Microsoft Exchange Server vulnerabilities
219 known vulnerabilities affecting microsoft/exchange_server.
Total CVEs
219
CISA KEV
20
actively exploited
Public exploits
46
Exploited in wild
29
Severity breakdown
CRITICAL25HIGH89MEDIUM99LOW6
Vulnerabilities
Page 7 of 11
CVE-2019-1233P3HIGHCVSS 7.5v2016v20192019-09-11
CVE-2019-1233 [HIGH] CVE-2019-1233: A denial of service vulnerability exists in Microsoft Exchange Server software when the software fai
A denial of service vulnerability exists in Microsoft Exchange Server software when the software fails to properly handle objects in memory, aka 'Microsoft Exchange Denial of Service Vulnerability'.
nvd
CVE-2025-25005P3MEDIUMCVSS 6.5v2016v2016-cumulative_update_1+35 more2025-08-12
CVE-2025-25005 [MEDIUM] CWE-20 CVE-2025-25005: Improper input validation in Microsoft Exchange Server allows an authorized attacker to perform tamp
Improper input validation in Microsoft Exchange Server allows an authorized attacker to perform tampering over a network.
nvd
CVE-2023-21761P3HIGHCVSS 7.5v2016v20192023-01-10
CVE-2023-21761 [HIGH] CWE-918 CVE-2023-21761: Microsoft Exchange Server Information Disclosure Vulnerability
Microsoft Exchange Server Information Disclosure Vulnerability
nvd
CVE-2026-45503P3MEDIUMCVSS 6.5v2016-cumulative_update_23v2019-cumulative_update_14+1 more2026-06-09
CVE-2026-45503 [MEDIUM] CWE-285 CVE-2026-45503: Improper authorization in Microsoft Exchange Server allows an authorized attacker to disclose inform
Improper authorization in Microsoft Exchange Server allows an authorized attacker to disclose information over a network.
nvd
CVE-2020-17083P3MEDIUMCVSS 5.4v2013v2016+1 more2020-11-11
CVE-2020-17083 [MEDIUM] CWE-79 CVE-2020-17083: Microsoft Exchange Server Remote Code Execution Vulnerability
Microsoft Exchange Server Remote Code Execution Vulnerability
nvd
CVE-2018-0940P3MEDIUMCVSS 6.5v2010v2013+1 more2018-03-14
CVE-2018-0940 [MEDIUM] CVE-2018-0940: Microsoft Exchange Outlook Web Access (OWA) in Microsoft Exchange Server 2010 Service Pack 3 Update
Microsoft Exchange Outlook Web Access (OWA) in Microsoft Exchange Server 2010 Service Pack 3 Update Rollup 20, Microsoft Exchange Server 2013 Cumulative Update 18, Microsoft Exchange Server 2013 Cumulative Update 19, Microsoft Exchange Server 2013 Service Pack 1, Microsoft Exchange Server 2016 Cumulative Update 7, and Microsoft Exchange Server 2016 Cumulative
nvd
CVE-2019-1084P3MEDIUMCVSS 6.5v2010v2013+1 more2019-07-15
CVE-2019-1084 [MEDIUM] CWE-200 CVE-2019-1084: An information disclosure vulnerability exists when Exchange allows creation of entities with Displa
An information disclosure vulnerability exists when Exchange allows creation of entities with Display Names having non-printable characters. An authenticated attacker could exploit this vulnerability by creating entities with invalid display names, which, when added to conversations, remain invisible. This security update addresses the issue by valida
nvd
CVE-2022-21978P3HIGHCVSS 8.2v2013v2016+1 more2022-05-10
CVE-2022-21978 [HIGH] CVE-2022-21978: Microsoft Exchange Server Elevation of Privilege Vulnerability
Microsoft Exchange Server Elevation of Privilege Vulnerability
nvd
CVE-2013-0418P3MEDIUMCVSS 6.8v2007v20102013-01-17
CVE-2013-0418 [MEDIUM] CVE-2013-0418: Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware
Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.7 and 8.4 allows context-dependent attackers to affect availability via unknown vectors related to Outside In Filters, a different vulnerability than CVE-2013-0393. NOTE: the previous information was obtained from the January 2013 CPU. Oracle has not comment
nvd
CVE-2018-0924P3MEDIUMCVSS 6.5v2010v2013+1 more2018-03-14
CVE-2018-0924 [MEDIUM] CWE-601 CVE-2018-0924: Microsoft Exchange Server 2010 Service Pack 3 Update Rollup 20, Microsoft Exchange Server 2013 Cumul
Microsoft Exchange Server 2010 Service Pack 3 Update Rollup 20, Microsoft Exchange Server 2013 Cumulative Update 18, Microsoft Exchange Server 2013 Cumulative Update 19, Microsoft Exchange Server 2013 Service Pack 1, Microsoft Exchange Server 2016 Cumulative Update 7, and Microsoft Exchange Server 2016 Cumulative Update 8 allow an information disclosu
nvd
CVE-2002-0054P4HIGHCVSS 7.5v5.52002-03-08
CVE-2002-0054 [HIGH] CWE-294 CVE-2002-0054: SMTP service in (1) Microsoft Windows 2000 and (2) Internet Mail Connector (IMC) in Exchange Server
SMTP service in (1) Microsoft Windows 2000 and (2) Internet Mail Connector (IMC) in Exchange Server 5.5 does not properly handle responses to NTLM authentication, which allows remote attackers to perform mail relaying via an SMTP AUTH command using null session credentials.
