VYPR

Exchange Server

by Microsoft

CVEs (259)

  • CVE-2023-35368HigAug 8, 2023
    risk 0.57cvss 8.8epss 0.02

    Microsoft Exchange Remote Code Execution Vulnerability

  • CVE-2018-16793HigSep 21, 2018
    risk 0.57cvss 8.6epss 0.11

    Rollup 18 for Microsoft Exchange Server 2010 SP3 and previous versions has an SSRF vulnerability via the username parameter in /owa/auth/logon.aspx in the OWA (Outlook Web Access) login page.

  • CVE-2020-17084HigNov 11, 2020
    risk 0.56cvss 8.5epss 0.04

    Microsoft Exchange Server Remote Code Execution Vulnerability

  • CVE-2025-53782HigOct 14, 2025
    risk 0.55cvss 8.4epss 0.00

    Incorrect implementation of authentication algorithm in Microsoft Exchange Server allows an unauthorized attacker to elevate privileges locally.

  • CVE-2023-36050HigNov 14, 2023
    risk 0.55cvss 8.0epss 0.39

    Microsoft Exchange Server Spoofing Vulnerability

  • CVE-2020-17141HigDec 10, 2020
    risk 0.55cvss 8.4epss 0.07

    Microsoft Exchange Remote Code Execution Vulnerability

  • CVE-2023-28310HigJun 14, 2023
    risk 0.54cvss 8.0epss 0.25

    Microsoft Exchange Server Remote Code Execution Vulnerability

  • CVE-2026-69380HigSep 8, 2026
    risk 0.53cvss 8.1epss 0.01

    Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-55007HigSep 8, 2026
    risk 0.53cvss 8.1epss 0.01

    Double free in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network.

  • CVE-2026-47631HigJun 9, 2026
    risk 0.53cvss 8.1epss 0.00

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2026-45503HigJun 9, 2026
    risk 0.53cvss 8.1epss 0.00

    Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to disclose information over a network.

  • CVE-2025-53786HigAug 6, 2025
    risk 0.53cvss 8.0epss 0.08

    On April 18th 2025, Microsoft announced Exchange Server Security Changes for Hybrid Deployments and accompanying non-security Hot Fix. Microsoft made these changes in the general interest of improving the security of hybrid Exchange deployments. Following further investigation,…

  • CVE-2023-35388HigAug 8, 2023
    risk 0.53cvss 8.0epss 0.07

    Microsoft Exchange Server Remote Code Execution Vulnerability

  • CVE-2022-21978HigMay 10, 2022
    risk 0.53cvss 8.2epss 0.01

    Microsoft Exchange Server Elevation of Privilege Vulnerability

  • CVE-2020-0692HigFeb 11, 2020
    risk 0.53cvss 8.1epss 0.03

    An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka 'Microsoft Exchange Server Elevation of Privilege Vulnerability'.

  • CVE-2019-1136HigJul 15, 2019
    risk 0.53cvss 8.1epss 0.03

    An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka 'Microsoft Exchange Server Elevation of Privilege Vulnerability'.

  • CVE-2017-11932HigDec 12, 2017
    risk 0.53cvss 8.1epss 0.06

    Microsoft Exchange Server 2016 CU5 and Microsoft Exchange Server 2016 CU5 allow a spoofing vulnerability due to the way Outlook Web Access (OWA) validates web requests, aka "Microsoft Exchange Spoofing Vulnerability".

  • CVE-2017-11937HigDec 7, 2017
    risk 0.53cvss 7.8epss 0.28

    The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Windows 7 SP1, Windows 8.1, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, 1709 and Windows Server 2016, Windows Server, version 1709, Microsoft Exchange Server 2013 and…

  • CVE-2026-62911HigAug 11, 2026
    risk 0.52cvss 8.0epss 0.01

    Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

  • CVE-2023-36439HigNov 14, 2023
    risk 0.52cvss 8.0epss 0.05

    Microsoft Exchange Server Remote Code Execution Vulnerability

Page 4 of 13