VulnSea

exchange_server_subscription_edition vulnerabilities

CVEs whose affected-version data names the exchange_server_subscription_edition package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

7 CVEsRSS

CVE-2026-47631High· 8.1
3mo ago

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

Twilightmicrosoft · exchange_serverEPSS 0.35%via NVD
CVE-2026-45583High· 7.5
3mo ago

Improper control of generation of code ('code injection') in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network.

Improper control of generation of code ('code injection') in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network.

Twilightmicrosoft · exchange_serverEPSS 0.52%via NVD
CVE-2026-45504High· 8.8PoC
3mo ago

Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

Midnightmicrosoft · exchange_serverEPSS 0.85%via NVD
CVE-2026-45503High· 8.1
3mo ago

Improper authorization in Microsoft Exchange Server allows an authorized attacker to disclose information over a network.

Improper authorization in Microsoft Exchange Server allows an authorized attacker to disclose information over a network.

Twilightmicrosoft · exchange_serverEPSS 0.45%via NVD
CVE-2026-45502Medium· 5.0
3mo ago

Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to disclose information over a network.

Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to disclose information over a network.

Sunlitmicrosoft · exchange_serverEPSS 20%via NVD
CVE-2026-45501Medium· 6.5
3mo ago

Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.

Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.

Sunlitmicrosoft · exchange_serverEPSS 0.31%via NVD
CVE-2026-45500Medium· 6.1
3mo ago

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

Sunlitmicrosoft · exchange_serverEPSS 0.38%via NVD
exchange_server_subscription_edition vulnerabilities (CVEs) · VulnSea