Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Group: cwe Tag: exchange-server Clear
ID Title
CVE-2026-65813 SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-65813)
SSRF in ssrf (CVE-2026-65813). Confidential information can be exposed externally.
CVE-2026-62915 Vulnerability in microsoft (CVE-2026-62915)
vulnerability in microsoft (CVE-2026-62915). Data can be tampered with by attackers.
CVE-2026-62914 Cross-Site Scripting (XSS) in microsoft (CVE-2026-62914)
cross-site scripting in microsoft (CVE-2026-62914). Confidential information can be exposed externally.
CVE-2026-62913 Vulnerability in microsoft (CVE-2026-62913)
vulnerability in microsoft (CVE-2026-62913). Successful exploitation can lead to full system takeover.
CVE-2026-62912 Unsafe Deserialization in deserialization (CVE-2026-62912)
vulnerability in deserialization (CVE-2026-62912). Risk of unauthorized operations or information disclosure.
CVE-2026-62911 Vulnerability in microsoft (CVE-2026-62911)
vulnerability in microsoft (CVE-2026-62911). Successful exploitation can lead to full system takeover.
CVE-2026-55009 Unsafe Deserialization in deserialization (CVE-2026-55009)
vulnerability in deserialization (CVE-2026-55009). Successful exploitation can lead to full system takeover.
CVE-2026-55008 Cross-Site Scripting (XSS) in microsoft (CVE-2026-55008)
cross-site scripting in microsoft (CVE-2026-55008). Successful exploitation can lead to full system takeover.
CVE-2026-55006 Vulnerability in microsoft (CVE-2026-55006)
vulnerability in microsoft (CVE-2026-55006). Successful exploitation can lead to full system takeover.
CVE-2026-55005 Vulnerability in microsoft (CVE-2026-55005)
vulnerability in microsoft (CVE-2026-55005). Successful exploitation can lead to full system takeover.
CVE-2026-45583 Code Injection in microsoft (CVE-2026-45583)
code injection in microsoft (CVE-2026-45583). Successful exploitation can lead to full system takeover.
CVE-2026-45504 SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-45504)
SSRF in ssrf (CVE-2026-45504). Successful exploitation can lead to full system takeover.
CVE-2026-45501 SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-45501)
SSRF in ssrf (CVE-2026-45501). Confidential information can be exposed externally.
CVE-2026-45502 SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-45502)
SSRF in ssrf (CVE-2026-45502). Risk of unauthorized operations or information disclosure.
CVE-2026-45500 Cross-Site Scripting (XSS) in microsoft (CVE-2026-45500)
cross-site scripting in microsoft (CVE-2026-45500). Risk of unauthorized operations or information disclosure.
CVE-2026-47631 Cross-Site Scripting (XSS) in microsoft (CVE-2026-47631)
cross-site scripting in microsoft (CVE-2026-47631). Confidential information can be exposed externally.
CVE-2026-45503 Vulnerability in ssrf (CVE-2026-45503)
vulnerability in ssrf (CVE-2026-45503). Confidential information can be exposed externally.
CVE-2026-42897 KEV [KEV] Cross-Site Scripting (XSS) in Microsoft exchange-server (CVE-2026-42897)
cross-site scripting in Microsoft exchange-server (CVE-2026-42897). Confidential information can be exposed externally. Listed in CISA KEV — actively exploited.
CVE-2023-21529 KEV [KEV] Unsafe Deserialization in Microsoft exchange-server (CVE-2023-21529)
vulnerability in Microsoft exchange-server (CVE-2023-21529). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2026-21527 Vulnerability in microsoft (CVE-2026-21527)
vulnerability in microsoft (CVE-2026-21527). Risk of unauthorized operations or information disclosure.
CVE-2025-64667 Vulnerability in microsoft (CVE-2025-64667)
vulnerability in microsoft (CVE-2025-64667). Risk of unauthorized operations or information disclosure.
CVE-2025-64666 Vulnerability in microsoft (CVE-2025-64666)
vulnerability in microsoft (CVE-2025-64666). Successful exploitation can lead to full system takeover.
CVE-2025-59249 Vulnerability in microsoft (CVE-2025-59249)
vulnerability in microsoft (CVE-2025-59249). Successful exploitation can lead to full system takeover.
CVE-2025-59248 Vulnerability in microsoft (CVE-2025-59248)
vulnerability in microsoft (CVE-2025-59248). Confidential information can be exposed externally.
