VendorsMicrosoftedgeany version
Vulnerabilities

Microsoft Edge any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

763CVEs
CVE-2016-3198
Microsoft Edge allows remote attackers to bypass the Content Security Policy (CSP) protection mechanism via a crafted document, aka "Microsoft Edge Security Feature Bypass."
Published 2016-06-16 · Modified
6.5EPSS 0.325
CVE-2016-3351
Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to obtain sensitive information via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability."
Published 2016-09-14 · Analyzed
6.5KEVEPSS 0.263
CVE-2016-3374
The PDF library in Microsoft Edge, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows remote attackers to obtain sensitive information via a crafted web site, aka "PDF Library Information Disclosure Vulnerability," a different vulnerability than CVE-2016-3370.
Published 2016-09-14 · Modified
6.5EPSS 0.258
CVE-2016-3201
Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows 10 Gold and 1511, and Microsoft Edge allow remote attackers to obtain sensitive information from process memory via a crafted PDF document, aka "Windows PDF Information Disclosure Vulnerability," a different vulnerability than CVE-2016-3215.
Published 2016-06-16 · Modified
6.5EPSS 0.236
CVE-2017-8652
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to disclose information due to the way that Microsoft Edge handles objects in memory, aka "Microsoft Edge Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-8644 and CVE-2017-8662.
Published 2017-08-08 · Modified
6.51 PoCEPSS 0.229
CVE-2016-3370
The PDF library in Microsoft Edge, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows remote attackers to obtain sensitive information via a crafted web site, aka "PDF Library Information Disclosure Vulnerability," a different vulnerability than CVE-2016-3374.
Published 2016-09-14 · Modified
6.5EPSS 0.222
CVE-2016-3271
The VBScript engine in Microsoft Edge allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Scripting Engine Information Disclosure Vulnerability."
Published 2016-07-13 · Modified
6.5EPSS 0.209
CVE-2017-0196
An information disclosure vulnerability in Microsoft scripting engine allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability."
Published 2017-07-14 · Modified
6.5EPSS 0.182
CVE-2016-0158
Microsoft Edge allows remote attackers to bypass the Same Origin Policy via unspecified vectors, aka "Microsoft Edge Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-0161.
Published 2016-04-12 · Modified
6.5EPSS 0.151
CVE-2017-8529
Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, and Windows Server 2012 and R2 allow an attacker to detect specific files on the user's computer when affected Microsoft scripting engines do not properly handle objects in memory, aka "Microsoft Browser Information Disclosure Vulnerability".
Published 2017-06-15 · Modified
6.5EPSS 0.142
CVE-2017-8611
Microsoft Edge on Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows remote attackers to spoof web content via a crafted web site, aka "Microsoft Edge Spoofing Vulnerability."
Published 2017-07-11 · Modified
6.5EPSS 0.115
CVE-2017-8592
Microsoft browsers on when Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1, Windows RT 8.1, and Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow a security feature bypass vulnerability when they improperly handle redirect requests, aka "Microsoft Browser Security Feature Bypass".
Published 2017-07-11 · Modified
6.5EPSS 0.080
CVE-2018-8351
An information disclosure vulnerability exists when affected Microsoft browsers improperly allow cross-frame interaction, aka "Microsoft Browser Information Disclosure Vulnerability." This affects Internet Explorer 11, Microsoft Edge, Internet Explorer 10.
Published 2018-08-15 · Modified
6.5EPSS 0.079
CVE-2019-0658
An information disclosure vulnerability exists when the scripting engine does not properly handle objects in memory in Microsoft Edge, aka 'Scripting Engine Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0648.
Published 2019-03-06 · Modified
6.5EPSS 0.077
CVE-2017-11872
Microsoft Edge in Microsoft Windows 10 1607, 1703, and Windows Server 2016 allows an attacker to force the browser to send data that would otherwise be restricted to a destination website of the attacker's choice, due to how Microsoft Edge handles redirect requests, aka "Microsoft Edge Security Feature Bypass Vulnerability". This CVE ID is unique from CVE-2017-11863 and CVE-2017-11874.
Published 2017-11-15 · Modified
6.5EPSS 0.072
CVE-2019-0833
An information disclosure vulnerability exists when Microsoft Edge improperly handles objects in memory, aka 'Microsoft Edge Information Disclosure Vulnerability'.
Published 2019-04-09 · Modified
6.5EPSS 0.071
CVE-2019-0746
An information disclosure vulnerability exists when the scripting engine does not properly handle objects in memory in Microsoft Edge, aka 'Scripting Engine Information Disclosure Vulnerability'.
Published 2019-04-08 · Modified
6.5EPSS 0.066
CVE-2019-1356
An information disclosure vulnerability exists when Microsoft Edge based on Edge HTML improperly handles objects in memory, aka 'Microsoft Edge based on Edge HTML Information Disclosure Vulnerability'.
Published 2019-10-10 · Modified
6.5EPSS 0.062
CVE-2019-1299
An information disclosure vulnerability exists when Microsoft Edge based on Edge HTML improperly handles objects in memory, aka 'Microsoft Edge based on Edge HTML Information Disclosure Vulnerability'.
