microsoft Office software when it fails to properly handle objects in memory, aka…
CVE-2026-69722 — CVSS 8.8 (high): Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
CVE-2026-78526 — CVSS 8.8 (high): Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
CVE-2026-78525 — CVSS 8.8 (high): Use after free in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.
CVE-2026-77901 — CVSS 8.8 (high): Null pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
CVE-2026-40420 — CVSS 8.8 (high): Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.
CVE-2026-69442 — CVSS 8.8 (high): Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code over a network.
CVE-2026-70329 — CVSS 8.8 (high): Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.
CVE-2026-78511 — CVSS 8.8 (high): Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
CVE-2020-1494 — CVSS 8.8 (high): A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An…
CVE-2026-78519 — CVSS 8.8 (high): Use of uninitialized resource in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.
CVE-2021-28455 — CVSS 8.8 (high): Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability
CVE-2026-69686 — CVSS 8.8 (high): Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
CVE-2026-69285 — CVSS 8.8 (high): Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code over a network.
CVE-2026-78507 — CVSS 8.8 (high): Use after free in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
CVE-2026-69678 — CVSS 8.8 (high): Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code over a network.
CVE-2026-69671 — CVSS 8.8 (high): Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
CVE-2026-78524 — CVSS 8.8 (high): Out-of-bounds write in Microsoft Office allows an unauthorized attacker to execute code over a network.
CVE-2026-80085 — CVSS 8.8 (high): Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
CVE-2026-81952 — CVSS 8.8 (high): Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
CVE-2026-65807 — CVSS 8.8 (high): Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code…
CVE-2026-78505 — CVSS 8.8 (high): Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code over a network.
CVE-2020-1225 — CVSS 8.8 (high): A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka…
CVE-2026-62870 — CVSS 8.8 (high): Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code over a network.
CVE-2026-72972 — CVSS 8.8 (high): Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
CVE-2026-69629 — CVSS 8.8 (high): Heap-based buffer overflow in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.
CVE-2026-69614 — CVSS 8.8 (high): Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code over a network.
CVE-2020-1498 — CVSS 8.8 (high): A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An…
CVE-2020-1583 — CVSS 8.8 (high): An information disclosure vulnerability exists when Microsoft Word improperly discloses the contents of its memory. An attacker who…
CVE-2020-1226 — CVSS 8.8 (high): A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka…
CVE-2026-69632 — CVSS 8.8 (high): Use after free in Microsoft Office allows an unauthorized attacker to execute code over a network.
CVE-2020-1496 — CVSS 8.8 (high): A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An…
CVE-2026-80081 — CVSS 8.8 (high): Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code over a network.
CVE-2026-78521 — CVSS 8.8 (high): Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
CVE-2026-81385 — CVSS 8.8 (high): Deserialization of untrusted data in Microsoft Office Publisher allows an unauthorized attacker to execute code over a network.
CVE-2026-80080 — CVSS 8.8 (high): Double free in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
CVE-2020-1446 — CVSS 8.8 (high): A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft…
CVE-2026-69797 — CVSS 8.8 (high): Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code over a network.
CVE-2026-69556 — CVSS 8.8 (high): Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
CVE-2026-35436 — CVSS 8.8 (high): Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.
CVE-2020-1447 — CVSS 8.8 (high): A remote code execution vulnerability exists in Microsoft Word software when it fails to properly handle objects in memory, aka 'Microsoft…
CVE-2020-1240 — CVSS 8.8 (high): A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory, aka…
CVE-2026-69778 — CVSS 8.8 (high): Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code over a network.
CVE-2026-78518 — CVSS 8.8 (high): Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code over a network.
CVE-2026-78517 — CVSS 8.8 (high): Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
CVE-2026-69529 — CVSS 8.8 (high): Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code over a network.
CVE-2026-33114 — CVSS 8.4 (high): Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-26113 — CVSS 8.4 (high): Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-78510 — CVSS 8.4 (high): Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-26110 — CVSS 8.4 (high): Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-26109 — CVSS 8.4 (high): Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-62554 — CVSS 8.4 (high): Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2025-59236 — CVSS 8.4 (high): Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-54910 — CVSS 8.4 (high): Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2025-53784 — CVSS 8.4 (high): Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-55045 — CVSS 8.4 (high): Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2025-53733 — CVSS 8.4 (high): Incorrect conversion between numeric types in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-45456 — CVSS 8.4 (high): Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-40367 — CVSS 8.4 (high): Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code…
CVE-2026-40366 — CVSS 8.4 (high): Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code…
CVE-2025-47957 — CVSS 8.4 (high): Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-40364 — CVSS 8.4 (high): Access of resource using incompatible type ('type confusion') in Microsoft Office Word allows an unauthorized attacker to execute code…
CVE-2026-40363 — CVSS 8.4 (high): Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2025-47167 — CVSS 8.4 (high): Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-44822 — CVSS 8.2 (high): Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.
CVE-2024-20677 — CVSS 7.8 (high): A security vulnerability exists in FBX that could lead to remote code execution. To mitigate this vulnerability, the ability to insert FBX…
CVE-2025-27750 — CVSS 7.8 (high): Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-27751 — CVSS 7.8 (high): Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-27752 — CVSS 7.8 (high): Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-29791 — CVSS 7.8 (high): Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.