VendorsMicrosoftedgeall versions
Vulnerabilities

Microsoft Edge

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

764CVEs
CVE-2017-8642
Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to elevate privileges due to the way that Microsoft Edge validates JavaScript under specific conditions, aka "Microsoft Edge Elevation of Privilege Vulnerability". This CVE ID is unique from CVE-2017-8503.
Published 2017-08-08 · Modified
6.1EPSS 0.030
CVE-2020-17153
Microsoft Edge for Android Spoofing Vulnerability
Published 2020-12-09 · Modified
6.1EPSS 0.022
CVE-2020-1220
A spoofing vulnerability exists when theMicrosoft Edge (Chromium-based) in IE Mode improperly handles specific redirects, aka 'Microsoft Edge (Chromium-based) in IE Mode Spoofing Vulnerability'.
Published 2020-06-09 · Modified
6.1EPSS 0.018
CVE-2021-38641
Microsoft Edge for Android Spoofing Vulnerability
Published 2021-09-02 · Modified
6.1EPSS 0.012
CVE-2021-38642
Microsoft Edge for iOS Spoofing Vulnerability
Published 2021-09-02 · Modified
6.1EPSS 0.012
CVE-2024-38156
Microsoft Edge (Chromium-based) Spoofing Vulnerability
Published 2024-07-18 · Modified
6.1EPSS 0.004
CVE-2024-38208
Microsoft Edge for Android Spoofing Vulnerability
Published 2024-08-22 · Modified
6.1EPSS 0.004
CVE-2019-0641
A security feature bypass vulnerability exists in Microsoft Edge handles whitelisting, aka 'Microsoft Edge Security Feature Bypass Vulnerability'.
Published 2019-03-06 · Modified
5.9EPSS 0.034
CVE-2021-26439
Microsoft Edge for Android Information Disclosure Vulnerability
Published 2021-09-02 · Modified
5.9EPSS 0.029
CVE-2020-1195
An elevation of privilege vulnerability exists in Microsoft Edge (Chromium-based) when the Feedback extension improperly validates input, aka 'Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability'.
Published 2020-05-21 · Modified
5.9EPSS 0.020
CVE-2024-38103
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
Published 2024-07-25 · Modified
5.9EPSS 0.005
CVE-2018-0803
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to access information from one domain and inject it into another domain, due to how Microsoft Edge enforces cross-domain policies, aka "Microsoft Edge Elevation of Privilege Vulnerability".
Published 2018-01-04 · Modified
5.8EPSS 0.037
CVE-2018-8512
A security feature bypass vulnerability exists in Microsoft Edge when the Edge Content Security Policy (CSP) fails to properly validate certain specially crafted documents, aka "Microsoft Edge Security Feature Bypass Vulnerability." This affects Microsoft Edge. This CVE ID is unique from CVE-2018-8530.
Published 2018-10-10 · Modified
5.8EPSS 0.035
CVE-2018-8567
An elevation of privilege vulnerability exists when Microsoft Edge does not properly enforce cross-domain policies, which could allow an attacker to access information from one domain and inject it into another domain, aka "Microsoft Edge Elevation of Privilege Vulnerability." This affects Microsoft Edge.
Published 2018-11-14 · Modified
5.8EPSS 0.031
CVE-2017-8530
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an attacker to trick a user into loading a page with malicious content when Microsoft Edge does not properly enforce same-origin policies, aka "Microsoft Edge Security Feature Bypass Vulnerability". This CVE ID is unique from CVE-2017-8523 and CVE-2017-8555.
Published 2017-06-15 · Modified
5.8EPSS 0.017
CVE-2017-8650
Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to exploit a security feature bypass due to Microsoft Edge not properly enforcing same-origin policies, aka "Microsoft Edge Security Feature Bypass Vulnerability".
Published 2017-08-08 · Modified
5.8EPSS 0.015
CVE-2016-3215
Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows 10 1511, and Microsoft Edge allow remote attackers to obtain sensitive information from process memory via a crafted PDF document, aka "Windows PDF Information Disclosure Vulnerability," a different vulnerability than CVE-2016-3201.
Published 2016-06-16 · Modified
5.5EPSS 0.336
CVE-2025-62224
Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability
Published 2026-01-07 · Analyzed
5.5EPSS 0.003
CVE-2017-0241
An elevation of privilege vulnerability exists when Microsoft Edge renders a domain-less page in the URL, which could allow Microsoft Edge to perform actions in the context of the Intranet Zone and access functionality that is not typically available to the browser when browsing in the context of the Internet Zone, aka "Microsoft Edge Elevation of Privilege Vulnerability." This CVE ID is unique from CVE-2017-0233.
Published 2017-05-12 · Modified
5.4EPSS 0.029
CVE-2026-70331
Microsoft Edge for iOS Spoofing Vulnerability
Published 2026-08-28 · Analyzed
5.4EPSS 0.004
CVE-2026-62828
Microsoft Edge for Android (Chromium-based) Tampering Vulnerability
Published 2026-07-28 · Analyzed
5.4EPSS 0.004
CVE-2026-33119
Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability
Published 2026-04-10 · Analyzed
