VendorsMicrosoftedgeall versions
Vulnerabilities

Microsoft Edge

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

764CVEs
CVE-2017-11919
ChakraCore, and Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 R2, and Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016, and Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to obtain information to further compromise the user's system, due to how the scripting engine handles objects in memory, aka "Scripting Engine Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-11887 and CVE-2017-11906.
Published 2017-12-12 · Modified
5.3EPSS 0.064
CVE-2017-8637
Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to bypass Arbitrary Code Guard (ACG) due to how Microsoft Edge accesses memory in code compiled by the Edge Just-In-Time (JIT) compiler, aka "Scripting Engine Security Feature Bypass Vulnerability".
Published 2017-08-08 · Modified
5.3EPSS 0.050
CVE-2020-1242
An information disclosure vulnerability exists in the way that Microsoft Edge handles cross-origin requests, aka 'Microsoft Edge Information Disclosure Vulnerability'.
Published 2020-06-09 · Modified
5.3EPSS 0.038
CVE-2025-21253
Microsoft Edge for IOS and Android Spoofing Vulnerability
Published 2025-02-06 · Analyzed
5.3EPSS 0.012
CVE-2019-1054
Microsoft Edge Security Feature Bypass Vulnerability
Published 2019-06-12 · Modified
5.1EPSS 0.016
CVE-2015-6057
Microsoft Edge allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Microsoft Edge Information Disclosure Vulnerability."
Published 2015-10-14 · Modified
5.0EPSS 0.159
CVE-2021-24100
Microsoft Edge for Android Information Disclosure Vulnerability
Published 2021-02-25 · Modified
5.0EPSS 0.031
CVE-2024-26247
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
Published 2024-03-22 · Modified
4.7EPSS 0.011
CVE-2025-29796
Microsoft Edge for iOS Spoofing Vulnerability
Published 2025-04-04 · Analyzed
4.7EPSS 0.006
CVE-2024-38082
Microsoft Edge (Chromium-based) Spoofing Vulnerability
Published 2024-06-20 · Modified
4.7EPSS 0.005
CVE-2025-47967
Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability
Published 2025-09-16 · Analyzed
4.7EPSS 0.004
CVE-2015-6058
Microsoft Edge mishandles HTML attributes in HTTP responses, which allows remote attackers to bypass a cross-site scripting (XSS) protection mechanism via unspecified vectors, aka "Microsoft Edge XSS Filter Bypass."
Published 2015-10-14 · Modified
4.3EPSS 0.700
CVE-2017-0011
Microsoft Edge allows remote attackers to obtain sensitive information via a crafted web site, aka "Microsoft Edge Information Disclosure Vulnerability." This vulnerability is different from those described in CVE-2017-0009, CVE-2017-0017, CVE-2017-0065, and CVE-2017-0068.
Published 2017-03-17 · Modified
4.3EPSS 0.424
CVE-2015-6088
Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Microsoft Browser ASLR Bypass."
Published 2015-11-11 · Modified
4.3EPSS 0.305
CVE-2017-0065
Microsoft Edge allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability." This vulnerability is different from those described in CVE-2017-0009, CVE-2017-0011, CVE-2017-0017, and CVE-2017-0068.
Published 2017-03-17 · Modified
4.3EPSS 0.274
CVE-2016-3244
Microsoft Edge allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Microsoft Edge Security Feature Bypass."
Published 2016-07-13 · Modified
4.3EPSS 0.188
CVE-2015-2449
Microsoft Internet Explorer 7 through 11 and Edge allow remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "ASLR Bypass."
Published 2015-08-14 · Modified
4.3EPSS 0.156
CVE-2017-0208
An information disclosure vulnerability exists in Microsoft Edge when the Chakra scripting engine does not properly handle objects in memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user's system, a.k.a. "Scripting Engine Information Disclosure Vulnerability."
Published 2017-04-12 · Modified
4.3EPSS 0.153
CVE-2017-0068
Browsers in Microsoft Edge allow remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Microsoft Edge Information Disclosure Vulnerability." This vulnerability is different from those described in CVE-2017-0009, CVE-2017-0011, CVE-2017-0017, and CVE-2017-0065.
Published 2017-03-17 · Modified
4.3EPSS 0.152
CVE-2017-8644
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to disclose information due to the way that Microsoft Edge handles objects in memory, aka "Microsoft Edge Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-8652 and CVE-2017-8662.
Published 2017-08-08 · Modified
4.31 PoCEPSS 0.151
CVE-2016-0080
Microsoft Edge mishandles exceptions during window-message dispatch operations, which allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Microsoft Edge ASLR Bypass."
Published 2016-02-10 · Modified
4.3EPSS 0.150
CVE-2018-0891
ChakraCore, and Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, and Internet Explorer and Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allow information disclosure, due to how the scripting engine handles objects in memory, aka "Scripting Engine Information Disclosure Vulnerability". This CVE ID is unique from CVE-2018-0939.
Published 2018-03-14 · Modified
4.31 PoCEPSS 0.142
CVE-2015-6176
Microsoft Edge mishandles HTML attributes in HTTP responses, which allows remote attackers to bypass a cross-site scripting (XSS) protection mechanism via unspecified vectors, aka "Microsoft Edge XSS Filter Bypass Vulnerability."
