VendorsMicrosoftexchange_server2013
Vulnerabilities

Microsoft Exchange Server 2013

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

109CVEs
CVE-2021-31209
Microsoft Exchange Server Spoofing Vulnerability
Published 2021-05-11 · Modified
8.1EPSS 0.026
CVE-2022-41082
Microsoft Exchange Server Remote Code Execution Vulnerability
Published 2022-10-03 · Analyzed
8.0KEVEPSS 1.000
CVE-2021-31206
Microsoft Exchange Server Remote Code Execution Vulnerability
Published 2021-07-14 · Modified
8.0EPSS 0.130
CVE-2021-34470
Microsoft Exchange Server Elevation of Privilege Vulnerability
Published 2021-07-14 · Modified
8.0EPSS 0.044
CVE-2022-21980
Microsoft Exchange Server Elevation of Privilege Vulnerability
Published 2022-08-09 · Modified
8.0EPSS 0.025
CVE-2022-24516
Microsoft Exchange Server Elevation of Privilege Vulnerability
Published 2022-08-09 · Modified
8.0EPSS 0.022
CVE-2022-24477
Microsoft Exchange Server Elevation of Privilege Vulnerability
Published 2022-08-09 · Modified
8.0EPSS 0.021
CVE-2023-21762
Microsoft Exchange Server Spoofing Vulnerability
Published 2023-01-10 · Modified
8.0EPSS 0.016
CVE-2022-41079
Microsoft Exchange Server Spoofing Vulnerability
Published 2022-11-09 · Modified
8.0EPSS 0.008
CVE-2022-41078
Microsoft Exchange Server Spoofing Vulnerability
Published 2022-11-09 · Modified
8.0EPSS 0.008
CVE-2021-27065
Microsoft Exchange Server Remote Code Execution Vulnerability
Published 2021-03-02 · Analyzed
7.8KEV1 PoCEPSS 0.999
CVE-2021-26857
Microsoft Exchange Server Remote Code Execution Vulnerability
Published 2021-03-02 · Analyzed
7.8KEVEPSS 0.958
CVE-2021-26858
Microsoft Exchange Server Remote Code Execution Vulnerability
Published 2021-03-02 · Analyzed
7.8KEVEPSS 0.937
CVE-2021-31198
Microsoft Exchange Server Remote Code Execution Vulnerability
Published 2021-05-11 · Modified
7.8EPSS 0.049
CVE-2021-3146
The Dolby Audio X2 (DAX2) API service before 0.8.8.90 on Windows allows local users to gain privileges.
Published 2021-04-08 · Modified
7.8EPSS 0.004
CVE-2021-33766
Microsoft Exchange Server Information Disclosure Vulnerability
Published 2021-07-14 · Analyzed
7.5KEVEPSS 0.981
CVE-2018-8581
An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka "Microsoft Exchange Server Elevation of Privilege Vulnerability." This affects Microsoft Exchange Server.
Published 2018-11-14 · Analyzed
7.4KEVEPSS 0.274
CVE-2016-3378
Open redirect vulnerability in Microsoft Exchange Server 2013 SP1, 2013 Cumulative Update 12, 2013 Cumulative Update 13, 2016 Cumulative Update 1, and 2016 Cumulative Update 2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL, aka "Microsoft Exchange Open Redirect Vulnerability."
Published 2016-09-14 · Modified
7.4EPSS 0.153
CVE-2019-0686
An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka 'Microsoft Exchange Server Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0724.
Published 2019-03-06 · Modified
7.4EPSS 0.050
CVE-2021-31196
Microsoft Exchange Server Remote Code Execution Vulnerability
Published 2021-07-14 · Analyzed
7.2KEVEPSS 0.541
CVE-2021-26854
Microsoft Exchange Server Remote Code Execution Vulnerability
Published 2021-03-02 · Modified
7.2EPSS 0.247
CVE-2020-16969
Microsoft Exchange Information Disclosure Vulnerability
Published 2020-10-16 · Modified
7.1EPSS 0.027
CVE-2015-1771
Cross-site request forgery (CSRF) vulnerability in the web applications in Microsoft Exchange Server 2013 SP1 and Cumulative Update 8 allows remote attackers to hijack the authentication of arbitrary users, aka "Exchange Cross-Site Request Forgery Vulnerability."
Published 2015-06-10 · Modified
6.8EPSS 0.058
CVE-2021-31207
Microsoft Exchange Server Security Feature Bypass Vulnerability
Published 2021-05-11 · Analyzed
6.6KEVEPSS 0.998
CVE-2021-41349
Microsoft Exchange Server Spoofing Vulnerability
Published 2021-11-10 · Modified
6.5EPSS 0.935
CVE-2018-0924
Microsoft Exchange Server 2010 Service Pack 3 Update Rollup 20, Microsoft Exchange Server 2013 Cumulative Update 18, Microsoft Exchange Server 2013 Cumulative Update 19, Microsoft Exchange Server 2013 Service Pack 1, Microsoft Exchange Server 2016 Cumulative Update 7, and Microsoft Exchange Server 2016 Cumulative Update 8 allow an information disclosure vulnerability due to how URL redirects are handled, aka "Microsoft Exchange Information Disclosure Vulnerability". This CVE is unique from CVE-2018-0941.
Published 2018-03-14 · Modified
6.5EPSS 0.080
CVE-2021-42305
Microsoft Exchange Server Spoofing Vulnerability
Published 2021-11-10 · Modified
6.5EPSS 0.079
CVE-2018-0940
Microsoft Exchange Outlook Web Access (OWA) in Microsoft Exchange Server 2010 Service Pack 3 Update Rollup 20, Microsoft Exchange Server 2013 Cumulative Update 18, Microsoft Exchange Server 2013 Cumulative Update 19, Microsoft Exchange Server 2013 Service Pack 1, Microsoft Exchange Server 2016 Cumulative Update 7, and Microsoft Exchange Server 2016 Cumulative Update 8 allows an elevation of privilege vulnerability due to how links in the body of an email message are rewritten, aka "Microsoft Exchange Elevation of Privilege Vulnerability".
Published 2018-03-14 · Modified
6.5EPSS 0.073
CVE-2019-1084
An information disclosure vulnerability exists when Exchange allows creation of entities with Display Names having non-printable characters. An authenticated attacker could exploit this vulnerability by creating entities with invalid display names, which, when added to conversations, remain invisible. This security update addresses the issue by validating display names upon creation in Microsoft Exchange, and by rendering invalid display names correctly in Microsoft Outlook clients., aka 'Microsoft Exchange Information Disclosure Vulnerability'.
Published 2019-07-15 · Modified
6.5EPSS 0.053
CVE-2019-0588
An information disclosure vulnerability exists when the Microsoft Exchange PowerShell API grants calendar contributors more view permissions than intended, aka "Microsoft Exchange Information Disclosure Vulnerability." This affects Microsoft Exchange Server.
Published 2019-01-08 · Modified
6.5EPSS 0.046
CVE-2022-30134
Microsoft Exchange Server Information Disclosure Vulnerability
Published 2022-08-09 · Modified
6.5EPSS 0.020
CVE-2020-17085
Microsoft Exchange Server Denial of Service Vulnerability
Published 2020-11-11 · Modified
6.2EPSS 0.036
CVE-2016-0030
Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) in Microsoft Exchange Server 2013 PS1, 2013 Cumulative Update 10, and 2016 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka "Exchange Spoofing Vulnerability."
Published 2016-01-13 · Modified
6.1EPSS 0.076
CVE-2016-0032
Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) in Microsoft Exchange Server 2013 PS1, 2013 Cumulative Update 10, 2013 Cumulative Update 11, and 2016 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka "Exchange Spoofing Vulnerability."
Published 2016-01-13 · Modified
6.1EPSS 0.076
CVE-2017-0110
Cross-site scripting (XSS) vulnerability in Microsoft Exchange Outlook Web Access (OWA) allows remote attackers to inject arbitrary web script or HTML via a crafted email or chat client, aka "Microsoft Exchange Server Elevation of Privilege Vulnerability."
Published 2017-03-17 · Modified
6.1EPSS 0.070
CVE-2017-8559
Microsoft Exchange Server 2010 SP3, Exchange Server 2013 SP3, Exchange Server 2013 CU16, and Exchange Server 2016 CU5 allows an elevation of privilege vulnerability due to the way that Exchange Outlook Web Access (OWA) handles web requests, aka "Microsoft Exchange Cross-Site Scripting Vulnerability". This CVE ID is unique from CVE-2017-8560.
Published 2017-07-11 · Modified
6.1EPSS 0.034
CVE-2017-8560
Microsoft Exchange Server 2010 SP3, Exchange Server 2013 SP3, Exchange Server 2013 CU16, and Exchange Server 2016 CU5 allows an elevation of privilege vulnerability due to the way that Exchange Outlook Web Access (OWA) handles web requests, aka "Microsoft Exchange Cross-Site Scripting Vulnerability". This CVE ID is unique from CVE-2017-8559.
Published 2017-07-11 · Modified
6.1EPSS 0.034
CVE-2017-8621
Microsoft Exchange Server 2010 SP3, Exchange Server 2013 SP3, Exchange Server 2013 CU16, and Exchange Server 2016 CU5 allows an open redirect vulnerability that could lead to spoofing, aka "Microsoft Exchange Open Redirect Vulnerability".
Published 2017-07-11 · Modified
6.1EPSS 0.032
CVE-2019-0858
A spoofing vulnerability exists in Microsoft Exchange Server when Outlook Web Access (OWA) fails to properly handle web requests, aka 'Microsoft Exchange Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-0817.
Published 2019-04-09 · Modified
6.1EPSS 0.021
CVE-2018-8159
An elevation of privilege vulnerability exists when Microsoft Exchange Outlook Web Access (OWA) fails to properly handle web requests, aka "Microsoft Exchange Elevation of Privilege Vulnerability." This affects Microsoft Exchange Server.
Published 2018-05-09 · Modified
5.8EPSS 0.036
← Prev2 / 3Next →