Word

Vendor:

First CVE: Nov 1, 1999 · Active for 26 years

270
Total CVEs
More Total CVEs than 100% of tracked products
10.0
Avg CVEs / Year
Higher CVE frequency than 96% of tracked products
7.9
Avg CVSS
Higher Avg CVSS than 68% of tracked products
3.7%
KEV Rate
Higher KEV Rate than 97% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Word over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 1, 1999
26 years ago
Most Recent CVE
Jul 14, 2026
10 days ago

CVE Severity & Scoring

Word270 CVEs
All CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local119 (44.1%)
Network45 (16.7%)
Unknown106 (39.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low157 (58.1%)
High7 (2.6%)
Unknown106 (39.3%)
User Interaction
None14 (5.2%)
Unknown106 (39.3%)
Required150 (55.6%)
Privileges Required
Low3 (1.1%)
High0 (0.0%)
None161 (59.6%)
Unknown106 (39.3%)

Top CVEs

Signals from CVEs in this product scope (270 CVEs).

270 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Microsoft Word 2003 SP3, 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT; Word Viewer; Office Compatibility Pack SP3; Office for Mac 2011; Word Automation Services on SharePoint Serv
Mar 25, 20147.896YESYES
Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way object
Jan 10, 20188.895YESNO
Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow a remote code execution vulnerability due to the way objects
Jan 10, 20187.894YESNO
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word for Mac 2011, Office Compatibility Pack SP3, Word Automation Services on SharePoint S
Apr 14, 20157.894YESNO
Microsoft Office 2010, SharePoint Enterprise Server 2010, SharePoint Server 2010, Web Applications, Office Web Apps Server 2010 and 2013, Word Viewer, Word 2007, 2010, 2013 and 201
Oct 13, 20177.892YESNO
Microsoft Word 2003 SP3, 2007 SP2 and SP3, and 2010 SP1; Word Viewer; Office Compatibility Pack SP2 and SP3; and Office Web Apps 2010 SP1 allow remote attackers to execute arbitrar
Dec 12, 20127.886YESNO
Unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, allows remote user-assisted attackers to execute arbitrary code v
Feb 3, 20078.884YESNO
Microsoft Word 2007 SP2, Office 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, Word for Mac 2011, Word 2016 for Mac, Office Compatibility Pack SP3, Word Viewer, Word Automat
Oct 14, 20167.883YESNO
Microsoft PowerPoint 2007 SP3, Word 2007 SP3, PowerPoint 2010 SP2, Word 2010 SP2, PowerPoint 2013 SP1, Word 2013 SP1, and PowerPoint 2013 RT SP1 allow remote attackers to execute a
Jul 14, 20158.882YESNO
Microsoft Word Remote Code Execution Vulnerability
Feb 14, 20239.877NONO

Exploit Exposure

Signals from CVEs in this product scope (270 CVEs).

CISA KEV
10 CVEs
3.7% of CVEs· 97th percentile
Metasploit
1 CVE
0.4% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
16 CVEs
5.9% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (270 CVEs).

Media Mentions

Signals from CVEs in this product scope (270 CVEs).

Top CNAs Publishing CVEs For Word

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
9876.718.7%01
9786.717.6%01
20161357.58.8%51
2013997.820.8%83
201138.357.8%20
20101058.122.0%75
2007_sp119.325.9%00
20071008.426.0%610
200428.126.0%00
2003_sp319.325.9%00
2003428.425.8%36
2002378.327.0%15
200134.718.9%01
2000287.321.4%14
16.8319.10.7%00