Exchange Server
by Microsoft
CVEs (259)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-69378 | Hig | 0.49 | 7.5 | 0.01 | Sep 8, 2026 | Uncontrolled recursion in Microsoft Exchange Server allows an unauthorized attacker to deny service over a network. | ||
| CVE-2026-45583 | Hig | 0.49 | 7.5 | 0.01 | Jun 9, 2026 | Improper control of generation of code ('code injection') in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network. | ||
| CVE-2025-58107 | Hig | 0.49 | 7.5 | 0.00 | Mar 2, 2026 | In Microsoft Exchange through 2019, Exchange ActiveSync (EAS) configurations on on-premises servers may transmit sensitive data from Samsung mobile devices in cleartext, including the user's name, e-mail address, device ID, bearer token, and base64-encoded password. | ||
| CVE-2025-64666 | Hig | 0.49 | 7.5 | 0.01 | Dec 9, 2025 | Improper input validation in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2025-59248 | Hig | 0.49 | 7.5 | 0.01 | Oct 14, 2025 | Improper input validation in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2025-33051 | Hig | 0.49 | 7.5 | 0.01 | Aug 12, 2025 | Exposure of sensitive information to an unauthorized actor in Microsoft Exchange Server allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2024-49040 | Hig | 0.49 | 7.5 | 0.08 | Nov 12, 2024 | Microsoft Exchange Server Spoofing Vulnerability | ||
| CVE-2023-21761 | Hig | 0.49 | 7.5 | 0.02 | Jan 10, 2023 | Microsoft Exchange Server Information Disclosure Vulnerability | ||
| CVE-2021-34453 | Hig | 0.49 | 7.5 | 0.03 | Oct 13, 2021 | Microsoft Exchange Server Denial of Service Vulnerability | ||
| CVE-2019-1233 | Hig | 0.49 | 7.5 | 0.06 | Sep 11, 2019 | A denial of service vulnerability exists in Microsoft Exchange Server software when the software fails to properly handle objects in memory, aka 'Microsoft Exchange Denial of Service Vulnerability'. | ||
| CVE-2019-0686 | Hig | 0.49 | 7.4 | 0.05 | Mar 5, 2019 | An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka 'Microsoft Exchange Server Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0724. | ||
| CVE-2016-3378 | Hig | 0.49 | 7.4 | 0.15 | Sep 14, 2016 | Open redirect vulnerability in Microsoft Exchange Server 2013 SP1, 2013 Cumulative Update 12, 2013 Cumulative Update 13, 2016 Cumulative Update 1, and 2016 Cumulative Update 2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a… | ||
| CVE-2021-31195 | Med | 0.48 | 6.5 | 0.74 | May 11, 2021 | Microsoft Exchange Server Remote Code Execution Vulnerability | ||
| CVE-2026-62914 | Hig | 0.47 | 7.3 | 0.00 | Aug 11, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network. | ||
| CVE-2026-62910 | Hig | 0.47 | 7.2 | 0.01 | Aug 11, 2026 | Improper control of resource identifiers ('resource injection') in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2023-21710 | Hig | 0.47 | 7.2 | 0.08 | Feb 14, 2023 | Microsoft Exchange Server Remote Code Execution Vulnerability | ||
| CVE-2020-17117 | Med | 0.47 | 6.6 | 0.49 | Dec 10, 2020 | Microsoft Exchange Remote Code Execution Vulnerability | ||
| CVE-2020-16969 | Hig | 0.46 | 7.1 | 0.03 | Oct 16, 2020 | An information disclosure vulnerability exists in how Microsoft Exchange validates tokens when handling certain messages. An attacker who successfully exploited the vulnerability could use this to gain further information from a user. To exploit the vulnerability, an… | ||
| CVE-2022-24463 | Med | 0.45 | 6.5 | 0.32 | Mar 9, 2022 | Microsoft Exchange Server Spoofing Vulnerability | ||
| CVE-2023-36777 | Med | 0.44 | 5.7 | 0.52 | Sep 12, 2023 | Microsoft Exchange Server Information Disclosure Vulnerability |
- risk 0.49cvss 7.5epss 0.01
Uncontrolled recursion in Microsoft Exchange Server allows an unauthorized attacker to deny service over a network.
- risk 0.49cvss 7.5epss 0.01
Improper control of generation of code ('code injection') in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network.
- risk 0.49cvss 7.5epss 0.00
In Microsoft Exchange through 2019, Exchange ActiveSync (EAS) configurations on on-premises servers may transmit sensitive data from Samsung mobile devices in cleartext, including the user's name, e-mail address, device ID, bearer token, and base64-encoded password.
- risk 0.49cvss 7.5epss 0.01
Improper input validation in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
- risk 0.49cvss 7.5epss 0.01
Improper input validation in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
- risk 0.49cvss 7.5epss 0.01
Exposure of sensitive information to an unauthorized actor in Microsoft Exchange Server allows an unauthorized attacker to disclose information over a network.
- risk 0.49cvss 7.5epss 0.08
Microsoft Exchange Server Spoofing Vulnerability
- risk 0.49cvss 7.5epss 0.02
Microsoft Exchange Server Information Disclosure Vulnerability
- risk 0.49cvss 7.5epss 0.03
Microsoft Exchange Server Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.06
A denial of service vulnerability exists in Microsoft Exchange Server software when the software fails to properly handle objects in memory, aka 'Microsoft Exchange Denial of Service Vulnerability'.
- risk 0.49cvss 7.4epss 0.05
An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka 'Microsoft Exchange Server Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0724.
- risk 0.49cvss 7.4epss 0.15
Open redirect vulnerability in Microsoft Exchange Server 2013 SP1, 2013 Cumulative Update 12, 2013 Cumulative Update 13, 2016 Cumulative Update 1, and 2016 Cumulative Update 2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a…
- risk 0.48cvss 6.5epss 0.74
Microsoft Exchange Server Remote Code Execution Vulnerability
- risk 0.47cvss 7.3epss 0.00
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.
- risk 0.47cvss 7.2epss 0.01
Improper control of resource identifiers ('resource injection') in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
- risk 0.47cvss 7.2epss 0.08
Microsoft Exchange Server Remote Code Execution Vulnerability
- risk 0.47cvss 6.6epss 0.49
Microsoft Exchange Remote Code Execution Vulnerability
- risk 0.46cvss 7.1epss 0.03
An information disclosure vulnerability exists in how Microsoft Exchange validates tokens when handling certain messages. An attacker who successfully exploited the vulnerability could use this to gain further information from a user. To exploit the vulnerability, an…
- risk 0.45cvss 6.5epss 0.32
Microsoft Exchange Server Spoofing Vulnerability
- risk 0.44cvss 5.7epss 0.52
Microsoft Exchange Server Information Disclosure Vulnerability
Page 6 of 13