Edge
by Microsoft
Source repositories
CVEs (950)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2015-0313 | Cri | 0.86 | 9.8 | 0.96 | KEV | Feb 2, 2015 | Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in February 2015,… | |
| CVE-2015-0311 | Cri | 0.86 | 9.8 | 0.86 | KEV | Jan 23, 2015 | Unspecified vulnerability in Adobe Flash Player through 13.0.0.262 and 14.x, 15.x, and 16.x through 16.0.0.287 on Windows and OS X and through 11.2.202.438 on Linux allows remote attackers to execute arbitrary code via unknown vectors, as exploited in the wild in January 2015. | |
| CVE-2021-26411 | Hig | 0.82 | 8.8 | 0.81 | KEV | Mar 11, 2021 | Internet Explorer Memory Corruption Vulnerability | |
| CVE-2024-7971 | Cri | 0.76 | 9.6 | 0.21 | KEV | Aug 21, 2024 | Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| CVE-2017-0037 | Hig | 0.74 | 8.1 | 0.80 | KEV | Feb 26, 2017 | Microsoft Internet Explorer 10 and 11 and Microsoft Edge have a type confusion issue in the Layout::MultiColumnBoxBuilder::HandleColumnBreakOnColumnSpanningElement function in mshtml.dll, which allows remote attackers to execute arbitrary code via vectors involving a crafted… | |
| CVE-2016-7201 | Hig | 0.72 | 8.8 | 0.80 | KEV | Nov 10, 2016 | The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than… | |
| CVE-2016-7200 | Hig | 0.72 | 8.8 | 0.82 | KEV | Nov 10, 2016 | The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than… | |
| CVE-2022-4135 | Cri | 0.70 | 9.6 | 0.32 | KEV | Nov 25, 2022 | Heap buffer overflow in GPU in Google Chrome prior to 107.0.5304.121 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | |
| CVE-2023-5217 | Hig | 0.66 | 8.8 | 0.49 | KEV | Sep 28, 2023 | Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| CVE-2020-16009 | Hig | 0.66 | 8.8 | 0.49 | KEV | Nov 3, 2020 | Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| CVE-2016-0003 | Cri | 0.66 | 9.6 | 0.38 | Jan 13, 2016 | Microsoft Edge allows remote attackers to execute arbitrary code via unspecified vectors, aka "Microsoft Edge Memory Corruption Vulnerability." | ||
| CVE-2025-55241 | Cri | 0.65 | 10.0 | 0.02 | Sep 4, 2025 | Azure Entra ID Elevation of Privilege Vulnerability | ||
| CVE-2017-0028 | Cri | 0.65 | 9.8 | 0.19 | Jul 17, 2017 | A remote code execution vulnerability exists when Microsoft scripting engine improperly accesses objects in memory. The vulnerability could corrupt memory in a way that enables an attacker to execute arbitrary code in the context of the current user. An attacker who successfully… | ||
| CVE-2016-3222 | Hig | 0.65 | 8.8 | 0.57 | Jun 16, 2016 | Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Edge Memory Corruption Vulnerability." | ||
| CVE-2025-59246 | Cri | 0.64 | 9.8 | 0.07 | Oct 9, 2025 | Azure Entra ID Elevation of Privilege Vulnerability | ||
| CVE-2023-35618 | Cri | 0.63 | 9.6 | 0.03 | Dec 7, 2023 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | ||
| CVE-2023-36735 | Cri | 0.63 | 9.6 | 0.02 | Sep 15, 2023 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | ||
| CVE-2022-33649 | Cri | 0.63 | 9.6 | 0.02 | Aug 9, 2022 | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | ||
| CVE-2025-59218 | Cri | 0.62 | 9.6 | 0.01 | Oct 9, 2025 | Azure Entra ID Elevation of Privilege Vulnerability | ||
| CVE-2024-21326 | Cri | 0.62 | 9.6 | 0.01 | Jan 26, 2024 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability |
- risk 0.86cvss 9.8epss 0.96
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in February 2015,…
- risk 0.86cvss 9.8epss 0.86
Unspecified vulnerability in Adobe Flash Player through 13.0.0.262 and 14.x, 15.x, and 16.x through 16.0.0.287 on Windows and OS X and through 11.2.202.438 on Linux allows remote attackers to execute arbitrary code via unknown vectors, as exploited in the wild in January 2015.
- risk 0.82cvss 8.8epss 0.81
Internet Explorer Memory Corruption Vulnerability
- risk 0.76cvss 9.6epss 0.21
Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- risk 0.74cvss 8.1epss 0.80
Microsoft Internet Explorer 10 and 11 and Microsoft Edge have a type confusion issue in the Layout::MultiColumnBoxBuilder::HandleColumnBreakOnColumnSpanningElement function in mshtml.dll, which allows remote attackers to execute arbitrary code via vectors involving a crafted…
- risk 0.72cvss 8.8epss 0.80
The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than…
- risk 0.72cvss 8.8epss 0.82
The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than…
- risk 0.70cvss 9.6epss 0.32
Heap buffer overflow in GPU in Google Chrome prior to 107.0.5304.121 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
- risk 0.66cvss 8.8epss 0.49
Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- risk 0.66cvss 8.8epss 0.49
Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- risk 0.66cvss 9.6epss 0.38
Microsoft Edge allows remote attackers to execute arbitrary code via unspecified vectors, aka "Microsoft Edge Memory Corruption Vulnerability."
- risk 0.65cvss 10.0epss 0.02
Azure Entra ID Elevation of Privilege Vulnerability
- risk 0.65cvss 9.8epss 0.19
A remote code execution vulnerability exists when Microsoft scripting engine improperly accesses objects in memory. The vulnerability could corrupt memory in a way that enables an attacker to execute arbitrary code in the context of the current user. An attacker who successfully…
- risk 0.65cvss 8.8epss 0.57
Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Edge Memory Corruption Vulnerability."
- risk 0.64cvss 9.8epss 0.07
Azure Entra ID Elevation of Privilege Vulnerability
- risk 0.63cvss 9.6epss 0.03
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
- risk 0.63cvss 9.6epss 0.02
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
- risk 0.63cvss 9.6epss 0.02
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
- risk 0.62cvss 9.6epss 0.01
Azure Entra ID Elevation of Privilege Vulnerability
- risk 0.62cvss 9.6epss 0.01
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
Page 1 of 48