Known Vulnerabilities for Exchange by Ithemes
Listed below are 1 of the newest known vulnerabilities associated with "Exchange" by "Ithemes".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-55653 json | A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in the Diffie-Hellman Group Excha... | Not Provided | 2026-06-23 | 2026-06-23 |
| CVE-2026-55199 json | libssh2 through 1.11.1, fixed in commit 1762685, contains a pre-authentication denial of service vulnerability in the SSH_MSG... | Not Provided | 2026-06-17 | 2026-06-18 |
| CVE-2026-53928 json | NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, a stolen refresh token survived a password-for... | Not Provided | 2026-06-23 | 2026-06-24 |
| CVE-2026-50752 json | A weakness in the certificate validation logic of the deprecated IKEv1 key exchange may allow an unauthenticated attacker pos... | Not Provided | 2026-06-08 | 2026-06-08 |
| CVE-2026-50751 json | A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an un... | Not Provided | 2026-06-08 | 2026-06-09 |
| CVE-2026-49323 json | Weak authentication between the Wireless Control Module (WCM) and the Engine Control Module (ECM) of the Indian Motorcycle Sc... | Not Provided | 2026-05-29 | 2026-05-29 |
| CVE-2026-49322 json | Weak authentication in the Wireless Control Module (WCM) of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows ... | Not Provided | 2026-05-29 | 2026-05-29 |
| CVE-2026-48582 json | Missing authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network. | Not Provided | 2026-06-19 | 2026-06-24 |
| CVE-2026-48579 json | Improper authorization in Microsoft Exchange Online allows an unauthorized attacker to disclose information over a network. | Not Provided | 2026-06-04 | 2026-06-04 |
| CVE-2026-47631 json | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an u... | Not Provided | 2026-06-09 | 2026-06-10 |