cbcvebase.

Microsoft Exchange Server vulnerabilities

219 known vulnerabilities affecting microsoft/exchange_server.

Total CVEs
219
CISA KEV
20
actively exploited
Public exploits
46
Exploited in wild
29
Severity breakdown
CRITICAL25HIGH89MEDIUM99LOW6

Vulnerabilities

Page 8 of 11
CVE-2015-1771P4MEDIUMCVSS 6.8v20132015-06-10
CVE-2015-1771 [MEDIUM] CWE-352 CVE-2015-1771: Cross-site request forgery (CSRF) vulnerability in the web applications in Microsoft Exchange Server Cross-site request forgery (CSRF) vulnerability in the web applications in Microsoft Exchange Server 2013 SP1 and Cumulative Update 8 allows remote attackers to hijack the authentication of arbitrary users, aka "Exchange Cross-Site Request Forgery Vulnerability."
nvd
CVE-2001-0726P4HIGHCVSS 7.5v5.52001-12-06
CVE-2001-0726 [HIGH] CVE-2001-0726: Outlook Web Access (OWA) in Microsoft Exchange 5.5 Server, when used with Internet Explorer, does no Outlook Web Access (OWA) in Microsoft Exchange 5.5 Server, when used with Internet Explorer, does not properly detect certain inline script, which can allow remote attackers to perform arbitrary actions on a user's Exchange mailbox via an HTML e-mail message.
nvd
CVE-2016-0032P4MEDIUMCVSS 6.1v2013v20162016-01-13
CVE-2016-0032 [MEDIUM] CWE-79 CVE-2016-0032: Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) in Microsoft Exchange Server 20 Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) in Microsoft Exchange Server 2013 PS1, 2013 Cumulative Update 10, 2013 Cumulative Update 11, and 2016 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka "Exchange Spoofing Vulnerability."
nvd
CVE-2016-0030P4MEDIUMCVSS 6.1v2013v20162016-01-13
CVE-2016-0030 [MEDIUM] CWE-79 CVE-2016-0030: Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) in Microsoft Exchange Server 20 Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) in Microsoft Exchange Server 2013 PS1, 2013 Cumulative Update 10, and 2016 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka "Exchange Spoofing Vulnerability."
nvd
CVE-2017-0110P4MEDIUMCVSS 6.1v20132017-03-17
CVE-2017-0110 [MEDIUM] CWE-79 CVE-2017-0110: Cross-site scripting (XSS) vulnerability in Microsoft Exchange Outlook Web Access (OWA) allows remot Cross-site scripting (XSS) vulnerability in Microsoft Exchange Outlook Web Access (OWA) allows remote attackers to inject arbitrary web script or HTML via a crafted email or chat client, aka "Microsoft Exchange Server Elevation of Privilege Vulnerability."
nvd
CVE-2015-1631P4MEDIUMCVSS 5.0v20132015-03-11
CVE-2015-1631 [MEDIUM] CWE-284 CVE-2015-1631: Microsoft Exchange Server 2013 SP1 and Cumulative Update 7 allows remote attackers to spoof meeting Microsoft Exchange Server 2013 SP1 and Cumulative Update 7 allows remote attackers to spoof meeting organizers via unspecified vectors, aka "Exchange Forged Meeting Request Spoofing Vulnerability."
nvd
CVE-2026-45501P4MEDIUMCVSS 6.1v2016-cumulative_update_23v2019-cumulative_update_14+1 more2026-06-09
CVE-2026-45501 [MEDIUM] CWE-918 CVE-2026-45501: Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to per Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.
nvd
CVE-2015-1764P4MEDIUMCVSS 4.3v20132015-06-10
CVE-2015-1764 [MEDIUM] CVE-2015-1764: The web applications in Microsoft Exchange Server 2013 SP1 and Cumulative Update 8 allow remote atta The web applications in Microsoft Exchange Server 2013 SP1 and Cumulative Update 8 allow remote attackers to bypass the Same Origin Policy and send HTTP traffic to intranet servers via a crafted request, related to a Server-Side Request Forgery (SSRF) issue, aka "Exchange Server-Side Request Forgery Vulnerability."
nvd
CVE-2008-2248P4MEDIUMCVSS 4.3v2003v20072008-07-08
CVE-2008-2248 [MEDIUM] CVE-2008-2248: Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) for Exchange Server 2003 SP2 al Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) for Exchange Server 2003 SP2 allows remote attackers to inject arbitrary web script or HTML via unspecified HTML, a different vulnerability than CVE-2008-2247.
nvd
CVE-2008-2247P4MEDIUMCVSS 4.3v2003v20072008-07-08
CVE-2008-2247 [MEDIUM] CWE-79 CVE-2008-2247: Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) for Exchange Server 2003 SP2 al Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) for Exchange Server 2003 SP2 allows remote attackers to inject arbitrary web script or HTML via unspecified e-mail fields, a different vulnerability than CVE-2008-2248.
nvd
CVE-2010-0024P4MEDIUMCVSS 5.0v2000v2003+2 more2010-04-14
