VulnSea

exchange_server vulnerabilities

CVEs whose affected-version data names the exchange_server package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

19 CVEsRSS

CVE-2026-47631High· 8.1
3mo ago

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

Twilightmicrosoft · exchange_serverEPSS 0.35%via NVD
CVE-2026-45583High· 7.5
3mo ago

Improper control of generation of code ('code injection') in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network.

Improper control of generation of code ('code injection') in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network.

Twilightmicrosoft · exchange_serverEPSS 0.52%via NVD
CVE-2026-45504High· 8.8PoC
3mo ago

Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

Midnightmicrosoft · exchange_serverEPSS 0.85%via NVD
CVE-2026-45503High· 8.1
3mo ago

Improper authorization in Microsoft Exchange Server allows an authorized attacker to disclose information over a network.

Improper authorization in Microsoft Exchange Server allows an authorized attacker to disclose information over a network.

Twilightmicrosoft · exchange_serverEPSS 0.45%via NVD
CVE-2026-45502Medium· 5.0
3mo ago

Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to disclose information over a network.

Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to disclose information over a network.

Sunlitmicrosoft · exchange_serverEPSS 20%via NVD
CVE-2026-45501Medium· 6.5
3mo ago

Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.

Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.

Sunlitmicrosoft · exchange_serverEPSS 0.31%via NVD
CVE-2026-45500Medium· 6.1
3mo ago

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

Sunlitmicrosoft · exchange_serverEPSS 0.38%via NVD
CVE-2021-42321High· 8.8CISA KEVPoC
4y ago

Microsoft Exchange Server Remote Code Execution Vulnerability

Microsoft Exchange Server Remote Code Execution Vulnerability

Abyssalmicrosoft · exchange_serverEPSS 92%via NVD
CVE-2021-34523Critical· 9.0CISA KEV0dayPoC
5y ago

Microsoft Exchange Server Elevation of Privilege Vulnerability

Microsoft Exchange Server Elevation of Privilege Vulnerability

Hadalmicrosoft · exchange_serverEPSS 100%via NVD
CVE-2021-34473Critical· 9.1CISA KEV0dayPoC
5y ago

Microsoft Exchange Server Remote Code Execution Vulnerability

Microsoft Exchange Server Remote Code Execution Vulnerability

Hadalmicrosoft · exchange_serverEPSS 100%via NVD
CVE-2021-34470High· 8.0PoC
5y ago

Microsoft Exchange Server Elevation of Privilege Vulnerability

Microsoft Exchange Server Elevation of Privilege Vulnerability

Midnightmicrosoft · exchange_serverEPSS 4.4%via NVD
CVE-2021-33768High· 8.0
5y ago

Microsoft Exchange Server Elevation of Privilege Vulnerability

Microsoft Exchange Server Elevation of Privilege Vulnerability

Twilightmicrosoft · exchange_serverEPSS 1.2%via NVD
CVE-2021-33766High· 7.3CISA KEV0dayPoC
5y ago

Microsoft Exchange Server Information Disclosure Vulnerability

Microsoft Exchange Server Information Disclosure Vulnerability

Abyssalmicrosoft · exchange_serverEPSS 98%via NVD
CVE-2021-31206High· 7.6⚠ Exploited0day
5y ago

Microsoft Exchange Server Remote Code Execution Vulnerability

Microsoft Exchange Server Remote Code Execution Vulnerability

Abyssalmicrosoft · exchange_serverEPSS 13%via NVD
CVE-2021-31196High· 7.2CISA KEV
5y ago

Microsoft Exchange Server Remote Code Execution Vulnerability

Microsoft Exchange Server Remote Code Execution Vulnerability

Abyssalmicrosoft · exchange_serverEPSS 54%via NVD
CVE-2021-27065High· 7.8CISA KEV0dayPoC
5y ago

Microsoft Exchange Server Remote Code Execution Vulnerability

Microsoft Exchange Server Remote Code Execution Vulnerability

Abyssalmicrosoft · exchange_serverEPSS 100%via NVD
CVE-2021-26858High· 7.8CISA KEV0day
5y ago

Microsoft Exchange Server Remote Code Execution Vulnerability

Microsoft Exchange Server Remote Code Execution Vulnerability

Abyssalmicrosoft · exchange_serverEPSS 94%via NVD
CVE-2021-26857High· 7.8CISA KEV0dayPoC
5y ago

Microsoft Exchange Server Remote Code Execution Vulnerability

Microsoft Exchange Server Remote Code Execution Vulnerability

Abyssalmicrosoft · exchange_serverEPSS 96%via NVD
CVE-2021-26855Critical· 9.1CISA KEV0dayPoC
5y ago

Microsoft Exchange Server Remote Code Execution Vulnerability

Microsoft Exchange Server Remote Code Execution Vulnerability

Hadalmicrosoft · exchange_serverEPSS 100%via NVD
exchange_server vulnerabilities (CVEs) · VulnSea