VendorsMicrosoftexchange_serverall versions
Vulnerabilities

Microsoft Exchange Server

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

259CVEs
CVE-2023-36050
Microsoft Exchange Server Spoofing Vulnerability
Published 2023-11-14 · Modified
8.0EPSS 0.392
CVE-2023-36757
Microsoft Exchange Server Spoofing Vulnerability
Published 2023-09-12 · Modified
8.0EPSS 0.369
CVE-2023-28310
Microsoft Exchange Server Remote Code Execution Vulnerability
Published 2023-06-14 · Modified
8.0EPSS 0.250
CVE-2021-31206
Microsoft Exchange Server Remote Code Execution Vulnerability
Published 2021-07-14 · Modified
8.0EPSS 0.130
CVE-2025-53786
Microsoft Exchange Server Hybrid Deployment Elevation of Privilege Vulnerability
Published 2025-08-06 · Analyzed
8.0EPSS 0.077
CVE-2023-35388
Microsoft Exchange Server Remote Code Execution Vulnerability
Published 2023-08-08 · Modified
8.0EPSS 0.068
CVE-2023-38182
Microsoft Exchange Server Remote Code Execution Vulnerability
Published 2023-08-08 · Modified
8.0EPSS 0.059
CVE-2023-36439
Microsoft Exchange Server Remote Code Execution Vulnerability
Published 2023-11-14 · Modified
8.0EPSS 0.049
CVE-2021-34470
Microsoft Exchange Server Elevation of Privilege Vulnerability
Published 2021-07-14 · Modified
8.0EPSS 0.044
CVE-2023-36778
Microsoft Exchange Server Remote Code Execution Vulnerability
Published 2023-10-10 · Modified
8.0EPSS 0.037
CVE-2022-21980
Microsoft Exchange Server Elevation of Privilege Vulnerability
Published 2022-08-09 · Modified
8.0EPSS 0.025
CVE-2022-24516
Microsoft Exchange Server Elevation of Privilege Vulnerability
Published 2022-08-09 · Modified
8.0EPSS 0.022
CVE-2022-24477
Microsoft Exchange Server Elevation of Privilege Vulnerability
Published 2022-08-09 · Modified
8.0EPSS 0.021
CVE-2023-21762
Microsoft Exchange Server Spoofing Vulnerability
Published 2023-01-10 · Modified
8.0EPSS 0.016
CVE-2023-21745
Microsoft Exchange Server Spoofing Vulnerability
Published 2023-01-10 · Modified
8.0EPSS 0.015
CVE-2021-33768
Microsoft Exchange Server Elevation of Privilege Vulnerability
Published 2021-07-14 · Modified
8.0EPSS 0.012
CVE-2022-41078
Microsoft Exchange Server Spoofing Vulnerability
Published 2022-11-09 · Modified
8.0EPSS 0.008
CVE-2022-41079
Microsoft Exchange Server Spoofing Vulnerability
Published 2022-11-09 · Modified
8.0EPSS 0.008
CVE-2026-62911
Microsoft Exchange Server Elevation of Privilege Vulnerability
Published 2026-08-11 · Modified
8.0EPSS 0.007
CVE-2021-41348
Microsoft Exchange Server Elevation of Privilege Vulnerability
Published 2021-10-13 · Modified
8.0EPSS 0.006
CVE-2021-27065
Microsoft Exchange Server Remote Code Execution Vulnerability
Published 2021-03-02 · Analyzed
7.8KEV1 PoCEPSS 0.999
CVE-2021-26857
Microsoft Exchange Server Remote Code Execution Vulnerability
Published 2021-03-02 · Analyzed
7.8KEVEPSS 0.958
CVE-2021-26858
Microsoft Exchange Server Remote Code Execution Vulnerability
Published 2021-03-02 · Analyzed
7.8KEVEPSS 0.937
CVE-2007-0039
The Exchange Collaboration Data Objects (EXCDO) functionality in Microsoft Exchange Server 2000 SP3, 2003 SP1 and SP2, and 2007 allows remote attackers to cause a denial of service (crash) via an Internet Calendar (iCal) file containing multiple X-MICROSOFT-CDO-MODPROPS (MODPROPS) properties in which the second MODPROPS is longer than the first, which triggers a NULL pointer dereference and an unhandled exception.
Published 2007-05-08 · Modified
7.8EPSS 0.446
CVE-2007-0221
