CVE Tools

Onedrive

16 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Onedrive, a product in the cloud saas space. Use it to gauge the current risk picture and drill into individual advisories.

Onedrive CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Onedrive CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-071
2025-080
2025-090
2025-100
2025-111
2025-120
2026-010
2026-020
2026-030
2026-040
2026-050
2026-060
2026-070
2026-081
2026-090

Severity

How the 16 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical16%
  • High850%
  • Medium744%

Latest CVEs

The 15 most recently published vulnerabilities affecting Onedrive.

  1. CVE-2026-65680Microsoft OneDrive for MacOS Elevation of Privilege Vulnerability6.7
  2. CVE-2025-60722Microsoft OneDrive for Android Elevation of Privilege Vulnerability6.5
  3. BDU:2025-08829Уязвимость службы размещения файлов OneDrive для операционной системы macOS, связанная с небезопасным управлением привилегиями, позволяющая нарушителю повысить свои привилегии до уровня root-пользователя7.8
  4. CVE-2023-24890Microsoft OneDrive for iOS Security Feature Bypass Vulnerability6.5
  5. CVE-2023-24930Microsoft OneDrive for MacOS Elevation of Privilege Vulnerability7.8
  6. CVE-2023-24882Microsoft OneDrive for Android Information Disclosure Vulnerability5.5
  7. CVE-2023-24923Microsoft OneDrive for Android Information Disclosure Vulnerability5.5
  8. CVE-2022-23255Microsoft OneDrive for Android Security Feature Bypass Vulnerability5.9
  9. CVE-2020-16853OneDrive for Windows Elevation of Privilege Vulnerability7.1
  10. CVE-2020-16851OneDrive for Windows Elevation of Privilege Vulnerability7.1
  11. CVE-2020-16852OneDrive for Windows Elevation of Privilege Vulnerability7.1
  12. CVE-2020-1465An elevation of privilege vulnerability exists in Microsoft OneDrive that allows file deletion in arbitrary locations.To exploit the vulnerability, an attacker would first have to log on to the sys...7.8
  13. CVE-2020-0935An elevation of privilege vulnerability exists when the OneDrive for Windows Desktop application improperly handles symbolic links, aka 'OneDrive for Windows Elevation of Privilege Vulnerability'.5.5
  14. CVE-2020-0654A security feature bypass vulnerability exists in Microsoft OneDrive App for Android.This could allow an attacker to bypass the passcode or fingerprint requirements of the App.The security update a...9.1
  15. CVE-2018-0593Untrusted search path vulnerability in the installer of Microsoft OneDrive allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.7.8

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store