Exchange Server
by Microsoft
CVEs (250)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-34473 | Cri | 0.88 | 9.1 | 1.00 | KEV | Jul 14, 2021 | Microsoft Exchange Server Remote Code Execution Vulnerability | |
| CVE-2021-26855 | Cri | 0.88 | 9.1 | 1.00 | KEV | Mar 3, 2021 | Microsoft Exchange Server Remote Code Execution Vulnerability | |
| CVE-2021-34523 | Cri | 0.87 | 9.0 | 1.00 | KEV | Jul 14, 2021 | Microsoft Exchange Server Elevation of Privilege Vulnerability | |
| CVE-2022-41040 | Hig | 0.86 | 8.8 | 1.00 | KEV | Oct 3, 2022 | Microsoft Exchange Server Elevation of Privilege Vulnerability | |
| CVE-2020-0688 | Hig | 0.86 | 8.8 | 1.00 | KEV | Feb 11, 2020 | A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka 'Microsoft Exchange Memory Corruption Vulnerability'. | |
| CVE-2021-42321 | Hig | 0.85 | 8.8 | 0.90 | KEV | Nov 10, 2021 | Microsoft Exchange Server Remote Code Execution Vulnerability | |
| CVE-2022-41080 | Hig | 0.81 | 8.8 | 0.77 | KEV | Nov 9, 2022 | Microsoft Exchange Server Elevation of Privilege Vulnerability | |
| CVE-2022-41082 | Hig | 0.81 | 8.0 | 1.00 | KEV | Oct 3, 2022 | Microsoft Exchange Server Remote Code Execution Vulnerability | |
| CVE-2023-21529 | Hig | 0.80 | 8.8 | 0.62 | KEV | Feb 14, 2023 | Microsoft Exchange Server Remote Code Execution Vulnerability | |
| CVE-2021-27065 | Hig | 0.80 | 7.8 | 1.00 | KEV | Mar 3, 2021 | Microsoft Exchange Server Remote Code Execution Vulnerability | |
| CVE-2024-21410 | Cri | 0.77 | 9.8 | 0.13 | KEV | Feb 13, 2024 | Microsoft Exchange Server Elevation of Privilege Vulnerability | |
| CVE-2021-26858 | Hig | 0.76 | 7.8 | 0.90 | KEV | Mar 3, 2021 | Microsoft Exchange Server Remote Code Execution Vulnerability | |
| CVE-2021-26857 | Hig | 0.76 | 7.8 | 0.94 | KEV | Mar 3, 2021 | Microsoft Exchange Server Remote Code Execution Vulnerability | |
| CVE-2021-31207 | Med | 0.72 | 6.6 | 1.00 | KEV | May 11, 2021 | Microsoft Exchange Server Security Feature Bypass Vulnerability | |
| CVE-2017-8540 | Hig | 0.71 | 7.8 | 0.72 | KEV | May 26, 2017 | The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server… | |
| CVE-2026-42897 | Hig | 0.70 | 8.1 | 0.70 | KEV | May 14, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. | |
| CVE-2020-17144 | Hig | 0.70 | 8.4 | 0.37 | KEV | Dec 10, 2020 | Microsoft Exchange Remote Code Execution Vulnerability | |
| CVE-2021-28480 | Cri | 0.69 | 9.8 | 0.71 | Apr 13, 2021 | Microsoft Exchange Server Remote Code Execution Vulnerability | ||
| CVE-2020-17132 | Cri | 0.69 | 9.1 | 0.90 | Dec 10, 2020 | Microsoft Exchange Remote Code Execution Vulnerability | ||
| CVE-2018-8581 | Hig | 0.68 | 7.4 | 0.27 | KEV | Nov 14, 2018 | An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka "Microsoft Exchange Server Elevation of Privilege Vulnerability." This affects Microsoft Exchange Server. |
- risk 0.88cvss 9.1epss 1.00
Microsoft Exchange Server Remote Code Execution Vulnerability
- risk 0.88cvss 9.1epss 1.00
Microsoft Exchange Server Remote Code Execution Vulnerability
- risk 0.87cvss 9.0epss 1.00
Microsoft Exchange Server Elevation of Privilege Vulnerability
- risk 0.86cvss 8.8epss 1.00
Microsoft Exchange Server Elevation of Privilege Vulnerability
- risk 0.86cvss 8.8epss 1.00
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka 'Microsoft Exchange Memory Corruption Vulnerability'.
- risk 0.85cvss 8.8epss 0.90
Microsoft Exchange Server Remote Code Execution Vulnerability
- risk 0.81cvss 8.8epss 0.77
Microsoft Exchange Server Elevation of Privilege Vulnerability
- risk 0.81cvss 8.0epss 1.00
Microsoft Exchange Server Remote Code Execution Vulnerability
- risk 0.80cvss 8.8epss 0.62
Microsoft Exchange Server Remote Code Execution Vulnerability
- risk 0.80cvss 7.8epss 1.00
Microsoft Exchange Server Remote Code Execution Vulnerability
- risk 0.77cvss 9.8epss 0.13
Microsoft Exchange Server Elevation of Privilege Vulnerability
- risk 0.76cvss 7.8epss 0.90
Microsoft Exchange Server Remote Code Execution Vulnerability
- risk 0.76cvss 7.8epss 0.94
Microsoft Exchange Server Remote Code Execution Vulnerability
- risk 0.72cvss 6.6epss 1.00
Microsoft Exchange Server Security Feature Bypass Vulnerability
- risk 0.71cvss 7.8epss 0.72
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server…
- risk 0.70cvss 8.1epss 0.70
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
- risk 0.70cvss 8.4epss 0.37
Microsoft Exchange Remote Code Execution Vulnerability
- risk 0.69cvss 9.8epss 0.71
Microsoft Exchange Server Remote Code Execution Vulnerability
- risk 0.69cvss 9.1epss 0.90
Microsoft Exchange Remote Code Execution Vulnerability
- risk 0.68cvss 7.4epss 0.27
An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka "Microsoft Exchange Server Elevation of Privilege Vulnerability." This affects Microsoft Exchange Server.
Page 1 of 13