VendorsMicrosoftedgeall versions
Vulnerabilities

Microsoft Edge

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

764CVEs
CVE-2018-8425
A spoofing vulnerability exists when Microsoft Edge improperly handles specific HTML content, aka "Microsoft Edge Spoofing Vulnerability." This affects Microsoft Edge.
Published 2018-09-13 · Modified
4.3EPSS 0.035
CVE-2018-8235
A security feature bypass vulnerability exists when Microsoft Edge improperly handles requests of different origins, aka "Microsoft Edge Security Feature Bypass Vulnerability." This affects Microsoft Edge.
Published 2018-06-14 · Modified
4.3EPSS 0.029
CVE-2018-8112
A security feature bypass vulnerability exists when Microsoft Edge improperly handles requests of different origins, aka "Microsoft Edge Security Feature Bypass Vulnerability." This affects Microsoft Edge.
Published 2018-05-09 · Modified
4.3EPSS 0.028
CVE-2019-0654
A spoofing vulnerability exists when Microsoft browsers improperly handles specific redirects, aka 'Microsoft Browser Spoofing Vulnerability'.
Published 2019-03-06 · Modified
4.3EPSS 0.028
CVE-2018-8564
A spoofing vulnerability exists when Microsoft Edge improperly handles specific HTML content, aka "Microsoft Edge Spoofing Vulnerability." This affects Microsoft Edge.
Published 2018-11-14 · Modified
4.3EPSS 0.027
CVE-2019-0608
A spoofing vulnerability exists when Microsoft Browsers does not properly parse HTTP content, aka 'Microsoft Browser Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-1357.
Published 2019-10-10 · Modified
4.3EPSS 0.023
CVE-2019-1357
A spoofing vulnerability exists when Microsoft Browsers improperly handle browser cookies, aka 'Microsoft Browser Spoofing Vulnerability'. This CVE ID is unique from CVE-2019-0608.
Published 2019-10-10 · Modified
4.3EPSS 0.023
CVE-2020-1059
A spoofing vulnerability exists when Microsoft Edge does not properly parse HTTP content, aka 'Microsoft Edge Spoofing Vulnerability'.
Published 2020-05-21 · Modified
4.3EPSS 0.021
CVE-2022-23258
Microsoft Edge for Android Spoofing Vulnerability
Published 2022-01-25 · Modified
4.3EPSS 0.016
CVE-2017-8523
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an attacker to trick a user into loading a page with malicious content when Microsoft Edge fails to correctly apply Same Origin Policy for HTML elements present in other browser windows, aka "Microsoft Edge Security Feature Bypass Vulnerability". This CVE ID is unique from CVE-2017-8530 and CVE-2017-8555.
Published 2017-06-15 · Modified
4.3EPSS 0.015
CVE-2024-26196
Microsoft Edge for Android (Chromium-based) Information Disclosure Vulnerability
Published 2024-02-29 · Modified
4.3EPSS 0.012
CVE-2019-1413
A security feature bypass vulnerability exists when Microsoft Edge improperly handles extension requests and fails to request host permission for all_urls, aka 'Microsoft Edge Security Feature Bypass Vulnerability'.
Published 2019-11-12 · Modified
4.3EPSS 0.011
CVE-2024-29057
Microsoft Edge (Chromium-based) Spoofing Vulnerability
Published 2024-03-22 · Modified
4.3EPSS 0.010
CVE-2023-36029
Microsoft Edge (Chromium-based) Spoofing Vulnerability
Published 2023-11-03 · Modified
4.3EPSS 0.010
CVE-2024-26167
Microsoft Edge for Android Spoofing Vulnerability
Published 2024-03-07 · Analyzed
4.3EPSS 0.009
CVE-2024-26188
Microsoft Edge (Chromium-based) Spoofing Vulnerability
Published 2024-02-23 · Analyzed
4.3EPSS 0.008
CVE-2023-28284
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
Published 2023-04-11 · Modified
4.3EPSS 0.008
CVE-2025-25001
Microsoft Edge for iOS Spoofing Vulnerability
Published 2025-04-04 · Analyzed
4.3EPSS 0.008
CVE-2026-35429
Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability
Published 2026-05-12 · Modified
4.3EPSS 0.007
CVE-2023-36883
Microsoft Edge for iOS Spoofing Vulnerability
Published 2023-07-14 · Modified
4.3EPSS 0.006
CVE-2025-49736
Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability
Published 2025-08-12 · Analyzed
4.3EPSS 0.005
CVE-2024-38093
Microsoft Edge (Chromium-based) Spoofing Vulnerability
Published 2024-06-20 · Modified
4.3EPSS 0.005
CVE-2025-49755
Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability
Published 2025-08-12 · Analyzed
4.3EPSS 0.005
CVE-2017-0066
Microsoft Edge allows remote attackers to bypass the Same Origin Policy for HTML elements in other browser windows, aka "Microsoft Edge Security Feature Bypass Vulnerability." This vulnerability is different from those described in CVE-2017-0135 and CVE-2017-0140.
Published 2017-03-17 · Modified
4.2EPSS 0.299
CVE-2017-0140
