Skip to main content

Vendor/product archive

microsoft / teams CVEs

Beta · best-effort

23 CVEs tagged to microsoft / teams1 Critical, 14 High, 7 Medium, 1 Low, 0 Unrated.

CVE-2026-42835

Published Jun 9, 2026

Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Teams for Android allows an authorized attacker to disclose informa…

CVSS 8.1 · High
evidence mentions
3
Buzz score
21.9
Vendor/product tagsBeta · best-effort

CVE-2026-32185

Published May 12, 2026

Files or directories accessible to external parties in Microsoft Teams allows an unauthorized attacker to perform spoofing locally.

CVSS 5.5 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-33823

Published May 7, 2026

Improper authorization in Microsoft Teams allows an authorized attacker to disclose information over a network.

CVSS 9.6 · Critical
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-21535

Published Feb 19, 2026

Improper access control in Microsoft Teams allows an unauthorized attacker to disclose information over a network.

CVSS 8.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-49737

Published Jul 8, 2025

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Teams allows an authorized attacker to elevate privileges locally.

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2025-49731

Published Jul 8, 2025

Improper handling of insufficient permissions or privileges in Microsoft Teams allows an authorized attacker to elevate privileges over a network.

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-42004

Published Dec 18, 2024

A library injection vulnerability exists in Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A specially crafted library can leverage Teams's access privileges, le…

CVSS 7.1 · High
evidence mentions
3
Buzz score
21.9
Vendor/product tagsBeta · best-effort

CVE-2024-41145

Published Dec 18, 2024

A library injection vulnerability exists in the WebView.app helper app of Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A specially crafted library can leverage…

CVSS 7.1 · High
evidence mentions
3
Buzz score
21.9
Vendor/product tagsBeta · best-effort

CVE-2024-41138

Published Dec 18, 2024

A library injection vulnerability exists in the com.microsoft.teams2.modulehost.app helper app of Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A specially craf…

CVSS 7.1 · High
evidence mentions
3
Buzz score
21.9
Vendor/product tagsBeta · best-effort

CVE-2024-38197

Published Aug 13, 2024

Microsoft Teams for iOS Spoofing Vulnerability

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2023-4863

Published Sep 12, 2023

Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML pa…

CVSS 8.8 · High
evidence mentions
30
Buzz score
72.5
KEV listed

CVE-2023-29330

Published Aug 8, 2023

Microsoft Teams Remote Code Execution Vulnerability

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-29328

Published Aug 8, 2023

Microsoft Teams Remote Code Execution Vulnerability

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-21965

Published Feb 9, 2022

Microsoft Teams Denial of Service Vulnerability

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-24114

Published Feb 25, 2021

Microsoft Teams iOS Information Disclosure Vulnerability

CVSS 5.7 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-10146

Published Dec 9, 2020

The Microsoft Teams online service contains a stored cross-site scripting vulnerability in the displayName parameter that can be exploited on Teams clients to obtain sensitive inf…

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-5922

Published Mar 12, 2019

Untrusted search path vulnerability in The installer of Microsoft Teams allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-23 of 23 CVEsPage 1 of 1