Total
239 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-53786 | 1 Microsoft | 1 Exchange Server | 2026-02-27 | N/A | 8.0 HIGH |
|
On April 18th 2025, Microsoft announced Exchange Server Security Changes for Hybrid Deployments and accompanying non-security Hot Fix. Microsoft made these changes in the general interest of improving the security of hybrid Exchange deployments. Following further investigation, Microsoft identified specific security implications tied to the guidance and configuration steps outlined in the April announcement. Microsoft is issuing CVE-2025-53786 to document a vulnerability that is addressed by tak ...
Show More |
|||||
| CVE-2021-1730 | 1 Microsoft | 1 Exchange Server | 2026-02-24 | 5.8 MEDIUM | 5.4 MEDIUM |
|
<p>A spoofing vulnerability exists in Microsoft Exchange Server which could result in an attack that would allow a malicious actor to impersonate the user.</p>
<p>This update addresses this vulnerability.</p>
<p>To prevent these types of attacks, Microsoft recommends customers to download inline images from different DNSdomains than the rest of OWA. Please see further instructions in the FAQ to put in place this mitigations.</p>
|
|||||
| CVE-2020-16969 | 1 Microsoft | 1 Exchange Server | 2026-02-23 | 4.3 MEDIUM | 7.1 HIGH |
|
<p>An information disclosure vulnerability exists in how Microsoft Exchange validates tokens when handling certain messages. An attacker who successfully exploited the vulnerability could use this to gain further information from a user.</p>
<p>To exploit the vulnerability, an attacker could include specially crafted OWA messages that could be loaded, without warning or filtering, from the attacker-controlled URL. This callback vector provides an information disclosure tactic used in web beacons ...
Show More |
|||||
| CVE-2020-16875 | 1 Microsoft | 1 Exchange Server | 2026-02-23 | 9.0 HIGH | 8.4 HIGH |
|
<p>A remote code execution vulnerability exists in Microsoft Exchange server due to improper validation of cmdlet arguments.</p>
<p>An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the System user. Exploitation of the vulnerability requires an authenticated user in a certain Exchange role to be compromised.</p>
<p>The security update addresses the vulnerability by correcting how Microsoft Exchange handles cmdlet arguments.</p>
|
|||||
| CVE-2026-21527 | 1 Microsoft | 1 Exchange Server | 2026-02-11 | N/A | 6.5 MEDIUM |
|
User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
|
|||||
| CVE-2025-64667 | 1 Microsoft | 1 Exchange Server | 2026-01-02 | N/A | 5.3 MEDIUM |
|
User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
|
|||||
| CVE-2025-64666 | 1 Microsoft | 1 Exchange Server | 2026-01-02 | N/A | 7.5 HIGH |
|
Improper input validation in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
|
|||||
| CVE-2021-26855 | 1 Microsoft | 1 Exchange Server | 2025-10-30 | 7.5 HIGH | 9.1 CRITICAL |
|
Microsoft Exchange Server Remote Code Execution Vulnerability
|
|||||
| CVE-2021-26857 | 1 Microsoft | 1 Exchange Server | 2025-10-30 | 6.8 MEDIUM | 7.8 HIGH |
|
Microsoft Exchange Server Remote Code Execution Vulnerability
|
|||||
| CVE-2021-26858 | 1 Microsoft | 1 Exchange Server | 2025-10-30 | 6.8 MEDIUM | 7.8 HIGH |
|
Microsoft Exchange Server Remote Code Execution Vulnerability
|
|||||
| CVE-2021-27065 | 1 Microsoft | 1 Exchange Server | 2025-10-30 | 6.8 MEDIUM | 7.8 HIGH |
|
Microsoft Exchange Server Remote Code Execution Vulnerability
|
|||||
| CVE-2021-31207 | 1 Microsoft | 1 Exchange Server | 2025-10-30 | 6.5 MEDIUM | 6.6 MEDIUM |
|
Microsoft Exchange Server Security Feature Bypass Vulnerability
|
|||||
| CVE-2022-41080 | 1 Microsoft | 1 Exchange Server | 2025-10-30 | N/A | 8.8 HIGH |
|
Microsoft Exchange Server Elevation of Privilege Vulnerability
|
|||||
| CVE-2022-41082 | 1 Microsoft | 1 Exchange Server | 2025-10-30 | N/A | 8.0 HIGH |
|
Microsoft Exchange Server Remote Code Execution Vulnerability
|
|||||
| CVE-2022-41040 | 1 Microsoft | 1 Exchange Server | 2025-10-30 | N/A | 8.8 HIGH |
|
Microsoft Exchange Server Elevation of Privilege Vulnerability
|
|||||
| CVE-2021-42321 | 1 Microsoft | 1 Exchange Server | 2025-10-30 | 6.5 MEDIUM | 8.8 HIGH |
|
Microsoft Exchange Server Remote Code Execution Vulnerability
|
|||||
| CVE-2021-34523 | 1 Microsoft | 1 Exchange Server | 2025-10-30 | 7.5 HIGH | 9.0 CRITICAL |
|
Microsoft Exchange Server Elevation of Privilege Vulnerability
|
|||||
| CVE-2021-31196 | 1 Microsoft | 1 Exchange Server | 2025-10-29 | 6.5 MEDIUM | 7.2 HIGH |
|
Microsoft Exchange Server Remote Code Execution Vulnerability
|
|||||
| CVE-2021-33766 | 1 Microsoft | 1 Exchange Server | 2025-10-29 | 5.0 MEDIUM | 7.3 HIGH |
|
Microsoft Exchange Server Information Disclosure Vulnerability
|
|||||
| CVE-2021-34473 | 1 Microsoft | 1 Exchange Server | 2025-10-29 | 10.0 HIGH | 9.1 CRITICAL |
|
Microsoft Exchange Server Remote Code Execution Vulnerability
|
|||||
| CVE-2020-0688 | 1 Microsoft | 1 Exchange Server | 2025-10-29 | 9.0 HIGH | 8.8 HIGH |
|
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka 'Microsoft Exchange Memory Corruption Vulnerability'.
