Show filters
417 Total Results
Displaying 11-20 of 417
Sort by:
Attacker Value
Unknown

CVE-2015-2523

Disclosure Date: September 09, 2015 (last updated October 05, 2023)
Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel for Mac 2011 and 2016, Office Compatibility Pack SP3, and Excel Viewer allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."
1
Attacker Value
Unknown

Microsoft Tagged Image File Format Heap Overflow

Disclosure Date: November 06, 2013 (last updated July 25, 2024)
GDI+ in Microsoft Windows Vista SP2 and Server 2008 SP2; Office 2003 SP3, 2007 SP3, and 2010 SP1 and SP2; Office Compatibility Pack SP3; and Lync 2010, 2010 Attendee, 2013, and Basic 2013 allows remote attackers to execute arbitrary code via a crafted TIFF image, as demonstrated by an image in a Word document, and exploited in the wild in October and November 2013.
Attacker Value
Unknown

CVE-2025-1043

Disclosure Date: February 20, 2025 (last updated February 21, 2025)
The Embed Any Document – Embed PDF, Word, PowerPoint and Excel Files plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.7.5 via the 'embeddoc' shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.
Attacker Value
Unknown

CVE-2025-21394

Disclosure Date: February 11, 2025 (last updated February 20, 2025)
Microsoft Excel Remote Code Execution Vulnerability
Attacker Value
Unknown

CVE-2025-21390

Disclosure Date: February 11, 2025 (last updated February 20, 2025)
Microsoft Excel Remote Code Execution Vulnerability
Attacker Value
Unknown

CVE-2025-21387

Disclosure Date: February 11, 2025 (last updated February 20, 2025)
Microsoft Excel Remote Code Execution Vulnerability
Attacker Value
Unknown

CVE-2025-21386

Disclosure Date: February 11, 2025 (last updated February 20, 2025)
Microsoft Excel Remote Code Execution Vulnerability
Attacker Value
Unknown

CVE-2025-21383

Disclosure Date: February 11, 2025 (last updated February 20, 2025)
Microsoft Excel Information Disclosure Vulnerability
Attacker Value
Unknown

CVE-2025-21381

Disclosure Date: February 11, 2025 (last updated February 20, 2025)
Microsoft Excel Remote Code Execution Vulnerability
Attacker Value
Unknown

CVE-2025-24629

Disclosure Date: February 03, 2025 (last updated February 04, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPGear Import Excel to Gravity Forms allows Reflected XSS. This issue affects Import Excel to Gravity Forms: from n/a through 1.18.
0