VYPR

Exchange Server

by Microsoft

CVEs (259)

  • CVE-2026-69378HigSep 8, 2026
    risk 0.49cvss 7.5epss 0.01

    Uncontrolled recursion in Microsoft Exchange Server allows an unauthorized attacker to deny service over a network.

  • CVE-2026-45583HigJun 9, 2026
    risk 0.49cvss 7.5epss 0.01

    Improper control of generation of code ('code injection') in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network.

  • CVE-2025-58107HigMar 2, 2026
    risk 0.49cvss 7.5epss 0.00

    In Microsoft Exchange through 2019, Exchange ActiveSync (EAS) configurations on on-premises servers may transmit sensitive data from Samsung mobile devices in cleartext, including the user's name, e-mail address, device ID, bearer token, and base64-encoded password.

  • CVE-2025-64666HigDec 9, 2025
    risk 0.49cvss 7.5epss 0.01

    Improper input validation in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

  • CVE-2025-59248HigOct 14, 2025
    risk 0.49cvss 7.5epss 0.01

    Improper input validation in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2025-33051HigAug 12, 2025
    risk 0.49cvss 7.5epss 0.01

    Exposure of sensitive information to an unauthorized actor in Microsoft Exchange Server allows an unauthorized attacker to disclose information over a network.

  • CVE-2024-49040HigNov 12, 2024
    risk 0.49cvss 7.5epss 0.08

    Microsoft Exchange Server Spoofing Vulnerability

  • CVE-2023-21761HigJan 10, 2023
    risk 0.49cvss 7.5epss 0.02

    Microsoft Exchange Server Information Disclosure Vulnerability

  • CVE-2021-34453HigOct 13, 2021
    risk 0.49cvss 7.5epss 0.03

    Microsoft Exchange Server Denial of Service Vulnerability

  • CVE-2019-1233HigSep 11, 2019
    risk 0.49cvss 7.5epss 0.06

    A denial of service vulnerability exists in Microsoft Exchange Server software when the software fails to properly handle objects in memory, aka 'Microsoft Exchange Denial of Service Vulnerability'.

  • CVE-2019-0686HigMar 5, 2019
    risk 0.49cvss 7.4epss 0.05

    An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka 'Microsoft Exchange Server Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0724.

  • CVE-2016-3378HigSep 14, 2016
    risk 0.49cvss 7.4epss 0.15

    Open redirect vulnerability in Microsoft Exchange Server 2013 SP1, 2013 Cumulative Update 12, 2013 Cumulative Update 13, 2016 Cumulative Update 1, and 2016 Cumulative Update 2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a…

  • CVE-2021-31195MedMay 11, 2021
    risk 0.48cvss 6.5epss 0.74

    Microsoft Exchange Server Remote Code Execution Vulnerability

  • CVE-2026-62914HigAug 11, 2026
    risk 0.47cvss 7.3epss 0.00

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.

  • CVE-2026-62910HigAug 11, 2026
    risk 0.47cvss 7.2epss 0.01

    Improper control of resource identifiers ('resource injection') in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

  • CVE-2023-21710HigFeb 14, 2023
    risk 0.47cvss 7.2epss 0.08

    Microsoft Exchange Server Remote Code Execution Vulnerability

  • CVE-2020-17117MedDec 10, 2020
    risk 0.47cvss 6.6epss 0.49

    Microsoft Exchange Remote Code Execution Vulnerability

  • CVE-2020-16969HigOct 16, 2020
    risk 0.46cvss 7.1epss 0.03

    An information disclosure vulnerability exists in how Microsoft Exchange validates tokens when handling certain messages. An attacker who successfully exploited the vulnerability could use this to gain further information from a user. To exploit the vulnerability, an…

  • CVE-2022-24463MedMar 9, 2022
    risk 0.45cvss 6.5epss 0.32

    Microsoft Exchange Server Spoofing Vulnerability

  • CVE-2023-36777MedSep 12, 2023
    risk 0.44cvss 5.7epss 0.52

    Microsoft Exchange Server Information Disclosure Vulnerability

Page 6 of 13