Office

Vendor:

First CVE: Jan 1, 1999 · Active for 27 years

1,033
Total CVEs
More Total CVEs than 100% of tracked products
36.9
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
7.9
Avg CVSS
Higher Avg CVSS than 68% of tracked products
3.5%
KEV Rate
Higher KEV Rate than 97% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Office over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 1, 1999
27 years ago
Most Recent CVE
Jul 14, 2026
10 days ago

CVE Severity & Scoring

Office1,033 CVEs
All CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local547 (53.0%)
Network158 (15.3%)
Unknown328 (31.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low677 (65.5%)
High28 (2.7%)
Unknown328 (31.8%)
User Interaction
None97 (9.4%)
Unknown328 (31.8%)
Required608 (58.9%)
Privileges Required
Low66 (6.4%)
High1 (0.1%)
None638 (61.8%)
Unknown328 (31.8%)

Top CVEs

Signals from CVEs in this product scope (1033 CVEs).

1,033 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Microsoft Office 2016 allow an attacker to run arbitrary code
Nov 15, 20177.898YESYES
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Windows Vista SP2, Windows Server 2008 SP2, Windows 7 SP1, Windows
Apr 12, 20177.898YESYES
The (1) ListView, (2) ListView2, (3) TreeView, and (4) TreeView2 ActiveX controls in MSCOMCTL.OCX in the Common Controls in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Go
Apr 10, 20128.898YESYES
GDI+ in Microsoft Windows Vista SP2 and Server 2008 SP2; Office 2003 SP3, 2007 SP3, and 2010 SP1 and SP2; Office Compatibility Pack SP3; and Lync 2010, 2010 Attendee, 2013, and Bas
Nov 6, 20137.897YESYES
Microsoft XML Core Services 3.0, 4.0, 5.0, and 6.0 accesses uninitialized memory locations, which allows remote attackers to execute arbitrary code or cause a denial of service (me
Jun 13, 20128.897YESYES
Stack-based buffer overflow in Microsoft Office XP SP3, Office 2003 SP3, Office 2007 SP2, Office 2010, Office 2004 and 2008 for Mac, Office for Mac 2011, and Open XML File Format C
Nov 10, 20107.897YESYES
Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Excel Viewer 2003 SP3; Office Excel Vi
Nov 11, 20097.897YESYES
Microsoft Outlook Elevation of Privilege Vulnerability
Mar 14, 20239.896YESNO
Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka "Microsoft Office Remote Code Execution Vulnerability". This CVE
Jul 11, 20177.896YESYES
Microsoft Word 2003 SP3, 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT; Word Viewer; Office Compatibility Pack SP3; Office for Mac 2011; Word Automation Services on SharePoint Serv
Mar 25, 20147.896YESYES

Exploit Exposure

Signals from CVEs in this product scope (1033 CVEs).

CISA KEV
36 CVEs
3.5% of CVEs· 97th percentile
Metasploit
15 CVEs
1.5% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
104 CVEs
10.1% of CVEs· 89th percentile

Social Chatter

Signals from CVEs in this product scope (1033 CVEs).

Media Mentions

Signals from CVEs in this product scope (1033 CVEs).

Top CNAs Publishing CVEs For Office

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
xp1188.631.9%519
x19.315.5%00
v.x217.727.2%03
9823.41.8%00
9717.21.9%00
202466.80.5%00
202115.50.5%00
20195077.64.5%816
20162947.612.3%1510
2013_rt87.24.0%00
20131787.612.9%1510
2011418.425.5%45
20102587.821.0%1935
2008999.129.8%512
2007_sp159.333.3%00
20071528.329.4%1636
20041489.129.9%625
20031228.632.4%1023
200178.122.8%00
2000848.430.5%413