Skip to main content

Vendor/product archive

microsoft / outlook CVEs

Beta · best-effort

120 CVEs tagged to microsoft / outlook10 Critical, 53 High, 57 Medium, 0 Low, 0 Unrated.

CVE-2026-42893

Published May 12, 2026

Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to perform tampering over a network.

CVSS 7.4 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2025-29805

Published Apr 8, 2025

Exposure of sensitive information to an unauthorized actor in Outlook for Android allows an unauthorized attacker to disclose information over a network.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-42220

Published Dec 18, 2024

A library injection vulnerability exists in Microsoft Outlook 16.83.3 for macOS. A specially crafted library can leverage Outlook's access privileges, leading to a permission bypa…

CVSS 7.1 · High
evidence mentions
3
Buzz score
21.9
Vendor/product tagsBeta · best-effort

CVE-2022-24480

Published Dec 13, 2022

Outlook for Android Elevation of Privilege Vulnerability

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 120 CVEsPage 1 of 5