Integer overflow in the IMAP (IMAP4) support in Microsoft Exchange Server 2000 SP3 allows remote attackers to cause a denial of service (service hang) via crafted literals in an IMAP command, aka the "IMAP Literal Processing Vulnerability."
Published 2007-05-08 · Modified
7.8EPSS 0.372
CVE-2019-1233
A denial of service vulnerability exists in Microsoft Exchange Server software when the software fails to properly handle objects in memory, aka 'Microsoft Exchange Denial of Service Vulnerability'.
Published 2019-09-11 · Modified
7.8EPSS 0.062
CVE-2021-31198
Microsoft Exchange Server Remote Code Execution Vulnerability
Published 2021-05-11 · Modified
7.8EPSS 0.049
CVE-2026-55009
Microsoft Exchange Server Elevation of Privilege Vulnerability
Published 2026-07-14 · Analyzed
7.8EPSS 0.025
CVE-2022-41123
Microsoft Exchange Server Elevation of Privilege Vulnerability
Published 2022-11-09 · Modified
7.8EPSS 0.006
CVE-2023-21763
Microsoft Exchange Server Elevation of Privilege Vulnerability
Published 2023-01-10 · Modified
7.8EPSS 0.006
CVE-2023-21764
Microsoft Exchange Server Elevation of Privilege Vulnerability
Published 2023-01-10 · Modified
7.8EPSS 0.006
CVE-2021-3146
The Dolby Audio X2 (DAX2) API service before 0.8.8.90 on Windows allows local users to gain privileges.
Published 2021-04-08 · Modified
7.8EPSS 0.004
CVE-2026-55006
Microsoft Exchange Server Elevation of Privilege Vulnerability
Published 2026-07-14 · Analyzed
7.8EPSS 0.003
CVE-2021-33766
Microsoft Exchange Server Information Disclosure Vulnerability
Published 2021-07-14 · Analyzed
7.5KEVEPSS 0.981
CVE-2006-0027
Unspecified vulnerability in Microsoft Exchange allows remote attackers to execute arbitrary code via e-mail messages with crafted (1) vCal or (2) iCal Calendar properties.
Published 2006-05-09 · Modified
7.5EPSS 0.787
CVE-2003-0714
The Internet Mail Service in Exchange Server 5.5 and Exchange 2000 allows remote attackers to cause a denial of service (memory exhaustion) by directly connecting to the SMTP service and sending a certain extended verb request, possibly triggering a buffer overflow in Exchange 2000.
Published 2003-10-17 · Modified
7.52 PoCEPSS 0.776
CVE-2005-0560
Heap-based buffer overflow in the SvrAppendReceivedChunk function in xlsasink.dll in the SMTP service of Exchange Server 2000 and 2003 allows remote attackers to execute arbitrary code via a crafted X-LINK2STATE extended verb request to the SMTP port.
Published 2005-04-13 · Modified
7.51 PoCEPSS 0.695
CVE-2006-0002
Unspecified vulnerability in Microsoft Outlook 2000 through 2003, Exchange 5.0 Server SP2 and 5.5 SP4, Exchange 2000 SP3, and Office allows remote attackers to execute arbitrary code via an e-mail message with a crafted Transport Neutral Encapsulation Format (TNEF) MIME attachment, related to message length validation.
Published 2006-01-10 · Modified
7.5EPSS 0.456
CVE-2005-1987
Buffer overflow in Collaboration Data Objects (CDO), as used in Microsoft Windows and Microsoft Exchange Server, allows remote attackers to execute arbitrary code when CDOSYS or CDOEX processes an e-mail message with a large header name, as demonstrated using the "Content-Type" string.
Published 2005-10-13 · Modified
7.5EPSS 0.445
CVE-2005-0044
The OLE component in Windows 98, 2000, XP, and Server 2003, and Exchange Server 5.0 through 2003, does not properly validate the lengths of messages for certain OLE data, which allows remote attackers to execute arbitrary code, aka the "Input Validation Vulnerability."
Published 2005-02-08 · Modified
7.5EPSS 0.334
← Prev3 / 7Next →