Filtered by vendor Microsoft Subscriptions
Filtered by product 365 Subscriptions
Total 61 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2025-62211 1 Microsoft 2 365, Dynamics 365 2025-11-13 8.7 High
Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Field Service (online) allows an authorized attacker to perform spoofing over a network.
CVE-2025-62205 1 Microsoft 6 365, 365 Apps, Office 2021 and 3 more 2025-11-13 7.8 High
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2025-62203 1 Microsoft 7 365, 365 Apps, Excel and 4 more 2025-11-13 7.8 High
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-62202 1 Microsoft 7 365, 365 Apps, Excel and 4 more 2025-11-13 7.1 High
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2025-62201 1 Microsoft 11 365, 365 Apps, Excel and 8 more 2025-11-13 7.8 High
Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-62200 1 Microsoft 8 365, 365 Apps, Excel and 5 more 2025-11-13 7.8 High
Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-59240 1 Microsoft 7 365, 365 Apps, Excel and 4 more 2025-11-13 5.5 Medium
Exposure of sensitive information to an unauthorized actor in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2025-62216 1 Microsoft 4 365, 365 Apps, Office 2021 and 1 more 2025-11-13 7.8 High
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2025-62210 1 Microsoft 2 365, Dynamics 365 2025-11-13 8.7 High
Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Field Service (online) allows an authorized attacker to perform spoofing over a network.
CVE-2025-62206 1 Microsoft 2 365, Dynamics 365 2025-11-13 6.5 Medium
Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an unauthorized attacker to disclose information over a network.
CVE-2025-62199 1 Microsoft 7 365, 365 Apps, Office and 4 more 2025-11-13 7.8 High
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2025-60728 1 Microsoft 6 365, 365 Apps, Office and 3 more 2025-11-13 4.3 Medium
Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.
CVE-2025-60727 1 Microsoft 7 365, 365 Apps, Excel and 4 more 2025-11-13 7.8 High
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-60726 1 Microsoft 7 365, 365 Apps, Excel and 4 more 2025-11-13 7.1 High
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVE-2025-53787 1 Microsoft 3 365, 365 Copilot, 365 Copilot Chat 2025-11-10 8.2 High
Microsoft 365 Copilot BizChat Information Disclosure Vulnerability
CVE-2025-53774 1 Microsoft 3 365, 365 Copilot, 365 Copilot Chat 2025-11-10 6.5 Medium
Microsoft 365 Copilot BizChat Information Disclosure Vulnerability
CVE-2025-53784 1 Microsoft 8 365, 365 Apps, Office and 5 more 2025-11-10 8.4 High
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2025-53740 1 Microsoft 10 365, 365 Apps, Office and 7 more 2025-11-10 8.4 High
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2025-53739 1 Microsoft 13 365, 365 Apps, Excel and 10 more 2025-11-10 7.8 High
Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
CVE-2025-53738 1 Microsoft 11 365, 365 Apps, Office and 8 more 2025-11-10 7.8 High
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.