Published 2019-09-11 · Modified
6.5EPSS 0.058
CVE-2018-8276
A security feature bypass vulnerability exists in the Microsoft Chakra scripting engine that allows Control Flow Guard (CFG) to be bypassed, aka "Scripting Engine Security Feature Bypass Vulnerability." This affects Microsoft Edge, ChakraCore.
Published 2018-07-11 · Modified
6.5EPSS 0.056
CVE-2021-30615
Chromium: CVE-2021-30615 Cross-origin data leak in Navigation
Published 2021-09-03 · Modified
6.5EPSS 0.056
CVE-2021-21141
Insufficient policy enforcement in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass file extension policy via a crafted HTML page.
Published 2021-02-09 · Modified
6.5EPSS 0.054
CVE-2019-0990
Chakra Scripting Engine Memory Corruption Vulnerability
Published 2019-06-12 · Modified
6.5EPSS 0.054
CVE-2019-1023
Scripting Engine Information Disclosure Vulnerability
Published 2019-06-12 · Modified
6.5EPSS 0.054
CVE-2017-8602
Microsoft browsers on Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow a spoofing vulnerability in the way they parse HTTP content, aka "Microsoft Browser Spoofing Vulnerability."
Published 2017-07-11 · Modified
6.5EPSS 0.053
CVE-2020-1433
An information disclosure vulnerability exists when Microsoft Edge PDF Reader improperly handles objects in memory, aka 'Microsoft Edge PDF Information Disclosure Vulnerability'.
Published 2020-07-14 · Modified
6.5EPSS 0.053
CVE-2017-8599
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an attacker to trick a user into loading a page with malicious content when the Edge Content Security Policy (CSP) fails to properly validate certain specially crafted documents, aka "Microsoft Edge Security Feature Bypass Vulnerability".
Published 2017-07-11 · Modified
6.5EPSS 0.051
CVE-2021-30617
Chromium: CVE-2021-30617 Policy bypass in Blink
Published 2021-09-03 · Modified
6.5EPSS 0.037
CVE-2019-0764
A tampering vulnerability exists when Microsoft browsers do not properly validate input under specific conditions, aka 'Microsoft Browsers Tampering Vulnerability'.
Published 2019-04-09 · Modified
6.5EPSS 0.036
CVE-2021-30621
Chromium: CVE-2021-30621 UI Spoofing in Autofill
Published 2021-09-03 · Modified
6.5EPSS 0.035
CVE-2021-30619
Chromium: CVE-2021-30619 UI Spoofing in Autofill
Published 2021-09-03 · Modified
6.5EPSS 0.035
CVE-2019-1081
Microsoft Browser Information Disclosure Vulnerability
Published 2019-06-12 · Modified
6.5EPSS 0.023
CVE-2024-38222
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
Published 2024-09-12 · Analyzed
6.5EPSS 0.012
CVE-2017-0017
The RegEx class in the XSS filter in Microsoft Edge allows remote attackers to conduct cross-site scripting (XSS) attacks and obtain sensitive information via unspecified vectors, aka "Microsoft Edge Information Disclosure Vulnerability." This vulnerability is different from those described in CVE-2017-0009, CVE-2017-0011, CVE-2017-0065, and CVE-2017-0068.
Published 2017-03-17 · Modified
6.1EPSS 0.420
CVE-2016-7206
Cross-site scripting (XSS) vulnerability in Microsoft Edge allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "Microsoft Edge Information Disclosure Vulnerability," a different vulnerability than CVE-2016-7280.
Published 2016-12-20 · Modified
6.1EPSS 0.116
CVE-2016-7282
Cross-site scripting (XSS) vulnerability in Microsoft Internet Explorer 9 through 11 and Microsoft Edge allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "Microsoft Browser Information Disclosure Vulnerability."
Published 2016-12-20 · Modified
6.1EPSS 0.103
CVE-2016-7280
Cross-site scripting (XSS) vulnerability in Microsoft Edge allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "Microsoft Edge Information Disclosure Vulnerability," a different vulnerability than CVE-2016-7206.
Published 2016-12-20 · Modified
6.1EPSS 0.094
CVE-2018-8278
A spoofing vulnerability exists when Microsoft Edge improperly handles specific HTML content, aka "Microsoft Edge Spoofing Vulnerability." This affects Microsoft Edge.
Published 2018-07-11 · Modified
6.1EPSS 0.069
CVE-2017-11863
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to trick a user into loading a page containing malicious content, due to how the Edge Content Security Policy (CSP) validates documents, aka "Microsoft Edge Security Feature Bypass Vulnerability". This CVE ID is unique from CVE-2017-11872 and CVE-2017-11874.
Published 2017-11-15 · Modified
6.1EPSS 0.035
CVE-2017-8642
Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to elevate privileges due to the way that Microsoft Edge validates JavaScript under specific conditions, aka "Microsoft Edge Elevation of Privilege Vulnerability". This CVE ID is unique from CVE-2017-8503.
Published 2017-08-08 · Modified
6.1EPSS 0.030
← Prev15 / 20Next →