nvd
CVE-2010-1689P3MEDIUMCVSS 6.4v2003v2007+1 more2010-05-07
CVE-2010-1689 [MEDIUM] CVE-2010-1689: The DNS implementation in smtpsvc.dll before 6.0.2600.5949 in Microsoft Windows 2000 SP4 and earlier
The DNS implementation in smtpsvc.dll before 6.0.2600.5949 in Microsoft Windows 2000 SP4 and earlier, Windows XP SP3 and earlier, Windows Server 2003 SP2 and earlier, Windows Server 2008 SP2 and earlier, Windows Server 2008 R2, Exchange Server 2003 SP3 and earlier, Exchange Server 2007 SP2 and earlier, and Exchange Server 2010 uses predictable transaction IDs
nvd
CVE-2010-1690P3MEDIUMCVSS 6.4v2003v2007+1 more2010-05-07
CVE-2010-1690 [MEDIUM] CVE-2010-1690: The DNS implementation in smtpsvc.dll before 6.0.2600.5949 in Microsoft Windows 2000 SP4 and earlier
The DNS implementation in smtpsvc.dll before 6.0.2600.5949 in Microsoft Windows 2000 SP4 and earlier, Windows XP SP3 and earlier, Windows Server 2003 SP2 and earlier, Windows Server 2008 SP2 and earlier, Windows Server 2008 R2, Exchange Server 2003 SP3 and earlier, Exchange Server 2007 SP2 and earlier, and Exchange Server 2010 does not verify that transaction
nvd
CVE-2021-34453P3HIGHCVSS 7.5v2016v20192021-10-13
CVE-2021-34453 [HIGH] CVE-2021-34453: Microsoft Exchange Server Denial of Service Vulnerability
Microsoft Exchange Server Denial of Service Vulnerability
nvd
CVE-2019-0588P3MEDIUMCVSS 6.5v2010-sp3_rollup25v2013-cumulative_update_21+3 more2019-01-08
CVE-2019-0588 [MEDIUM] CWE-732 CVE-2019-0588: An information disclosure vulnerability exists when the Microsoft Exchange PowerShell API grants cal
An information disclosure vulnerability exists when the Microsoft Exchange PowerShell API grants calendar contributors more view permissions than intended, aka "Microsoft Exchange Information Disclosure Vulnerability." This affects Microsoft Exchange Server.
nvd
CVE-2020-16969P4MEDIUMCVSS 6.5v2013v2016+1 more2020-10-16
CVE-2020-16969 [MEDIUM] CVE-2020-16969: <p>An information disclosure vulnerability exists in how Microsoft Exchange validates tokens when ha
An information disclosure vulnerability exists in how Microsoft Exchange validates tokens when handling certain messages. An attacker who successfully exploited the vulnerability could use this to gain further information from a user.
To exploit the vulnerability, an attacker could include specially crafted OWA messages that could be loaded, without warning
nvd
CVE-2015-2505P4MEDIUMCVSS 5.0v20132015-09-09
CVE-2015-2505 [MEDIUM] CWE-200 CVE-2015-2505: Outlook Web Access (OWA) in Microsoft Exchange Server 2013 Cumulative Update 8 and 9 and SP1 allows
Outlook Web Access (OWA) in Microsoft Exchange Server 2013 Cumulative Update 8 and 9 and SP1 allows remote attackers to obtain sensitive stacktrace information via a crafted request, aka "Exchange Information Disclosure Vulnerability."
nvd
CVE-2016-3379P4MEDIUMCVSS 6.1v20162016-09-14
CVE-2016-3379 [MEDIUM] CWE-79 CVE-2016-3379: Cross-site scripting (XSS) vulnerability in Microsoft Exchange Server 2016 Cumulative Update 1 and 2
Cross-site scripting (XSS) vulnerability in Microsoft Exchange Server 2016 Cumulative Update 1 and 2 allows remote attackers to inject arbitrary web script or HTML via a meeting-invitation request, aka "Microsoft Exchange Elevation of Privilege Vulnerability."
nvd
CVE-2016-0031P4MEDIUMCVSS 6.1v20162016-01-13
CVE-2016-0031 [MEDIUM] CVE-2016-0031: Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) in Microsoft Exchange Server 20
Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) in Microsoft Exchange Server 2016 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka "Exchange Spoofing Vulnerability," a different vulnerability than CVE-2016-0029.
nvd
CVE-2016-0029P4MEDIUMCVSS 6.1v20162016-01-13
CVE-2016-0029 [MEDIUM] CWE-79 CVE-2016-0029: Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) in Microsoft Exchange Server 20
Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) in Microsoft Exchange Server 2016 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka "Exchange Spoofing Vulnerability," a different vulnerability than CVE-2016-0031.
nvd