CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

microsoft

teams

19 known vulnerabilities · sorted by CVSS score

CVE-2023-29328
HIGH8.8

Microsoft Teams Remote Code Execution Vulnerability

microsoft / teams+3
Network
Published Aug 8, 2023
CVE-2023-29330
HIGH8.8

Microsoft Teams Remote Code Execution Vulnerability

microsoft / teams+3
Network
Published Aug 8, 2023
CVE-2023-4863
HIGH8.8

Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)

google / chrome+19
Network
Published Sep 12, 2023
CVE-2026-21535
HIGH8.2

Improper access control in Microsoft Teams allows an unauthorized attacker to disclose information over a network.

microsoft / teams
Network
Published Feb 19, 2026
CVE-2019-5922
HIGH7.8

Untrusted search path vulnerability in The installer of Microsoft Teams allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

microsoft / teams
Local
Published Mar 12, 2019
CVE-2020-17091
HIGH7.8

Microsoft Teams Remote Code Execution Vulnerability

microsoft / teams
Local
Published Nov 11, 2020
CVE-2022-21965
HIGH7.5

Microsoft Teams Denial of Service Vulnerability

microsoft / teams+2
Network
Published Feb 9, 2022
CVE-2025-53783
HIGH7.5

Heap-based buffer overflow in Microsoft Teams allows an unauthorized attacker to execute code over a network.

microsoft / dynamics_365_guides+7
Network
Published Aug 12, 2025
CVE-2024-42004
HIGH7.1

A library injection vulnerability exists in Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A specially crafted library can leverage Teams's access privileges, leading to a permission bypass. A malicious application could inject a library and start the program to trigger this vulnerability and then make use of the vulnerable application's permissions.

microsoft / teams
Local
Published Dec 18, 2024
CVE-2024-41145
HIGH7.1

A library injection vulnerability exists in the WebView.app helper app of Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A specially crafted library can leverage Teams's access privileges, leading to a permission bypass. A malicious application could inject a library and start the program to trigger this vulnerability and then make use of the vulnerable application's permissions.

microsoft / teams
Local
Published Dec 18, 2024
CVE-2024-41138
HIGH7.1

A library injection vulnerability exists in the com.microsoft.teams2.modulehost.app helper app of Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A specially crafted library can leverage Teams's access privileges, leading to a permission bypass. A malicious application could inject a library and start the program to trigger this vulnerability and then make use of the vulnerable application's permissions.

microsoft / teams
Local
Published Dec 18, 2024
CVE-2025-49737
HIGH7.0

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Teams allows an authorized attacker to elevate privileges locally.

microsoft / teams
Local
Published Jul 8, 2025
CVE-2024-38197
MEDIUM6.5

Microsoft Teams for iOS Spoofing Vulnerability

microsoft / teams
Network
Published Aug 13, 2024
CVE-2023-24881
MEDIUM6.5

Microsoft Teams Information Disclosure Vulnerability

microsoft / teams
Network
Published Jul 11, 2023
CVE-2021-24114
MEDIUM5.7

Microsoft Teams iOS Information Disclosure Vulnerability

microsoft / teams
Network
Published Feb 25, 2021
CVE-2020-10146
MEDIUM5.7

The Microsoft Teams online service contains a stored cross-site scripting vulnerability in the displayName parameter that can be exploited on Teams clients to obtain sensitive information such as authentication tokens and to possibly execute arbitrary commands. This vulnerability was fixed for all Teams users in the online service on or around October 2020.

microsoft / teams
Network
Published Dec 9, 2020
CVE-2024-21374
MEDIUM5.0

Microsoft Teams for Android Information Disclosure Vulnerability

microsoft / teams
Local
Published Feb 13, 2024
CVE-2024-21448
MEDIUM5.0

Microsoft Teams for Android Information Disclosure Vulnerability

microsoft / teams
Local
Published Mar 12, 2024
CVE-2025-49731
LOW3.1

Improper handling of insufficient permissions or privileges in Microsoft Teams allows an authorized attacker to elevate privileges over a network.

microsoft / teams+2
Network
Published Jul 8, 2025