Skip to main content

Vendor/product archive

microsoft / outlook CVEs

Beta · best-effort

122 CVEs tagged to microsoft / outlook10 Critical, 54 High, 58 Medium, 0 Low, 0 Unrated.

CVE-2026-42893

Published May 12, 2026

Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to perform tampering over a network.

CVSS 7.4 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2025-29805

Published Apr 8, 2025

Exposure of sensitive information to an unauthorized actor in Outlook for Android allows an unauthorized attacker to disclose information over a network.

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-42220

Published Dec 18, 2024

A library injection vulnerability exists in Microsoft Outlook 16.83.3 for macOS. A specially crafted library can leverage Outlook's access privileges, leading to a permission bypa…

CVSS 7.1 · High
evidence mentions
3
Buzz score
21.9
Vendor/product tagsBeta · best-effort

CVE-2024-43482

Published Sep 10, 2024

Microsoft Outlook for iOS Information Disclosure Vulnerability

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1-25 of 122 CVEsPage 1 of 5