Exchange Server
by Microsoft
CVEs (259)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-26854 | Med | 0.44 | 6.6 | 0.25 | Mar 3, 2021 | Microsoft Exchange Server Remote Code Execution Vulnerability | ||
| CVE-2026-21527 | Med | 0.43 | 6.5 | 0.08 | Feb 10, 2026 | User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2021-42305 | Med | 0.43 | 6.5 | 0.08 | Nov 10, 2021 | Microsoft Exchange Server Spoofing Vulnerability | ||
| CVE-2021-24085 | Med | 0.43 | 6.5 | 0.05 | Feb 25, 2021 | Microsoft Exchange Server Spoofing Vulnerability | ||
| CVE-2019-1084 | Med | 0.43 | 6.5 | 0.05 | Jul 15, 2019 | An information disclosure vulnerability exists when Exchange allows creation of entities with Display Names having non-printable characters. An authenticated attacker could exploit this vulnerability by creating entities with invalid display names, which, when added to… | ||
| CVE-2019-0588 | Med | 0.43 | 6.5 | 0.05 | Jan 8, 2019 | An information disclosure vulnerability exists when the Microsoft Exchange PowerShell API grants calendar contributors more view permissions than intended, aka "Microsoft Exchange Information Disclosure Vulnerability." This affects Microsoft Exchange Server. | ||
| CVE-2018-0940 | Med | 0.43 | 6.5 | 0.07 | Mar 14, 2018 | Microsoft Exchange Outlook Web Access (OWA) in Microsoft Exchange Server 2010 Service Pack 3 Update Rollup 20, Microsoft Exchange Server 2013 Cumulative Update 18, Microsoft Exchange Server 2013 Cumulative Update 19, Microsoft Exchange Server 2013 Service Pack 1, Microsoft… | ||
| CVE-2018-0924 | Med | 0.43 | 6.5 | 0.08 | Mar 14, 2018 | Microsoft Exchange Server 2010 Service Pack 3 Update Rollup 20, Microsoft Exchange Server 2013 Cumulative Update 18, Microsoft Exchange Server 2013 Cumulative Update 19, Microsoft Exchange Server 2013 Service Pack 1, Microsoft Exchange Server 2016 Cumulative Update 7, and… | ||
| CVE-2026-69375 | Med | 0.42 | 6.5 | 0.01 | Sep 8, 2026 | Authorization bypass through user-controlled key in Microsoft Exchange Server allows an authorized attacker to perform tampering over a network. | ||
| CVE-2026-69361 | Med | 0.42 | 6.5 | 0.01 | Sep 8, 2026 | Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network. | ||
| CVE-2026-65813 | Med | 0.42 | 6.5 | 0.01 | Aug 11, 2026 | Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-62915 | Med | 0.42 | 6.5 | 0.00 | Aug 11, 2026 | Missing authorization in Microsoft Exchange Server allows an authorized attacker to bypass a security feature over a network. | ||
| CVE-2026-62912 | Med | 0.42 | 6.5 | 0.01 | Aug 11, 2026 | Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to deny service over a network. | ||
| CVE-2026-45501 | Med | 0.42 | 6.5 | 0.00 | Jun 9, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2025-25005 | Med | 0.42 | 6.5 | 0.01 | Aug 12, 2025 | Improper input validation in Microsoft Exchange Server allows an authorized attacker to perform tampering over a network. | ||
| CVE-2022-30134 | Med | 0.42 | 6.5 | 0.02 | Aug 9, 2022 | Microsoft Exchange Server Information Disclosure Vulnerability | ||
| CVE-2021-41350 | Med | 0.42 | 6.5 | 0.02 | Oct 13, 2021 | Microsoft Exchange Server Spoofing Vulnerability | ||
| CVE-2021-31209 | Med | 0.42 | 6.5 | 0.03 | May 11, 2021 | Microsoft Exchange Server Spoofing Vulnerability | ||
| CVE-2020-17085 | Med | 0.41 | 6.2 | 0.04 | Nov 11, 2020 | Microsoft Exchange Server Denial of Service Vulnerability | ||
| CVE-2026-45500 | Med | 0.40 | 6.1 | 0.00 | Jun 9, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. |
- risk 0.44cvss 6.6epss 0.25
Microsoft Exchange Server Remote Code Execution Vulnerability
- risk 0.43cvss 6.5epss 0.08
User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
- risk 0.43cvss 6.5epss 0.08
Microsoft Exchange Server Spoofing Vulnerability
- risk 0.43cvss 6.5epss 0.05
Microsoft Exchange Server Spoofing Vulnerability
- risk 0.43cvss 6.5epss 0.05
An information disclosure vulnerability exists when Exchange allows creation of entities with Display Names having non-printable characters. An authenticated attacker could exploit this vulnerability by creating entities with invalid display names, which, when added to…
- risk 0.43cvss 6.5epss 0.05
An information disclosure vulnerability exists when the Microsoft Exchange PowerShell API grants calendar contributors more view permissions than intended, aka "Microsoft Exchange Information Disclosure Vulnerability." This affects Microsoft Exchange Server.
- risk 0.43cvss 6.5epss 0.07
Microsoft Exchange Outlook Web Access (OWA) in Microsoft Exchange Server 2010 Service Pack 3 Update Rollup 20, Microsoft Exchange Server 2013 Cumulative Update 18, Microsoft Exchange Server 2013 Cumulative Update 19, Microsoft Exchange Server 2013 Service Pack 1, Microsoft…
- risk 0.43cvss 6.5epss 0.08
Microsoft Exchange Server 2010 Service Pack 3 Update Rollup 20, Microsoft Exchange Server 2013 Cumulative Update 18, Microsoft Exchange Server 2013 Cumulative Update 19, Microsoft Exchange Server 2013 Service Pack 1, Microsoft Exchange Server 2016 Cumulative Update 7, and…
- risk 0.42cvss 6.5epss 0.01
Authorization bypass through user-controlled key in Microsoft Exchange Server allows an authorized attacker to perform tampering over a network.
- risk 0.42cvss 6.5epss 0.01
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.
- risk 0.42cvss 6.5epss 0.01
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
- risk 0.42cvss 6.5epss 0.00
Missing authorization in Microsoft Exchange Server allows an authorized attacker to bypass a security feature over a network.
- risk 0.42cvss 6.5epss 0.01
Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to deny service over a network.
- risk 0.42cvss 6.5epss 0.00
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
- risk 0.42cvss 6.5epss 0.01
Improper input validation in Microsoft Exchange Server allows an authorized attacker to perform tampering over a network.
- risk 0.42cvss 6.5epss 0.02
Microsoft Exchange Server Information Disclosure Vulnerability
- risk 0.42cvss 6.5epss 0.02
Microsoft Exchange Server Spoofing Vulnerability
- risk 0.42cvss 6.5epss 0.03
Microsoft Exchange Server Spoofing Vulnerability
- risk 0.41cvss 6.2epss 0.04
Microsoft Exchange Server Denial of Service Vulnerability
- risk 0.40cvss 6.1epss 0.00
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
Page 7 of 13