Known vulnerabilities in Microsoft Office 2013

Vendor: Microsoft
Version: 2013
Software CPE: cpe:2.3:a:microsoft:microsoft_office:*:*:*:*:*:*:*:*
Total vulnerabilities: 190
Public exploits: 17
Known exploited (KEV): 22
Highest CVSSv4 Score: 9.3

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting Microsoft Office version 2013 Microsoft Office 2013 is affected by 190 vulnerabilities: 17 critical, 129 high, 14 medium, 30 low Critical High Medium Low

Vulnerabilities (190)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU80655 - Exposure of sensitive information to an unauthorized actor
CVE-2023-36761
CWE-200 High
No
Exploited
- 12.09.2023 SB2023091249
#VU79575 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVE-2023-36769
CWE-451 Medium
No
No
- 16.08.2023 SB2023081611
#VU79148 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVE-2023-36893
CWE-451 Medium
No
No
- 08.08.2023 SB2023080866
#VU78099 - Improper input validation
CVE-2023-36884
CWE-20 Critical
Public exploit available
Exploited
- 11.07.2023 SB2023071170
#VU78096 - Improper input validation
CVE-2023-35311
CWE-20 Critical
No
Exploited
- 11.07.2023 SB2023071167
#VU73573 - Improper input validation
CVE-2023-23399
CWE-20 High
Public exploit available
No
- 14.03.2023 SB2023031456
#VU73511 - Exposure of sensitive information to an unauthorized actor
CVE-2023-23397
CWE-200 Critical
Public exploit available
Exploited
- 14.03.2023 SB2023031428
#VU72192 - Memory corruption
CVE-2023-21716
CWE-119 High
Public exploit available
Exploited
- 14.02.2023 SB2023021433
#VU60408 - Exposure of sensitive information to an unauthorized actor
CVE-2022-23252
CWE-200 Low
No
No
- 08.02.2022 SB2022020836
#VU60394 - Improper Control of Generation of Code ('Code Injection')
CVE-2022-22004
CWE-94 High
No
No
- 08.02.2022 SB2022020832
#VU60393 - Improper Control of Generation of Code ('Code Injection')
CVE-2022-22003
CWE-94 High
No
No
- 08.02.2022 SB2022020831
#VU59477 - Memory corruption
CVE-2022-21841
CWE-119 High
No
No
- 11.01.2022 SB2022011160
#VU59476 - Improper Control of Generation of Code ('Code Injection')
CVE-2022-21840
CWE-94 High
No
No
- 11.01.2022 SB2022011159
#VU58949 - Exposure of sensitive information to an unauthorized actor
CVE-2021-42295
CWE-200 Low
No
No
- 14.12.2021 SB2021121470
#VU58948 - Permissions, Privileges, and Access Controls
CVE-2021-42293
CWE-264 Medium
No
No
- 14.12.2021 SB2021121469
#VU58926 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVE-2021-43255
CWE-451 Low
No
No
- 14.12.2021 SB2021121454
#VU58064 - Improper Control of Generation of Code ('Code Injection')
CVE-2021-41368
CWE-94 High
No
No
- 09.11.2021 SB2021110936
#VU58058 - Improper input validation
CVE-2021-42292
CWE-20 Critical
No
Exploited
- 09.11.2021 SB2021110931
#VU57300 - Exposure of sensitive information to an unauthorized actor
CVE-2021-40454
CWE-200 Low
No
No
- 12.10.2021 SB2021101241
SB2022111615
#VU57267 - Exposure of sensitive information to an unauthorized actor
CVE-2021-40472
CWE-200 Low
No
No
- 12.10.2021 SB2021101217


Showing elements 1 - 20 out of 190