CVE-2010-0024 [MEDIUM] CWE-20 CVE-2010-0024: The SMTP component in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and Server 2008 G The SMTP component in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and Server 2008 Gold, SP2, and R2, and Exchange Server 2003 SP2, does not properly parse MX records, which allows remote DNS servers to cause a denial of service (service outage) via a crafted response to a DNS MX record query, aka "SMTP Server MX Record Vulnerability."
nvd
CVE-2014-6319P4MEDIUMCVSS 5.0v2007v2010+1 more2014-12-11
CVE-2014-6319 [MEDIUM] CWE-284 CVE-2014-6319: Outlook Web App (OWA) in Microsoft Exchange Server 2007 SP3, 2010 SP3, and 2013 SP1 and Cumulative U Outlook Web App (OWA) in Microsoft Exchange Server 2007 SP3, 2010 SP3, and 2013 SP1 and Cumulative Update 6 does not properly validate tokens in requests, which allows remote attackers to spoof the origin of e-mail messages via unspecified vectors, aka "Outlook Web App Token Spoofing Vulnerability."
nvd
CVE-2018-0941P4MEDIUMCVSS 5.5v20162018-03-14
CVE-2018-0941 [MEDIUM] CVE-2018-0941: Microsoft Exchange Server 2016 Cumulative Update 7 and Microsoft Exchange Server 2016 Cumulative Upd Microsoft Exchange Server 2016 Cumulative Update 7 and Microsoft Exchange Server 2016 Cumulative Update 8 allow an information disclosure vulnerability due to how data is imported, aka "Microsoft Exchange Information Disclosure Vulnerability". This CVE is unique from CVE-2018-0924.
nvd
CVE-2017-11761P4MEDIUMCVSS 5.3v2013v20162017-09-13
CVE-2017-11761 [MEDIUM] CWE-200 CVE-2017-11761: Microsoft Exchange Server 2013 and Microsoft Exchange Server 2016 allow an input sanitization issue Microsoft Exchange Server 2013 and Microsoft Exchange Server 2016 allow an input sanitization issue with Microsoft Exchange that could potentially result in unintended Information Disclosure, aka "Microsoft Exchange Information Disclosure Vulnerability"
nvd
CVE-1999-0682P4MEDIUMCVSS 5.0v5.51999-08-06
CVE-1999-0682 [MEDIUM] CVE-1999-0682: Microsoft Exchange 5.5 allows a remote attacker to relay email (i.e. spam) using encapsulated SMTP a Microsoft Exchange 5.5 allows a remote attacker to relay email (i.e. spam) using encapsulated SMTP addresses, even if the anti-relaying features are enabled.
nvd
CVE-2025-25007P4MEDIUMCVSS 5.3v2016v2016-cumulative_update_1+35 more2025-08-12
CVE-2025-25007 [MEDIUM] CWE-1286 CVE-2025-25007: Improper validation of syntactic correctness of input in Microsoft Exchange Server allows an unautho Improper validation of syntactic correctness of input in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
nvd
CVE-2016-0138P4MEDIUMCVSS 4.3v2007v2010+2 more2016-09-14
CVE-2016-0138 [MEDIUM] CWE-200 CVE-2016-0138: Microsoft Exchange Server 2007 SP3, 2010 SP3, 2013 SP1, 2013 Cumulative Update 12, 2013 Cumulative U Microsoft Exchange Server 2007 SP3, 2010 SP3, 2013 SP1, 2013 Cumulative Update 12, 2013 Cumulative Update 13, 2016 Cumulative Update 1, and 2016 Cumulative Update 2 misparses e-mail messages, which allows remote authenticated users to obtain sensitive Outlook application information by leveraging the Send As right, aka "Microsoft Exchange Information
nvd
CVE-2018-8159P4MEDIUMCVSS 5.4v2013-cumulative_update_19v2013-cumulative_update_20+2 more2018-05-09
CVE-2018-8159 [MEDIUM] CWE-79 CVE-2018-8159: An elevation of privilege vulnerability exists when Microsoft Exchange Outlook Web Access (OWA) fail An elevation of privilege vulnerability exists when Microsoft Exchange Outlook Web Access (OWA) fails to properly handle web requests, aka "Microsoft Exchange Elevation of Privilege Vulnerability." This affects Microsoft Exchange Server.
nvd
CVE-2018-8152P4MEDIUMCVSS 5.4v2016-cumulative_update_8v2016-cumulative_update_92018-05-09
CVE-2018-8152 [MEDIUM] CWE-79 CVE-2018-8152: An elevation of privilege vulnerability exists when Microsoft Exchange Outlook Web Access (OWA) fail An elevation of privilege vulnerability exists when Microsoft Exchange Outlook Web Access (OWA) fails to properly handle web requests, aka "Microsoft Exchange Server Elevation of Privilege Vulnerability." This affects Microsoft Exchange Server.
nvd
CVE-2018-8448P4MEDIUMCVSS 5.4v2013-cumulative_update_21v2016-cumulative_update_102018-10-10
CVE-2018-8448 [MEDIUM] CWE-79 CVE-2018-8448: An elevation of privilege vulnerability exists when Microsoft Exchange Outlook Web Access (OWA) fail An elevation of privilege vulnerability exists when Microsoft Exchange Outlook Web Access (OWA) fails to properly handle web requests, aka "Microsoft Exchange Server Elevation of Privilege Vulnerability." This affects Microsoft Exchange Server.
nvd
Microsoft Exchange Server vulnerabilities | cvebase