Edge
by Microsoft
Source repositories
CVEs (965)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2017-11862 | Hig | 0.42 | 7.5 | 0.08 | Nov 15, 2017 | ChakraCore and Microsoft Edge in Windows 10 1709 and Windows Server, version 1709 allows an attacker to gain the same user rights as the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID… | ||
| CVE-2017-11821 | Hig | 0.42 | 7.5 | 0.09 | Oct 13, 2017 | ChakraCore and Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique… | ||
| CVE-2017-11807 | Hig | 0.42 | 7.5 | 0.09 | Oct 13, 2017 | ChakraCore and Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique… | ||
| CVE-2017-11806 | Hig | 0.42 | 7.5 | 0.09 | Oct 13, 2017 | ChakraCore and Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique… | ||
| CVE-2017-11805 | Hig | 0.42 | 7.5 | 0.09 | Oct 13, 2017 | ChakraCore and Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique… | ||
| CVE-2017-11796 | Hig | 0.42 | 7.5 | 0.09 | Oct 13, 2017 | ChakraCore and Microsoft Edge in Windows 10 1703 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from… | ||
| CVE-2017-11792 | Hig | 0.42 | 7.5 | 0.09 | Oct 13, 2017 | ChakraCore and Microsoft Edge in Microsoft Windows 10 1703 allow an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique… | ||
| CVE-2025-60711 | Med | 0.41 | 6.3 | 0.00 | Oct 31, 2025 | Protection mechanism failure in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | ||
| CVE-2025-47963 | Med | 0.41 | 6.3 | 0.01 | Jul 11, 2025 | No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2024-38207 | Med | 0.41 | 6.3 | 0.00 | Aug 23, 2024 | Microsoft Edge (HTML-based) Memory Corruption Vulnerability | ||
| CVE-2024-20675 | Med | 0.41 | 6.3 | 0.00 | Jan 11, 2024 | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | ||
| CVE-2022-26899 | Med | 0.41 | 6.3 | 0.01 | Jun 29, 2023 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | ||
| CVE-2022-23262 | Med | 0.41 | 6.3 | 0.01 | Feb 7, 2022 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | ||
| CVE-2021-36929 | Med | 0.41 | 6.3 | 0.03 | Aug 26, 2021 | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | ||
| CVE-2026-77490 | Med | 0.40 | 6.1 | 0.00 | Sep 11, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2026-66325 | Med | 0.40 | 6.1 | 0.00 | Aug 4, 2026 | Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2026-66311 | Med | 0.40 | 6.2 | 0.00 | Aug 4, 2026 | Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally. | ||
| CVE-2026-65804 | Med | 0.40 | 6.1 | 0.00 | Aug 4, 2026 | Improper control of generation of code ('code injection') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2024-38208 | Med | 0.40 | 6.1 | 0.00 | Aug 22, 2024 | Microsoft Edge for Android Spoofing Vulnerability | ||
| CVE-2024-38156 | Med | 0.40 | 6.1 | 0.00 | Jul 19, 2024 | Microsoft Edge (Chromium-based) Spoofing Vulnerability |
- risk 0.42cvss 7.5epss 0.08
ChakraCore and Microsoft Edge in Windows 10 1709 and Windows Server, version 1709 allows an attacker to gain the same user rights as the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID…
- risk 0.42cvss 7.5epss 0.09
ChakraCore and Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique…
- risk 0.42cvss 7.5epss 0.09
ChakraCore and Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique…
- risk 0.42cvss 7.5epss 0.09
ChakraCore and Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique…
- risk 0.42cvss 7.5epss 0.09
ChakraCore and Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique…
- risk 0.42cvss 7.5epss 0.09
ChakraCore and Microsoft Edge in Windows 10 1703 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from…
- risk 0.42cvss 7.5epss 0.09
ChakraCore and Microsoft Edge in Microsoft Windows 10 1703 allow an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique…
- risk 0.41cvss 6.3epss 0.00
Protection mechanism failure in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
- risk 0.41cvss 6.3epss 0.01
No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
- risk 0.41cvss 6.3epss 0.00
Microsoft Edge (HTML-based) Memory Corruption Vulnerability
- risk 0.41cvss 6.3epss 0.00
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
- risk 0.41cvss 6.3epss 0.01
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
- risk 0.41cvss 6.3epss 0.01
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
- risk 0.41cvss 6.3epss 0.03
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
- risk 0.40cvss 6.1epss 0.00
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
- risk 0.40cvss 6.1epss 0.00
Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
- risk 0.40cvss 6.2epss 0.00
Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally.
- risk 0.40cvss 6.1epss 0.00
Improper control of generation of code ('code injection') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
- risk 0.40cvss 6.1epss 0.00
Microsoft Edge for Android Spoofing Vulnerability
- risk 0.40cvss 6.1epss 0.00
Microsoft Edge (Chromium-based) Spoofing Vulnerability
Page 33 of 49