CVE-2025-53782 Vulnerability in microsoft (CVE-2025-53782)
vulnerability in microsoft (CVE-2025-53782). Successful exploitation can lead to full system takeover.
CVE-2025-33051 Information Disclosure in microsoft (CVE-2025-33051)
vulnerability in microsoft (CVE-2025-33051). Confidential information can be exposed externally.
CVE-2025-25005 Vulnerability in microsoft (CVE-2025-25005)
vulnerability in microsoft (CVE-2025-25005). Confidential information can be exposed externally.
CVE-2025-53786 Authentication Bypass in microsoft (CVE-2025-53786)
authentication bypass in microsoft (CVE-2025-53786). Successful exploitation can lead to full system takeover.
CVE-2024-21410 KEV [KEV] Authentication Bypass in Microsoft exchange-server (CVE-2024-21410)
authentication bypass in Microsoft exchange-server (CVE-2024-21410). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2023-38185 Microsoft Exchange Server Remote Code Execution Vulnerability
Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2023-38181 Microsoft Exchange Server Spoofing Vulnerability
Microsoft Exchange Server Spoofing Vulnerability
CVE-2023-38182 Microsoft Exchange Server Remote Code Execution Vulnerability
Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2023-35388 Microsoft Exchange Server Remote Code Execution Vulnerability
Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2023-35368 Microsoft Exchange Remote Code Execution Vulnerability
Microsoft Exchange Remote Code Execution Vulnerability
CVE-2023-21707 Microsoft Exchange Server Remote Code Execution Vulnerability
Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2023-21706 Microsoft Exchange Server Remote Code Execution Vulnerability
Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2022-41040 KEV [KEV] SSRF (Server-Side Request Forgery) in Microsoft exchange-server (CVE-2022-41040)
SSRF in Microsoft exchange-server (CVE-2022-41040). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2022-41082 KEV [KEV] Unsafe Deserialization in Microsoft exchange-server (CVE-2022-41082)
vulnerability in Microsoft exchange-server (CVE-2022-41082). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2021-33766 KEV [KEV] Authentication Bypass in Microsoft exchange-server (CVE-2021-33766)
authentication bypass in Microsoft exchange-server (CVE-2021-33766). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2021-42321 KEV [KEV] Vulnerability in Microsoft exchange (CVE-2021-42321)
vulnerability in Microsoft exchange (CVE-2021-42321). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2020-17144 KEV [KEV] Unsafe Deserialization in Microsoft exchange-server (CVE-2020-17144)
vulnerability in Microsoft exchange-server (CVE-2020-17144). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2021-34523 KEV [KEV] Privilege Escalation in Microsoft exchange-server (CVE-2021-34523)
vulnerability in Microsoft exchange-server (CVE-2021-34523). Confidential information can be exposed externally. Listed in CISA KEV — actively exploited.
CVE-2021-27065 KEV [KEV] Path Traversal in Microsoft exchange-server (CVE-2021-27065)
path traversal in Microsoft exchange-server (CVE-2021-27065). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2020-0688 KEV [KEV] Authentication Bypass in Microsoft exchange-server (CVE-2020-0688)
authentication bypass in Microsoft exchange-server (CVE-2020-0688). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2021-34473 KEV [KEV] SSRF (Server-Side Request Forgery) in Microsoft exchange-server (CVE-2021-34473)
SSRF in Microsoft exchange-server (CVE-2021-34473). Confidential information can be exposed externally. Listed in CISA KEV — actively exploited.
CVE-2021-31207 KEV [KEV] Vulnerability in Microsoft exchange-server (CVE-2021-31207)
vulnerability in Microsoft exchange-server (CVE-2021-31207). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2021-26855 KEV [KEV] SSRF (Server-Side Request Forgery) in Microsoft exchange-server (CVE-2021-26855)
SSRF in Microsoft exchange-server (CVE-2021-26855). Confidential information can be exposed externally. Listed in CISA KEV — actively exploited.
CVE-2021-26857 KEV [KEV] Unsafe Deserialization in Microsoft exchange-server (CVE-2021-26857)
vulnerability in Microsoft exchange-server (CVE-2021-26857). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2017-11932 Vulnerability in microsoft (CVE-2017-11932)
vulnerability in microsoft (CVE-2017-11932). Confidential information can be exposed externally.
CVE-2017-11940 Buffer Overflow in microsoft (CVE-2017-11940)
vulnerability in microsoft (CVE-2017-11940). Successful exploitation can lead to full system takeover.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →