Exchange Server
by Microsoft
CVEs (250)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-33766 | Hig | 0.67 | 7.3 | 0.98 | KEV | Jul 14, 2021 | Microsoft Exchange Server Information Disclosure Vulnerability | |
| CVE-2021-28481 | Cri | 0.67 | 9.8 | 0.36 | Apr 13, 2021 | Microsoft Exchange Server Remote Code Execution Vulnerability | ||
| CVE-2018-8302 | Cri | 0.66 | 9.8 | 0.26 | Aug 15, 2018 | A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka "Microsoft Exchange Memory Corruption Vulnerability." This affects Microsoft Exchange Server. | ||
| CVE-2019-1373 | Cri | 0.65 | 9.8 | 0.18 | Nov 12, 2019 | A remote code execution vulnerability exists in Microsoft Exchange through the deserialization of metadata via PowerShell, aka 'Microsoft Exchange Remote Code Execution Vulnerability'. | ||
| CVE-2019-0586 | Cri | 0.65 | 9.8 | 0.15 | Jan 8, 2019 | A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka "Microsoft Exchange Memory Corruption Vulnerability." This affects Microsoft Exchange Server. | ||
| CVE-2018-8154 | Cri | 0.65 | 9.8 | 0.23 | May 9, 2018 | A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka "Microsoft Exchange Memory Corruption Vulnerability." This affects Microsoft Exchange Server. This CVE ID is unique from CVE-2018-8151. | ||
| CVE-2018-0986 | Hig | 0.65 | 8.8 | 0.63 | Apr 4, 2018 | A remote code execution vulnerability exists when the Microsoft Malware Protection Engine does not properly scan a specially crafted file, leading to memory corruption, aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability." This affects Windows Defender,… | ||
| CVE-2023-21709 | Cri | 0.64 | 9.8 | 0.02 | Aug 8, 2023 | Microsoft Exchange Server Elevation of Privilege Vulnerability | ||
| CVE-2023-32031 | Hig | 0.64 | 8.8 | 0.81 | Jun 14, 2023 | Microsoft Exchange Server Remote Code Execution Vulnerability | ||
| CVE-2023-21707 | Hig | 0.64 | 8.8 | 0.82 | Feb 14, 2023 | Microsoft Exchange Server Remote Code Execution Vulnerability | ||
| CVE-2021-28482 | Hig | 0.64 | 8.8 | 0.83 | Apr 13, 2021 | Microsoft Exchange Server Remote Code Execution Vulnerability | ||
| CVE-2022-23277 | Hig | 0.63 | 8.8 | 0.40 | Mar 9, 2022 | Microsoft Exchange Server Remote Code Execution Vulnerability | ||
| CVE-2021-31196 | Hig | 0.63 | 7.2 | 0.54 | KEV | Jul 14, 2021 | Microsoft Exchange Server Remote Code Execution Vulnerability | |
| CVE-2020-17143 | Hig | 0.63 | 8.8 | 0.71 | Dec 10, 2020 | Microsoft Exchange Server Information Disclosure Vulnerability | ||
| CVE-2021-26412 | Cri | 0.62 | 9.1 | 0.30 | Mar 3, 2021 | Microsoft Exchange Server Remote Code Execution Vulnerability | ||
| CVE-2021-27078 | Cri | 0.61 | 9.1 | 0.18 | Mar 3, 2021 | Microsoft Exchange Server Remote Code Execution Vulnerability | ||
| CVE-2020-16875 | Hig | 0.61 | 8.4 | 0.47 | Sep 11, 2020 | A remote code execution vulnerability exists in Microsoft Exchange server due to improper validation of cmdlet arguments. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the System user. Exploitation of the… | ||
| CVE-2023-36035 | Hig | 0.59 | 8.0 | 0.87 | Nov 14, 2023 | Microsoft Exchange Server Spoofing Vulnerability | ||
| CVE-2023-36744 | Hig | 0.59 | 8.0 | 0.82 | Sep 12, 2023 | Microsoft Exchange Server Remote Code Execution Vulnerability | ||
| CVE-2022-21969 | Cri | 0.59 | 9.0 | 0.01 | Jan 11, 2022 | Microsoft Exchange Server Remote Code Execution Vulnerability |
- risk 0.67cvss 7.3epss 0.98
Microsoft Exchange Server Information Disclosure Vulnerability
- risk 0.67cvss 9.8epss 0.36
Microsoft Exchange Server Remote Code Execution Vulnerability
- risk 0.66cvss 9.8epss 0.26
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka "Microsoft Exchange Memory Corruption Vulnerability." This affects Microsoft Exchange Server.
- risk 0.65cvss 9.8epss 0.18
A remote code execution vulnerability exists in Microsoft Exchange through the deserialization of metadata via PowerShell, aka 'Microsoft Exchange Remote Code Execution Vulnerability'.
- risk 0.65cvss 9.8epss 0.15
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka "Microsoft Exchange Memory Corruption Vulnerability." This affects Microsoft Exchange Server.
- risk 0.65cvss 9.8epss 0.23
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka "Microsoft Exchange Memory Corruption Vulnerability." This affects Microsoft Exchange Server. This CVE ID is unique from CVE-2018-8151.
- risk 0.65cvss 8.8epss 0.63
A remote code execution vulnerability exists when the Microsoft Malware Protection Engine does not properly scan a specially crafted file, leading to memory corruption, aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability." This affects Windows Defender,…
- risk 0.64cvss 9.8epss 0.02
Microsoft Exchange Server Elevation of Privilege Vulnerability
- risk 0.64cvss 8.8epss 0.81
Microsoft Exchange Server Remote Code Execution Vulnerability
- risk 0.64cvss 8.8epss 0.82
Microsoft Exchange Server Remote Code Execution Vulnerability
- risk 0.64cvss 8.8epss 0.83
Microsoft Exchange Server Remote Code Execution Vulnerability
- risk 0.63cvss 8.8epss 0.40
Microsoft Exchange Server Remote Code Execution Vulnerability
- risk 0.63cvss 7.2epss 0.54
Microsoft Exchange Server Remote Code Execution Vulnerability
- risk 0.63cvss 8.8epss 0.71
Microsoft Exchange Server Information Disclosure Vulnerability
- risk 0.62cvss 9.1epss 0.30
Microsoft Exchange Server Remote Code Execution Vulnerability
- risk 0.61cvss 9.1epss 0.18
Microsoft Exchange Server Remote Code Execution Vulnerability
- risk 0.61cvss 8.4epss 0.47
A remote code execution vulnerability exists in Microsoft Exchange server due to improper validation of cmdlet arguments. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the System user. Exploitation of the…
- risk 0.59cvss 8.0epss 0.87
Microsoft Exchange Server Spoofing Vulnerability
- risk 0.59cvss 8.0epss 0.82
Microsoft Exchange Server Remote Code Execution Vulnerability
- risk 0.59cvss 9.0epss 0.01
Microsoft Exchange Server Remote Code Execution Vulnerability
Page 2 of 13