|
|||||
| CVE-2020-17144 | 1 Microsoft | 1 Exchange Server | 2025-10-29 | 6.0 MEDIUM | 8.4 HIGH |
|
Microsoft Exchange Remote Code Execution Vulnerability
|
|||||
| CVE-2025-59248 | 1 Microsoft | 1 Exchange Server | 2025-10-28 | N/A | 7.5 HIGH |
|
Improper input validation in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
|
|||||
| CVE-2025-59249 | 1 Microsoft | 1 Exchange Server | 2025-10-28 | N/A | 8.8 HIGH |
|
Weak authentication in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
|
|||||
| CVE-2024-21410 | 1 Microsoft | 1 Exchange Server | 2025-10-28 | N/A | 9.8 CRITICAL |
|
Microsoft Exchange Server Elevation of Privilege Vulnerability
|
|||||
| CVE-2018-8581 | 1 Microsoft | 1 Exchange Server | 2025-10-28 | 5.8 MEDIUM | 7.4 HIGH |
|
An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka "Microsoft Exchange Server Elevation of Privilege Vulnerability." This affects Microsoft Exchange Server.
|
|||||
| CVE-2025-53782 | 1 Microsoft | 1 Exchange Server | 2025-10-27 | N/A | 8.4 HIGH |
|
Incorrect implementation of authentication algorithm in Microsoft Exchange Server allows an unauthorized attacker to elevate privileges locally.
|
|||||
| CVE-2017-8540 | 1 Microsoft | 19 Endpoint Protection, Exchange Server, Forefront Endpoint Protection and 16 more | 2025-10-22 | 9.3 HIGH | 7.8 HIGH |
|
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, Microsoft Exchange Server 2013 and 2016, does not properly scan a specially crafted file leading to memory corruption. aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability", a different vulner ...
Show More |
|||||
| CVE-2025-25007 | 1 Microsoft | 1 Exchange Server | 2025-09-03 | N/A | 5.3 MEDIUM |
|
Improper validation of syntactic correctness of input in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
|
|||||
| CVE-2025-25006 | 1 Microsoft | 1 Exchange Server | 2025-09-03 | N/A | 5.3 MEDIUM |
|
Improper handling of additional special element in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
|
|||||
| CVE-2025-33051 | 1 Microsoft | 1 Exchange Server | 2025-09-03 | N/A | 7.5 HIGH |
|
Exposure of sensitive information to an unauthorized actor in Microsoft Exchange Server allows an unauthorized attacker to disclose information over a network.
|
|||||
| CVE-2020-17143 | 1 Microsoft | 1 Exchange Server | 2025-08-28 | 6.5 MEDIUM | 8.8 HIGH |
|
Microsoft Exchange Server Information Disclosure Vulnerability
|
|||||
| CVE-2020-17142 | 1 Microsoft | 1 Exchange Server | 2025-08-28 | 6.5 MEDIUM | 9.1 CRITICAL |
|
Microsoft Exchange Remote Code Execution Vulnerability
|
|||||
| CVE-2020-17141 | 1 Microsoft | 1 Exchange Server | 2025-08-28 | 6.0 MEDIUM | 8.4 HIGH |
|
Microsoft Exchange Remote Code Execution Vulnerability
|
|||||
| CVE-2020-17132 | 1 Microsoft | 1 Exchange Server | 2025-08-28 | 6.5 MEDIUM | 9.1 CRITICAL |
|
Microsoft Exchange Remote Code Execution Vulnerability
|
|||||
| CVE-2020-17117 | 1 Microsoft | 1 Exchange Server | 2025-08-28 | 9.0 HIGH | 6.6 MEDIUM |
|
Microsoft Exchange Remote Code Execution Vulnerability
|
|||||
| CVE-2025-25005 | 1 Microsoft | 1 Exchange Server | 2025-08-21 | N/A | 6.5 MEDIUM |
|
Improper input validation in Microsoft Exchange Server allows an authorized attacker to perform tampering over a network.
|
|||||
| CVE-2022-34692 | 1 Microsoft | 1 Exchange Server | 2025-06-05 | N/A | 5.3 MEDIUM |
|
Microsoft Exchange Server Information Disclosure Vulnerability
|
|||||
| CVE-2017-8537 | 1 Microsoft | 13 Endpoint Protection, Exchange Server, Forefront Endpoint Protection and 10 more | 2025-04-20 | 4.3 MEDIUM | 5.5 MEDIUM |
|
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, Microsoft Exchange Server 2013 and 2016, does not properly scan a specially crafted file leading to denial of service. aka "Microsoft Malware Protection Engine Denial of Service Vulnerability", a different vulnerabil ...
Show More |
|||||
| CVE-2017-8536 | 1 Microsoft | 13 Endpoint Protection, Exchange Server, Forefront Endpoint Protection and 10 more | 2025-04-20 | 4.3 MEDIUM | 5.5 MEDIUM |
|
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, Microsoft Exchange Server 2013 and 2016, does not properly scan a specially crafted file leading to denial of service. aka "Microsoft Malware Protection Engine Denial of Service Vulnerability", a different vulnerabil ...
Show More |
|||||