VYPR

Exchange Server Subscription Edition

by Microsoft

CVEs (28)

  • CVE-2025-64667MedDec 9, 2025
    risk 0.35cvss 5.3epss 0.01

    User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2025-25007MedAug 12, 2025
    risk 0.35cvss 5.3epss 0.01

    Improper validation of syntactic correctness of input in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2025-25006MedAug 12, 2025
    risk 0.35cvss 5.3epss 0.01

    Improper handling of additional special element in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2026-45502MedJun 9, 2026
    risk 0.33cvss 5.0epss 0.20

    Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to disclose information over a network.

  • CVE-2026-55009HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.02

    Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.

  • CVE-2026-55008CriJul 14, 2026
    risk 0.00cvss 9.6epss 0.01

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2026-55006HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Insufficient granularity of access control in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.

  • CVE-2026-55005HigJul 14, 2026
    risk 0.00cvss 8.8epss 0.01

    Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network.

Page 2 of 2