Vulnerabilities
Vulnerable Software
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to perform spoofing over a network.
CVSS Score
6.5
EPSS Score
0.003
Published
2026-06-09
CVE-2026-42897
Known exploited
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
CVSS Score
8.1
EPSS Score
0.056
Published
2026-05-14
User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
CVSS Score
6.5
EPSS Score
0.077
Published
2026-02-10
User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
CVSS Score
5.3
EPSS Score
0.008
Published
2025-12-09
Improper input validation in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
CVSS Score
7.5
EPSS Score
0.01
Published
2025-12-09
Weak authentication in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
CVSS Score
8.8
EPSS Score
0.008
Published
2025-10-14
Improper input validation in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
CVSS Score
7.5
EPSS Score
0.009
Published
2025-10-14
Incorrect implementation of authentication algorithm in Microsoft Exchange Server allows an unauthorized attacker to elevate privileges locally.
CVSS Score
8.4
EPSS Score
0.003
Published
2025-10-14


Contact Us

Shodan ® - All rights reserved