Published 2015-12-09 · Modified
4.31 PoCEPSS 0.140
CVE-2017-8555
Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to trick a user into loading a page with malicious content when the Edge Content Security Policy (CSP) fails to properly validate certain specially crafted documents, aka "Microsoft Edge Security Feature Bypass Vulnerability". This CVE ID is unique from CVE-2017-8523 and CVE-2017-8530.
Published 2017-06-15 · Modified
4.3EPSS 0.125
CVE-2018-8289
An information disclosure vulnerability exists when Microsoft Edge improperly handles objects in memory, aka "Microsoft Edge Information Disclosure Vulnerability." This affects Microsoft Edge. This CVE ID is unique from CVE-2018-8297, CVE-2018-8324, CVE-2018-8325.
Published 2018-07-11 · Modified
4.3EPSS 0.100
CVE-2018-8297
An information disclosure vulnerability exists when Microsoft Edge improperly handles objects in memory, aka "Microsoft Edge Information Disclosure Vulnerability." This affects Microsoft Edge. This CVE ID is unique from CVE-2018-8289, CVE-2018-8324, CVE-2018-8325.
Published 2018-07-11 · Modified
4.3EPSS 0.100
CVE-2018-8324
An information disclosure vulnerability exists when Microsoft Edge improperly handles objects in memory, aka "Microsoft Edge Information Disclosure Vulnerability." This affects Microsoft Edge. This CVE ID is unique from CVE-2018-8289, CVE-2018-8297, CVE-2018-8325.
Published 2018-07-11 · Modified
4.3EPSS 0.100
CVE-2016-0077
Microsoft Internet Explorer 9 through 11 and Microsoft Edge misparse HTTP responses, which allows remote attackers to spoof web sites via a crafted URL, aka "Microsoft Browser Spoofing Vulnerability."
Published 2016-02-10 · Modified
4.3EPSS 0.097
CVE-2015-6169
Microsoft Edge misparses HTTP responses, which allows remote attackers to redirect users to arbitrary web sites via unspecified vectors, aka "Microsoft Edge Spoofing Vulnerability."
Published 2015-12-09 · Modified
4.3EPSS 0.093
CVE-2017-0069
Microsoft Edge allows remote attackers to spoof web content via a crafted web site, aka "Microsoft Edge Spoofing Vulnerability." This vulnerability is different from those described in CVE-2017-0012 and CVE-2017-0033.
Published 2017-03-17 · Modified
4.3EPSS 0.086
CVE-2017-8736
Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 R2, and Microsoft Edge and Internet Explorer in Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allow an attacker to obtain specific information used in the parent domain, due to Microsoft browser parent domain verification in certain functionality, aka "Microsoft Browser Information Disclosure Vulnerability".
Published 2017-09-13 · Modified
4.3EPSS 0.084
CVE-2018-0766
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to obtain information to further compromise the user's system, due to how the Microsoft Edge PDF Reader handles objects in memory, aka "Microsoft Edge Information Disclosure Vulnerability".
Published 2018-01-04 · Modified
4.3EPSS 0.083
CVE-2017-0033
Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to spoof web content via a crafted web site, aka "Microsoft Browser Spoofing Vulnerability." This vulnerability is different from those described in CVE-2017-0012 and CVE-2017-0069.
Published 2017-03-17 · Modified
4.3EPSS 0.081
CVE-2017-0012
Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to spoof web content via a crafted web site, aka "Microsoft Browser Spoofing Vulnerability." This vulnerability is different from those described in CVE-2017-0033 and CVE-2017-0069.
Published 2017-03-17 · Modified
4.3EPSS 0.076
CVE-2017-8726
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to how affected Microsoft scripting engines handle objects in memory, aka "Microsoft Edge Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-11794 and CVE-2017-11803.
Published 2017-10-13 · Modified
4.3EPSS 0.072
CVE-2018-8383
A spoofing vulnerability exists when Microsoft Edge does not properly parse HTTP content, aka "Microsoft Edge Spoofing Vulnerability." This affects Microsoft Edge. This CVE ID is unique from CVE-2018-8388.
Published 2018-08-15 · Modified
4.3EPSS 0.068
CVE-2018-0871
An information disclosure vulnerability exists when Edge improperly marks files, aka "Microsoft Edge Information Disclosure Vulnerability." This affects Microsoft Edge. This CVE ID is unique from CVE-2018-8234.
Published 2018-06-14 · Modified
4.3EPSS 0.063
CVE-2018-8234
An information disclosure vulnerability exists when Microsoft Edge improperly handles objects in memory, aka "Microsoft Edge Information Disclosure Vulnerability." This affects Microsoft Edge. This CVE ID is unique from CVE-2018-0871.
Published 2018-06-14 · Modified
4.3EPSS 0.063
CVE-2018-1021
An information disclosure vulnerability exists when Microsoft Edge improperly handles objects in memory, aka "Microsoft Edge Information Disclosure Vulnerability." This affects Microsoft Edge. This CVE ID is unique from CVE-2018-8123.
Published 2018-05-09 · Modified
4.3EPSS 0.062
CVE-2018-1025
An information disclosure vulnerability exists when affected Microsoft browsers improperly handle objects in memory, aka "Microsoft Browser Information Disclosure Vulnerability." This affects Internet Explorer 11, Microsoft Edge.
Published 2018-05-09 · Modified
4.3EPSS 0.062
← Prev17 / 20Next →