cbcvebase.

Microsoft Exchange Server vulnerabilities

219 known vulnerabilities affecting microsoft/exchange_server.

Total CVEs
219
CISA KEV
20
actively exploited
Public exploits
46
Exploited in wild
29
Severity breakdown
CRITICAL25HIGH89MEDIUM99LOW6

Vulnerabilities

Page 9 of 11
CVE-2001-0660P4MEDIUMCVSS 5.0≤ 5.52001-10-30
CVE-2001-0660 [MEDIUM] CVE-2001-0660: Outlook Web Access (OWA) in Microsoft Exchange 5.5, SP4 and earlier, allows remote attackers to iden Outlook Web Access (OWA) in Microsoft Exchange 5.5, SP4 and earlier, allows remote attackers to identify valid user email addresses by directly accessing a back-end function that processes the global address list (GAL).
nvd
CVE-2021-1730P4MEDIUMCVSS 5.4v2016v20192021-02-25
CVE-2021-1730 [MEDIUM] CVE-2021-1730: <p>A spoofing vulnerability exists in Microsoft Exchange Server which could result in an attack that A spoofing vulnerability exists in Microsoft Exchange Server which could result in an attack that would allow a malicious actor to impersonate the user. This update addresses this vulnerability. To prevent these types of attacks, Microsoft recommends customers to download inline images from different DNSdomains than the rest of OWA. Please see further instruc
nvd
CVE-2025-25006P4MEDIUMCVSS 5.3v2016v2016-cumulative_update_1+34 more2025-08-12
CVE-2025-25006 [MEDIUM] CWE-167 CVE-2025-25006: Improper handling of additional special element in Microsoft Exchange Server allows an unauthorized Improper handling of additional special element in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
nvd
CVE-1999-0993P4HIGHCVSS 7.5v5.0v5.51999-12-13
CVE-1999-0993 [HIGH] CWE-665 CVE-1999-0993: Modifications to ACLs (Access Control Lists) in Microsoft Exchange 5.5 do not take effect until the Modifications to ACLs (Access Control Lists) in Microsoft Exchange 5.5 do not take effect until the directory store cache is refreshed.
nvd
CVE-2017-8559P4MEDIUMCVSS 6.1v2013v20162017-07-11
CVE-2017-8559 [MEDIUM] CWE-79 CVE-2017-8559: Microsoft Exchange Server 2010 SP3, Exchange Server 2013 SP3, Exchange Server 2013 CU16, and Exchang Microsoft Exchange Server 2010 SP3, Exchange Server 2013 SP3, Exchange Server 2013 CU16, and Exchange Server 2016 CU5 allows an elevation of privilege vulnerability due to the way that Exchange Outlook Web Access (OWA) handles web requests, aka "Microsoft Exchange Cross-Site Scripting Vulnerability". This CVE ID is unique from CVE-2017-8560.
nvd
CVE-2017-8560P4MEDIUMCVSS 6.1v2013v20162017-07-11
CVE-2017-8560 [MEDIUM] CVE-2017-8560: Microsoft Exchange Server 2010 SP3, Exchange Server 2013 SP3, Exchange Server 2013 CU16, and Exchang Microsoft Exchange Server 2010 SP3, Exchange Server 2013 SP3, Exchange Server 2013 CU16, and Exchange Server 2016 CU5 allows an elevation of privilege vulnerability due to the way that Exchange Outlook Web Access (OWA) handles web requests, aka "Microsoft Exchange Cross-Site Scripting Vulnerability". This CVE ID is unique from CVE-2017-8559.
nvd
CVE-2002-0049P4MEDIUMCVSS 6.4v20002002-03-08
CVE-2002-0049 [MEDIUM] CWE-269 CVE-2002-0049: Microsoft Exchange Server 2000 System Attendant gives "Everyone" group privileges to the WinReg key, Microsoft Exchange Server 2000 System Attendant gives "Everyone" group privileges to the WinReg key, which could allow remote attackers to read or modify registry keys.
nvd
CVE-2018-8153P4MEDIUMCVSS 5.4v2016-cumulative_update_8v2016-cumulative_update_92018-05-09
CVE-2018-8153 [MEDIUM] CWE-290 CVE-2018-8153: A spoofing vulnerability exists in Microsoft Exchange Server when Outlook Web Access (OWA) fails to A spoofing vulnerability exists in Microsoft Exchange Server when Outlook Web Access (OWA) fails to properly handle web requests, aka "Microsoft Exchange Spoofing Vulnerability." This affects Microsoft Exchange Server.
nvd
CVE-2022-21979P4MEDIUMCVSS 5.7v2013v2016+1 more2022-08-09
CVE-2022-21979 [MEDIUM] CVE-2022-21979: Microsoft Exchange Server Information Disclosure Vulnerability Microsoft Exchange Server Information Disclosure Vulnerability
nvd
CVE-2026-45500P4MEDIUMCVSS 6.1v2016-cumulative_update_23v2019-cumulative_update_14+1 more2026-06-09
