VendorsMicrosoftexchange_serverall versions
Vulnerabilities

Microsoft Exchange Server

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

259CVEs
CVE-2022-21846
Microsoft Exchange Server Remote Code Execution Vulnerability
Published 2022-01-11 · Modified
9.0EPSS 0.011
CVE-2022-21855
Microsoft Exchange Server Remote Code Execution Vulnerability
Published 2022-01-11 · Modified
9.0EPSS 0.009
CVE-2022-41040
Microsoft Exchange Server Elevation of Privilege Vulnerability
Published 2022-10-03 · Analyzed
8.8KEVEPSS 1.000
CVE-2021-42321
Microsoft Exchange Server Remote Code Execution Vulnerability
Published 2021-11-10 · Analyzed
8.8KEVEPSS 0.917
CVE-2023-21707
Microsoft Exchange Server Remote Code Execution Vulnerability
Published 2023-02-14 · Modified
8.8EPSS 0.820
CVE-2023-32031
Microsoft Exchange Server Remote Code Execution Vulnerability
Published 2023-06-14 · Modified
8.8EPSS 0.815
CVE-2021-31195
Microsoft Exchange Server Remote Code Execution Vulnerability
Published 2021-05-11 · Modified
8.8EPSS 0.737
CVE-2020-17143
Microsoft Exchange Server Information Disclosure Vulnerability
Published 2020-12-09 · Modified
8.8EPSS 0.706
CVE-2023-21529
Microsoft Exchange Server Remote Code Execution Vulnerability
Published 2023-02-14 · Analyzed
8.8KEVEPSS 0.593
CVE-2022-23277
Microsoft Exchange Server Remote Code Execution Vulnerability
Published 2022-03-09 · Modified
8.8EPSS 0.411
CVE-2020-17144
Microsoft Exchange Remote Code Execution Vulnerability
Published 2020-12-09 · Analyzed
8.8KEVEPSS 0.365
CVE-2023-38181
Microsoft Exchange Server Spoofing Vulnerability
Published 2023-08-08 · Modified
8.8EPSS 0.108
CVE-2024-26198
Microsoft Exchange Server Remote Code Execution Vulnerability
Published 2024-03-12 · Analyzed
8.8EPSS 0.068
CVE-2023-21706
Microsoft Exchange Server Remote Code Execution Vulnerability
Published 2023-02-14 · Modified
8.8EPSS 0.041
CVE-2023-38185
Microsoft Exchange Server Remote Code Execution Vulnerability
Published 2023-08-08 · Modified
8.8EPSS 0.027
CVE-2023-35368
Microsoft Exchange Remote Code Execution Vulnerability
Published 2023-08-08 · Modified
8.8EPSS 0.025
CVE-2026-55005
Microsoft Exchange Server Remote Code Execution Vulnerability
Published 2026-07-14 · Analyzed
8.8EPSS 0.010
CVE-2026-62910
Microsoft Exchange Server Elevation of Privilege Vulnerability
Published 2026-08-11 · Analyzed
8.8EPSS 0.010
CVE-2026-65813
Microsoft Exchange Server Elevation of Privilege Vulnerability
Published 2026-08-11 · Analyzed
8.8EPSS 0.009
CVE-2026-62913
Microsoft Exchange Server Remote Code Execution Vulnerability
Published 2026-08-11 · Analyzed
8.8EPSS 0.009
CVE-2025-59249
Microsoft Exchange Server Elevation of Privilege Vulnerability
Published 2025-10-14 · Analyzed
8.8EPSS 0.008
CVE-2026-45504
Microsoft Exchange Server Elevation of Privilege Vulnerability
Published 2026-06-09 · Analyzed
8.8EPSS 0.008
CVE-2018-16793
Rollup 18 for Microsoft Exchange Server 2010 SP3 and previous versions has an SSRF vulnerability via the username parameter in /owa/auth/logon.aspx in the OWA (Outlook Web Access) login page.
Published 2018-09-21 · Modified
8.6EPSS 0.113
CVE-2020-17141
Microsoft Exchange Remote Code Execution Vulnerability
Published 2020-12-09 · Modified
8.4EPSS 0.066
CVE-2025-53782
Microsoft Exchange Server Elevation of Privilege Vulnerability
Published 2025-10-14 · Analyzed
8.4EPSS 0.004
CVE-2022-21978
Microsoft Exchange Server Elevation of Privilege Vulnerability
Published 2022-05-10 · Modified
8.2EPSS 0.008
CVE-2017-11932
Microsoft Exchange Server 2016 CU5 and Microsoft Exchange Server 2016 CU5 allow a spoofing vulnerability due to the way Outlook Web Access (OWA) validates web requests, aka "Microsoft Exchange Spoofing Vulnerability".
Published 2017-12-12 · Modified
8.1EPSS 0.059
CVE-2019-1136
An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka 'Microsoft Exchange Server Elevation of Privilege Vulnerability'.
Published 2019-07-29 · Modified
8.1EPSS 0.034
CVE-2020-0692
An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka 'Microsoft Exchange Server Elevation of Privilege Vulnerability'.
Published 2020-02-11 · Modified
8.1EPSS 0.033
CVE-2021-31209
Microsoft Exchange Server Spoofing Vulnerability
Published 2021-05-11 · Modified
8.1EPSS 0.026
CVE-2026-45503
Microsoft Exchange Server Information Disclosure Vulnerability
Published 2026-06-09 · Modified
8.1EPSS 0.009
CVE-2026-45583
Microsoft Exchange Server Remote Code Execution Vulnerability
Published 2026-06-09 · Analyzed
8.1EPSS 0.007
CVE-2026-42897
Microsoft Exchange Server Spoofing Vulnerability
Published 2026-05-14 · Analyzed
8.1KEVEPSS 0.005
CVE-2026-47631
Microsoft Exchange Server Spoofing Vulnerability
Published 2026-06-09 · Analyzed
8.1EPSS 0.005
CVE-2022-41082
Microsoft Exchange Server Remote Code Execution Vulnerability
Published 2022-10-03 · Analyzed
8.0KEVEPSS 1.000
CVE-2023-36035
Microsoft Exchange Server Spoofing Vulnerability
Published 2023-11-14 · Modified
8.0EPSS 0.866
CVE-2023-36745
Microsoft Exchange Server Remote Code Execution Vulnerability
Published 2023-09-12 · Modified
8.0EPSS 0.793
CVE-2023-36039
Microsoft Exchange Server Spoofing Vulnerability
Published 2023-11-14 · Modified
8.0EPSS 0.730
CVE-2023-36744
Microsoft Exchange Server Remote Code Execution Vulnerability
Published 2023-09-12 · Modified
8.0EPSS 0.571
CVE-2023-36756
Microsoft Exchange Server Remote Code Execution Vulnerability
Published 2023-09-12 · Modified
8.0EPSS 0.492
← Prev2 / 7Next →