Microsoft Edge allows remote attackers to bypass the Same Origin Policy for HTML elements in other browser windows, aka "Microsoft Edge Security Feature Bypass Vulnerability." This vulnerability is different from those described in CVE-2017-0066 and CVE-2017-0135.
Published 2017-03-17 · Modified
4.2EPSS 0.285
CVE-2017-0135
Microsoft Edge allows remote attackers to bypass the Same Origin Policy for HTML elements in other browser windows, aka "Microsoft Edge Security Feature Bypass Vulnerability." This vulnerability is different from those described in CVE-2017-0066 and CVE-2017-0140.
Published 2017-03-17 · Modified
4.2EPSS 0.077
CVE-2017-8754
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to trick a user into loading a page containing malicious content, due to the way that the Edge Content Security Policy (CSP) validates certain specially crafted documents, aka "Microsoft Edge Security Feature Bypass Vulnerability". This CVE ID is unique from CVE-2017-8723.
Published 2017-09-13 · Modified
4.2EPSS 0.035
CVE-2018-8315
An information disclosure vulnerability exists when the browser scripting engine improperly handle object types, aka "Microsoft Scripting Engine Information Disclosure Vulnerability." This affects ChakraCore, Internet Explorer 11, Microsoft Edge, Internet Explorer 10.
Published 2018-09-13 · Modified
4.2EPSS 0.031
CVE-2020-0663
An elevation of privilege vulnerability exists when Microsoft Edge does not properly enforce cross-domain policies, which could allow an attacker to access information from one domain and inject it into another domain.In a web-based attack scenario, an attacker could host a website that is used to attempt to exploit the vulnerability, aka 'Microsoft Edge Elevation of Privilege Vulnerability'.
Published 2020-02-11 · Modified
4.2EPSS 0.016
CVE-2024-26246
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
Published 2024-03-14 · Modified
3.9EPSS 0.006
CVE-2023-28301
Microsoft Edge (Chromium-based) Tampering Vulnerability
Published 2023-04-11 · Modified
3.7EPSS 0.009
CVE-2016-3325
Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to obtain sensitive information via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability."
Published 2016-09-14 · Modified
3.11 PoCEPSS 0.539
CVE-2016-7199
Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to bypass the Same Origin Policy and obtain sensitive window-state information via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability."
Published 2016-11-10 · Modified
3.1EPSS 0.131
CVE-2016-0125
Microsoft Edge mishandles the Referer policy, which allows remote attackers to obtain sensitive browser-history and request information via a crafted HTTPS web site, aka "Microsoft Edge Information Disclosure Vulnerability."
Published 2016-03-09 · Modified
3.1EPSS 0.119
CVE-2016-7227
The scripting engines in Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to determine the existence of local files via unspecified vectors, aka "Microsoft Browser Information Disclosure Vulnerability."
Published 2016-11-10 · Modified
3.1EPSS 0.116
CVE-2016-7239
The RegEx class in the XSS filter in Microsoft Internet Explorer 9 through 11 and Microsoft Edge allows remote attackers to conduct cross-site scripting (XSS) attacks and obtain sensitive information via unspecified vectors, aka "Microsoft Browser Information Disclosure Vulnerability."
Published 2016-11-10 · Modified
3.1EPSS 0.116
CVE-2016-7204
Microsoft Edge allows remote attackers to access arbitrary "My Documents" files via a crafted web site, aka "Microsoft Edge Information Disclosure Vulnerability."
Published 2016-11-10 · Modified
3.1EPSS 0.114
CVE-2016-3274
Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to conduct content-spoofing attacks via a crafted URL, aka "Microsoft Browser Spoofing Vulnerability."
Published 2016-07-13 · Modified
3.1EPSS 0.083
CVE-2017-11791
ChakraCore and Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, and Microsoft Edge and Internet Explorer in Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to obtain information to further compromise the user's system, due to how the scripting engine handles objects in memory, aka "Scripting Engine Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-11834.
Published 2017-11-15 · Modified
3.1EPSS 0.055
CVE-2017-11833
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to determine the origin of all webpages in the affected browser, due to how Microsoft Edge handles cross-origin requests, aka "Microsoft Edge Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-11803 and CVE-2017-11844.
Published 2017-11-15 · Modified
3.1EPSS 0.052
← Prev19 / 20Next →