VYPR

Exchange Server

by Microsoft

CVEs (259)

  • CVE-2021-26854MedMar 3, 2021
    risk 0.44cvss 6.6epss 0.25

    Microsoft Exchange Server Remote Code Execution Vulnerability

  • CVE-2026-21527MedFeb 10, 2026
    risk 0.43cvss 6.5epss 0.08

    User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2021-42305MedNov 10, 2021
    risk 0.43cvss 6.5epss 0.08

    Microsoft Exchange Server Spoofing Vulnerability

  • CVE-2021-24085MedFeb 25, 2021
    risk 0.43cvss 6.5epss 0.05

    Microsoft Exchange Server Spoofing Vulnerability

  • CVE-2019-1084MedJul 15, 2019
    risk 0.43cvss 6.5epss 0.05

    An information disclosure vulnerability exists when Exchange allows creation of entities with Display Names having non-printable characters. An authenticated attacker could exploit this vulnerability by creating entities with invalid display names, which, when added to…

  • CVE-2019-0588MedJan 8, 2019
    risk 0.43cvss 6.5epss 0.05

    An information disclosure vulnerability exists when the Microsoft Exchange PowerShell API grants calendar contributors more view permissions than intended, aka "Microsoft Exchange Information Disclosure Vulnerability." This affects Microsoft Exchange Server.

  • CVE-2018-0940MedMar 14, 2018
    risk 0.43cvss 6.5epss 0.07

    Microsoft Exchange Outlook Web Access (OWA) in Microsoft Exchange Server 2010 Service Pack 3 Update Rollup 20, Microsoft Exchange Server 2013 Cumulative Update 18, Microsoft Exchange Server 2013 Cumulative Update 19, Microsoft Exchange Server 2013 Service Pack 1, Microsoft…

  • CVE-2018-0924MedMar 14, 2018
    risk 0.43cvss 6.5epss 0.08

    Microsoft Exchange Server 2010 Service Pack 3 Update Rollup 20, Microsoft Exchange Server 2013 Cumulative Update 18, Microsoft Exchange Server 2013 Cumulative Update 19, Microsoft Exchange Server 2013 Service Pack 1, Microsoft Exchange Server 2016 Cumulative Update 7, and…

  • CVE-2026-69375MedSep 8, 2026
    risk 0.42cvss 6.5epss 0.01

    Authorization bypass through user-controlled key in Microsoft Exchange Server allows an authorized attacker to perform tampering over a network.

  • CVE-2026-69361MedSep 8, 2026
    risk 0.42cvss 6.5epss 0.01

    Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.

  • CVE-2026-65813MedAug 11, 2026
    risk 0.42cvss 6.5epss 0.01

    Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-62915MedAug 11, 2026
    risk 0.42cvss 6.5epss 0.00

    Missing authorization in Microsoft Exchange Server allows an authorized attacker to bypass a security feature over a network.

  • CVE-2026-62912MedAug 11, 2026
    risk 0.42cvss 6.5epss 0.01

    Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to deny service over a network.

  • CVE-2026-45501MedJun 9, 2026
    risk 0.42cvss 6.5epss 0.00

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2025-25005MedAug 12, 2025
    risk 0.42cvss 6.5epss 0.01

    Improper input validation in Microsoft Exchange Server allows an authorized attacker to perform tampering over a network.

  • CVE-2022-30134MedAug 9, 2022
    risk 0.42cvss 6.5epss 0.02

    Microsoft Exchange Server Information Disclosure Vulnerability

  • CVE-2021-41350MedOct 13, 2021
    risk 0.42cvss 6.5epss 0.02

    Microsoft Exchange Server Spoofing Vulnerability

  • CVE-2021-31209MedMay 11, 2021
    risk 0.42cvss 6.5epss 0.03

    Microsoft Exchange Server Spoofing Vulnerability

  • CVE-2020-17085MedNov 11, 2020
    risk 0.41cvss 6.2epss 0.04

    Microsoft Exchange Server Denial of Service Vulnerability

  • CVE-2026-45500MedJun 9, 2026
    risk 0.40cvss 6.1epss 0.00

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

Page 7 of 13