5.4EPSS 0.004
CVE-2024-30057
Microsoft Edge for iOS Spoofing Vulnerability
Published 2024-06-13 · Modified
5.4EPSS 0.004
CVE-2018-0767
Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to obtain information to further compromise the user's system, due to how the scripting engine handles objects in memory, aka "Scripting Engine Information Disclosure Vulnerability". This CVE ID is unique from CVE-2018-0780 and CVE-2018-0800.
Published 2018-01-04 · Modified
5.31 PoCEPSS 0.655
CVE-2018-0780
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to obtain information to further compromise the user's system, due to how the scripting engine handles objects in memory, aka "Scripting Engine Information Disclosure Vulnerability". This CVE ID is unique from CVE-2018-0767 and CVE-2018-0800.
Published 2018-01-04 · Modified
5.31 PoCEPSS 0.586
CVE-2016-3277
Microsoft Internet Explorer 10 and 11 and Microsoft Edge allow remote attackers to obtain sensitive information via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability."
Published 2016-07-13 · Modified
5.3EPSS 0.324
CVE-2016-3388
Microsoft Internet Explorer 10 and 11 and Microsoft Edge do not properly restrict access to private namespaces, which allows remote attackers to gain privileges via unspecified vectors, aka "Microsoft Browser Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-3387.
Published 2016-10-14 · Modified
5.31 PoCEPSS 0.276
CVE-2016-3267
Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to determine the existence of unspecified files via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability."
Published 2016-10-14 · Modified
5.3EPSS 0.159
CVE-2016-3326
Microsoft Internet Explorer 9 through 11 and Edge allow remote attackers to obtain sensitive information via a crafted web page, aka "Microsoft Browser Information Disclosure Vulnerability," a different vulnerability than CVE-2016-3327.
Published 2016-08-09 · Modified
5.3EPSS 0.158
CVE-2016-3273
The XSS Filter in Microsoft Internet Explorer 9 through 11 and Microsoft Edge does not properly restrict JavaScript code, which allows remote attackers to obtain sensitive information via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability."
Published 2016-07-13 · Modified
5.3EPSS 0.142
CVE-2016-3327
Microsoft Internet Explorer 9 through 11 and Edge allow remote attackers to obtain sensitive information via a crafted web page, aka "Microsoft Browser Information Disclosure Vulnerability," a different vulnerability than CVE-2016-3326.
Published 2016-08-09 · Modified
5.3EPSS 0.142
CVE-2016-3329
Microsoft Internet Explorer 9 through 11 and Edge allow remote attackers to determine the existence of files via a crafted webpage, aka "Internet Explorer Information Disclosure Vulnerability."
Published 2016-08-09 · Modified
5.3EPSS 0.142
CVE-2016-7152
The HTTPS protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party cookies are sent, aka a "HEIST" attack.
Published 2016-09-06 · Modified
5.3EPSS 0.140
CVE-2016-7153
The HTTP/2 protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party cookies are sent, aka a "HEIST" attack.
Published 2016-09-06 · Modified
5.3EPSS 0.140
CVE-2016-7281
The Web Workers implementation in Microsoft Internet Explorer 10 and 11 and Microsoft Edge allows remote attackers to bypass the Same Origin Policy via unspecified vectors, aka "Microsoft Browser Security Feature Bypass Vulnerability."
Published 2016-12-20 · Modified
5.3EPSS 0.137
CVE-2019-0612
A security feature bypass vulnerability exists when Click2Play protection in Microsoft Edge improperly handles flash objects. By itself, this bypass vulnerability does not allow arbitrary code execution, aka 'Microsoft Edge Security Feature Bypass Vulnerability'.
Published 2019-04-08 · Modified
5.31 PoCEPSS 0.105
CVE-2016-3392
The Edge Content Security Policy feature in Microsoft Edge does not properly validate documents, which allows remote attackers to bypass intended access restrictions via a crafted web site, aka "Microsoft Browser Security Feature Bypass Vulnerability."
Published 2016-10-14 · Modified
5.3EPSS 0.100
CVE-2016-7209
Microsoft Edge allows remote attackers to spoof web content via a crafted web site, aka "Microsoft Edge Spoofing Vulnerability."
Published 2016-11-10 · Modified
5.3EPSS 0.093
CVE-2016-3391
Microsoft Internet Explorer 10 and 11 and Microsoft Edge allow context-dependent attackers to discover credentials by leveraging access to a memory dump, aka "Microsoft Browser Information Disclosure Vulnerability."
Published 2016-10-14 · Modified
5.3EPSS 0.079
CVE-2018-0800
Microsoft Edge in Microsoft Windows 10 1709 allows an attacker to obtain information to further compromise the user's system, due to how the scripting engine handles objects in memory, aka "Scripting Engine Information Disclosure Vulnerability". This CVE ID is unique from CVE-2018-0767 and CVE-2018-0780.
Published 2018-01-04 · Modified
5.3EPSS 0.067
← Prev16 / 20Next →