VendorsMicrosoftexchange_serverall versions
Vulnerabilities

Microsoft Exchange Server

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

259CVEs
CVE-2002-0054
SMTP service in (1) Microsoft Windows 2000 and (2) Internet Mail Connector (IMC) in Exchange Server 5.5 does not properly handle responses to NTLM authentication, which allows remote attackers to perform mail relaying via an SMTP AUTH command using null session credentials.
Published 2003-04-02 · Modified
7.5EPSS 0.224
CVE-2002-0698
Buffer overflow in Internet Mail Connector (IMC) for Microsoft Exchange Server 5.5 allows remote attackers to execute arbitrary code via an EHLO request from a system with a long name as obtained through a reverse DNS lookup, which triggers the overflow in IMC's hello response.
Published 2003-04-02 · Modified
7.5EPSS 0.203
CVE-2001-0726
Outlook Web Access (OWA) in Microsoft Exchange 5.5 Server, when used with Internet Explorer, does not properly detect certain inline script, which can allow remote attackers to perform arbitrary actions on a user's Exchange mailbox via an HTML e-mail message.
Published 2002-06-25 · Modified
7.5EPSS 0.161
CVE-1999-0284
Denial of service to NT mail servers including Ipswitch, Mdaemon, and Exchange through a buffer overflow in the SMTP HELO command.
Published 2000-02-04 · Modified
7.53 PoCEPSS 0.115
CVE-2024-49040
Microsoft Exchange Server Spoofing Vulnerability
Published 2024-11-12 · Analyzed
7.5EPSS 0.085
CVE-1999-0993
Modifications to ACLs (Access Control Lists) in Microsoft Exchange 5.5 do not take effect until the directory store cache is refreshed.
Published 2000-02-04 · Modified
7.5EPSS 0.071
CVE-2001-0340
An interaction between the Outlook Web Access (OWA) service in Microsoft Exchange 2000 Server and Internet Explorer allows attackers to execute malicious script code against a user's mailbox via a message attachment that contains HTML code, which is executed automatically.
Published 2001-09-18 · Modified
7.5EPSS 0.064
CVE-2000-1139
The installation of Microsoft Exchange 2000 before Rev. A creates a user account with a known password, which could allow attackers to gain privileges, aka the "Exchange User Account" vulnerability.
Published 2001-01-22 · Modified
7.5EPSS 0.050
CVE-2021-34453
Microsoft Exchange Server Denial of Service Vulnerability
Published 2021-10-13 · Modified
7.5EPSS 0.028
CVE-2023-21761
Microsoft Exchange Server Information Disclosure Vulnerability
Published 2023-01-10 · Modified
7.5EPSS 0.016
CVE-2025-33051
Microsoft Exchange Server Information Disclosure Vulnerability
Published 2025-08-12 · Analyzed
7.5EPSS 0.013
CVE-2025-64666
Microsoft Exchange Server Elevation of Privilege Vulnerability
Published 2025-12-09 · Analyzed
7.5EPSS 0.010
CVE-2025-59248
Microsoft Exchange Server Spoofing Vulnerability
Published 2025-10-14 · Analyzed
7.5EPSS 0.010
CVE-2018-8581
An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka "Microsoft Exchange Server Elevation of Privilege Vulnerability." This affects Microsoft Exchange Server.
Published 2018-11-14 · Analyzed
7.4KEVEPSS 0.274
CVE-2016-3378
Open redirect vulnerability in Microsoft Exchange Server 2013 SP1, 2013 Cumulative Update 12, 2013 Cumulative Update 13, 2016 Cumulative Update 1, and 2016 Cumulative Update 2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL, aka "Microsoft Exchange Open Redirect Vulnerability."
Published 2016-09-14 · Modified
7.4EPSS 0.153
CVE-2019-0686
An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka 'Microsoft Exchange Server Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-0724.
Published 2019-03-06 · Modified
7.4EPSS 0.050
CVE-2026-62914
Microsoft Exchange Server Spoofing Vulnerability
Published 2026-08-11 · Analyzed
7.3EPSS 0.004
CVE-2021-31196
Microsoft Exchange Server Remote Code Execution Vulnerability
Published 2021-07-14 · Analyzed
7.2KEVEPSS 0.541
CVE-2021-26854
Microsoft Exchange Server Remote Code Execution Vulnerability
Published 2021-03-02 · Modified
7.2EPSS 0.247
CVE-2023-21710
Microsoft Exchange Server Remote Code Execution Vulnerability
Published 2023-02-14 · Modified
7.2EPSS 0.079
CVE-2020-16969
Microsoft Exchange Information Disclosure Vulnerability
Published 2020-10-16 · Modified
7.1EPSS 0.027
CVE-2007-0220
Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) in Microsoft Exchange Server 2000 SP3, and 2003 SP1 and SP2 allows remote attackers to execute arbitrary scripts, spoof content, or obtain sensitive information via certain UTF-encoded, script-based e-mail attachments, involving an "incorrectly handled UTF character set label".
Published 2007-05-08 · Modified
6.8EPSS 0.331
CVE-2013-0418
Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.7 and 8.4 allows context-dependent attackers to affect availability via unknown vectors related to Outside In Filters, a different vulnerability than CVE-2013-0393. NOTE: the previous information was obtained from the January 2013 CPU. Oracle has not commented on claims from an independent researcher that this is a heap-based buffer overflow in the Paradox database stream filter (vspdx.dll) that can be triggered using a table header with a crafted "number of fields" value.
Published 2013-01-17 · Modified
6.8EPSS 0.083
CVE-2015-1771
Cross-site request forgery (CSRF) vulnerability in the web applications in Microsoft Exchange Server 2013 SP1 and Cumulative Update 8 allows remote attackers to hijack the authentication of arbitrary users, aka "Exchange Cross-Site Request Forgery Vulnerability."
Published 2015-06-10 · Modified
6.8EPSS 0.058
CVE-2021-31207
Microsoft Exchange Server Security Feature Bypass Vulnerability
Published 2021-05-11 · Analyzed
6.6KEVEPSS 0.998
CVE-2021-41349
Microsoft Exchange Server Spoofing Vulnerability
Published 2021-11-10 · Modified
6.5EPSS 0.935
CVE-2022-24463
Microsoft Exchange Server Spoofing Vulnerability
Published 2022-03-09 · Modified
6.5EPSS 0.318
CVE-2018-0924
Microsoft Exchange Server 2010 Service Pack 3 Update Rollup 20, Microsoft Exchange Server 2013 Cumulative Update 18, Microsoft Exchange Server 2013 Cumulative Update 19, Microsoft Exchange Server 2013 Service Pack 1, Microsoft Exchange Server 2016 Cumulative Update 7, and Microsoft Exchange Server 2016 Cumulative Update 8 allow an information disclosure vulnerability due to how URL redirects are handled, aka "Microsoft Exchange Information Disclosure Vulnerability". This CVE is unique from CVE-2018-0941.
Published 2018-03-14 · Modified
6.5EPSS 0.080
CVE-2026-21527
Microsoft Exchange Server Spoofing Vulnerability
Published 2026-02-10 · Analyzed
6.5EPSS 0.080
CVE-2021-42305
Microsoft Exchange Server Spoofing Vulnerability
Published 2021-11-10 · Modified
6.5EPSS 0.079
CVE-2018-0940
Microsoft Exchange Outlook Web Access (OWA) in Microsoft Exchange Server 2010 Service Pack 3 Update Rollup 20, Microsoft Exchange Server 2013 Cumulative Update 18, Microsoft Exchange Server 2013 Cumulative Update 19, Microsoft Exchange Server 2013 Service Pack 1, Microsoft Exchange Server 2016 Cumulative Update 7, and Microsoft Exchange Server 2016 Cumulative Update 8 allows an elevation of privilege vulnerability due to how links in the body of an email message are rewritten, aka "Microsoft Exchange Elevation of Privilege Vulnerability".
Published 2018-03-14 · Modified
6.5EPSS 0.073
CVE-2019-1084
An information disclosure vulnerability exists when Exchange allows creation of entities with Display Names having non-printable characters. An authenticated attacker could exploit this vulnerability by creating entities with invalid display names, which, when added to conversations, remain invisible. This security update addresses the issue by validating display names upon creation in Microsoft Exchange, and by rendering invalid display names correctly in Microsoft Outlook clients., aka 'Microsoft Exchange Information Disclosure Vulnerability'.
Published 2019-07-15 · Modified
6.5EPSS 0.053
CVE-2021-24085
Microsoft Exchange Server Spoofing Vulnerability
Published 2021-02-25 · Modified
6.5EPSS 0.046
CVE-2019-0588
An information disclosure vulnerability exists when the Microsoft Exchange PowerShell API grants calendar contributors more view permissions than intended, aka "Microsoft Exchange Information Disclosure Vulnerability." This affects Microsoft Exchange Server.
Published 2019-01-08 · Modified
6.5EPSS 0.046
CVE-2011-0290
The BlackBerry Collaboration Service in Research In Motion (RIM) BlackBerry Enterprise Server (BES) 5.0.3 through MR4 for Microsoft Exchange and Lotus Domino allows remote authenticated users to log into arbitrary user accounts associated with the same organization, and send messages, read messages, read contact lists, or cause a denial of service (login unavailability), via unspecified vectors.
Published 2011-10-21 · Modified
6.5EPSS 0.021
CVE-2026-62912
Microsoft Exchange Server Denial of Service Vulnerability
Published 2026-08-11 · Analyzed
6.5EPSS 0.020
CVE-2022-30134
Microsoft Exchange Server Information Disclosure Vulnerability
Published 2022-08-09 · Modified
6.5EPSS 0.020
CVE-2021-41350
Microsoft Exchange Server Spoofing Vulnerability
Published 2021-10-13 · Modified
6.5EPSS 0.019
CVE-2025-25005
Microsoft Exchange Server Tampering Vulnerability
Published 2025-08-12 · Analyzed
6.5EPSS 0.014
CVE-2026-62915
Microsoft Exchange Server Security Feature Bypass Vulnerability
Published 2026-08-11 · Analyzed
6.5EPSS 0.006
← Prev4 / 7Next →