CVE-2026-45500 [MEDIUM] CWE-79 CVE-2026-45500: Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Ex Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
nvd
CVE-2017-8758P4MEDIUMCVSS 6.1v20162017-09-13
CVE-2017-8758 [MEDIUM] CWE-79 CVE-2017-8758: Microsoft Exchange Server 2016 allows an elevation of privilege vulnerability when Microsoft Exchang Microsoft Exchange Server 2016 allows an elevation of privilege vulnerability when Microsoft Exchange Outlook Web Access (OWA) fails to properly handle web requests, aka "Microsoft Exchange Cross-Site Scripting Vulnerability."
nvd
CVE-2017-8621P4MEDIUMCVSS 6.1v2010v2013+1 more2017-07-11
CVE-2017-8621 [MEDIUM] CWE-601 CVE-2017-8621: Microsoft Exchange Server 2010 SP3, Exchange Server 2013 SP3, Exchange Server 2013 CU16, and Exchang Microsoft Exchange Server 2010 SP3, Exchange Server 2013 SP3, Exchange Server 2013 CU16, and Exchange Server 2016 CU5 allows an open redirect vulnerability that could lead to spoofing, aka "Microsoft Exchange Open Redirect Vulnerability".
nvd
CVE-2000-1139P4HIGHCVSS 7.5v20002001-01-09
CVE-2000-1139 [HIGH] CWE-798 CVE-2000-1139: The installation of Microsoft Exchange 2000 before Rev. A creates a user account with a known passwo The installation of Microsoft Exchange 2000 before Rev. A creates a user account with a known password, which could allow attackers to gain privileges, aka the "Exchange User Account" vulnerability.
nvd
CVE-2019-0858P4MEDIUMCVSS 6.1v2013v2016+1 more2019-04-09
CVE-2019-0858 [MEDIUM] CVE-2019-0858: A spoofing vulnerability exists in Microsoft Exchange Server when Outlook Web Access (OWA) fails to A spoofing vulnerability exists in Microsoft Exchange Server when Outlook Web Access (OWA) fails to properly handle web requests, aka 'Microsoft Exchange Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-0817.
nvd
CVE-2019-1266P4MEDIUMCVSS 6.1v2016v20192019-09-11
CVE-2019-1266 [MEDIUM] CWE-79 CVE-2019-1266: A spoofing vulnerability exists in Microsoft Exchange Server when Outlook Web App (OWA) fails to pro A spoofing vulnerability exists in Microsoft Exchange Server when Outlook Web App (OWA) fails to properly handle web requests, aka 'Microsoft Exchange Spoofing Vulnerability'.
nvd
CVE-2002-0055P4MEDIUMCVSS 5.0v20002002-03-08
CVE-2002-0055 [MEDIUM] CWE-669 CVE-2002-0055: SMTP service in Microsoft Windows 2000, Windows XP Professional, and Exchange 2000 allows remote att SMTP service in Microsoft Windows 2000, Windows XP Professional, and Exchange 2000 allows remote attackers to cause a denial of service via a command with a malformed data transfer (BDAT) request.
nvd
CVE-2003-0904P4MEDIUMCVSS 6.0v20032004-01-20
CVE-2003-0904 [MEDIUM] CWE-200 CVE-2003-0904: Microsoft Exchange 2003 and Outlook Web Access (OWA), when configured to use NTLM authentication, do Microsoft Exchange 2003 and Outlook Web Access (OWA), when configured to use NTLM authentication, does not properly reuse HTTP connections, which can cause OWA users to view mailboxes of other users when Kerberos has been disabled as an authentication method for IIS 6.0, e.g. when SharePoint Services 2.0 is installed.
nvd
CVE-2026-47631P4MEDIUMCVSS 5.4v2016-cumulative_update_23v2019-cumulative_update_14+1 more2026-06-09
CVE-2026-47631 [MEDIUM] CWE-79 CVE-2026-47631: Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Ex Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
nvd
CVE-2004-0203P4MEDIUMCVSS 4.3v5.52004-11-23
CVE-2004-0203 [MEDIUM] CWE-79 CVE-2004-0203: Cross-site scripting (XSS) vulnerability in Outlook Web Access for Exchange Server 5.5 Service Pack Cross-site scripting (XSS) vulnerability in Outlook Web Access for Exchange Server 5.5 Service Pack 4 allows remote attackers to insert arbitrary script and spoof content in HTML email or web caches via an HTML redirect query.
nvd
CVE-2019-0817P4MEDIUMCVSS 5.4v2010v2013+2 more2019-04-09
CVE-2019-0817 [MEDIUM] CWE-19 CVE-2019-0817: A spoofing vulnerability exists in Microsoft Exchange Server when Outlook Web Access (OWA) fails to A spoofing vulnerability exists in Microsoft Exchange Server when Outlook Web Access (OWA) fails to properly handle web requests, aka 'Microsoft Exchange Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-0858.
nvd
Microsoft Exchange Server vulnerabilities | cvebase