Known vulnerabilities in Microsoft Exchange Server - page 5

Vendor: Microsoft
Software CPE: cpe:2.3:a:microsoft:microsoft_exchange_server:*:*:*:*:*:*:*:*
Total vulnerabilities: 216
Public exploits: 36
Known exploited (KEV): 20
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Microsoft Exchange Server Microsoft Exchange Server is affected by 216 known vulnerabilities: 8 critical, 46 high, 102 medium, 60 low Critical High Medium Low

Vulnerabilities (216)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU58069 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVE-2021-42305
CWE-451 Medium
No
No
- 09.11.2021 SB2021110940
#VU58068 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVE-2021-41349
CWE-451 Medium
Available
No
- 09.11.2021 SB2021110940
#VU58055 - Improper input validation
CVE-2021-42321
CWE-20 Critical
Available
Exploited
- 09.11.2021 SB2021110928
#VU57255 - Permissions, Privileges, and Access Controls
CVE-2021-26427
CWE-264 Medium
No
No
- 12.10.2021 SB2021101214
#VU57254 - Improper input validation
CVE-2021-34453
CWE-20 Medium
No
No
- 12.10.2021 SB2021101214
#VU57252 - Permissions, Privileges, and Access Controls
CVE-2021-41348
CWE-264 Medium
No
No
- 12.10.2021 SB2021101214
#VU57251 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-41350
CWE-79 Medium
No
No
- 12.10.2021 SB2021101214
#VU54766 - Improper Authentication
CVE-2021-33766
CWE-287 Medium
Available
Exploited
- 13.07.2021 SB2021071342
#VU54712 - Permissions, Privileges, and Access Controls
CVE-2021-34470
CWE-264 Low
No
No
- 13.07.2021 SB2021071319
#VU54709 - Permissions, Privileges, and Access Controls
CVE-2021-33768
CWE-264 Low
No
No
- 13.07.2021 SB2021071319
#VU54705 - Improper Control of Generation of Code ('Code Injection')
CVE-2021-34473
CWE-94 High
Available
Exploited
- 13.07.2021 SB2021071319
#VU54704 - Permissions, Privileges, and Access Controls
CVE-2021-34523
CWE-264 Low
Available
Exploited
- 13.07.2021 SB2021071319
#VU54703 - Improper Control of Generation of Code ('Code Injection')
CVE-2021-31206
CWE-94 High
No
No
- 13.07.2021 SB2021071319
#VU54702 - Improper Control of Generation of Code ('Code Injection')
CVE-2021-31196
CWE-94 Low
Available
Exploited
- 13.07.2021 SB2021071319
#VU53085 - Security Features
CVE-2021-31207
CWE-254 Low
Available
Exploited
- 11.05.2021 SB2021051112
#VU53084 - Improper Control of Generation of Code ('Code Injection')
CVE-2021-31198
CWE-94 High
No
No
- 11.05.2021 SB2021051112
#VU53083 - Improper Control of Generation of Code ('Code Injection')
CVE-2021-31195
CWE-94 High
Available
No
- 11.05.2021 SB2021051112
#VU53082 - Improper Validation of Integrity Check Value
CVE-2021-31209
CWE-354 Medium
No
No
- 11.05.2021 SB2021051112
#VU52141 - Improper Control of Generation of Code ('Code Injection')
CVE-2021-28483
CWE-94 Low
Available
No
2013 Cumulative Update 23 Apr21SU 15.00.1497.015, 2016 Cumulative Update 19 Apr21SU 15.01.2176.012, 2016 Cumulative Update 20 Apr21SU 15.01.2242.008, 2019 Cumulative Update 8 Apr21SU 15.02.0792.013, 2019 Cumulative Update 9 Apr21SU 15.02.0858.010 13.04.2021 SB2021041327
#VU52138 - Improper Control of Generation of Code ('Code Injection')
CVE-2021-28480
CWE-94 High
Available
No
2013 Cumulative Update 23 Apr21SU 15.00.1497.015, 2016 Cumulative Update 19 Apr21SU 15.01.2176.012, 2016 Cumulative Update 20 Apr21SU 15.01.2242.008, 2019 Cumulative Update 8 Apr21SU 15.02.0792.013, 2019 Cumulative Update 9 Apr21SU 15.02.0858.010 13.04.2021 SB2021041327


Showing elements 81 - 100 out of 216