Edge
by Microsoft
Source repositories
CVEs (950)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2017-11806 | Hig | 0.42 | 7.5 | 0.09 | Oct 13, 2017 | ChakraCore and Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique… | ||
| CVE-2017-11805 | Hig | 0.42 | 7.5 | 0.09 | Oct 13, 2017 | ChakraCore and Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique… | ||
| CVE-2017-11796 | Hig | 0.42 | 7.5 | 0.09 | Oct 13, 2017 | ChakraCore and Microsoft Edge in Windows 10 1703 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from… | ||
| CVE-2017-11792 | Hig | 0.42 | 7.5 | 0.09 | Oct 13, 2017 | ChakraCore and Microsoft Edge in Microsoft Windows 10 1703 allow an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique… | ||
| CVE-2025-60711 | Med | 0.41 | 6.3 | 0.00 | Oct 31, 2025 | Protection mechanism failure in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | ||
| CVE-2025-47963 | Med | 0.41 | 6.3 | 0.01 | Jul 11, 2025 | No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2024-38207 | Med | 0.41 | 6.3 | 0.00 | Aug 23, 2024 | Microsoft Edge (HTML-based) Memory Corruption Vulnerability | ||
| CVE-2024-20675 | Med | 0.41 | 6.3 | 0.00 | Jan 11, 2024 | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | ||
| CVE-2022-26899 | Med | 0.41 | 6.3 | 0.01 | Jun 29, 2023 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | ||
| CVE-2022-23262 | Med | 0.41 | 6.3 | 0.01 | Feb 7, 2022 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | ||
| CVE-2021-36929 | Med | 0.41 | 6.3 | 0.03 | Aug 26, 2021 | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | ||
| CVE-2026-66325 | Med | 0.40 | 6.1 | 0.00 | Aug 4, 2026 | Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2026-66311 | Med | 0.40 | 6.2 | 0.00 | Aug 4, 2026 | Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally. | ||
| CVE-2026-65804 | Med | 0.40 | 6.1 | 0.00 | Aug 4, 2026 | Improper control of generation of code ('code injection') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2024-38208 | Med | 0.40 | 6.1 | 0.00 | Aug 22, 2024 | Microsoft Edge for Android Spoofing Vulnerability | ||
| CVE-2024-38156 | Med | 0.40 | 6.1 | 0.00 | Jul 19, 2024 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | ||
| CVE-2023-36727 | Med | 0.40 | 6.1 | 0.01 | Sep 15, 2023 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | ||
| CVE-2021-34506 | Med | 0.40 | 6.1 | 0.02 | Jul 1, 2023 | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | ||
| CVE-2023-29345 | Med | 0.40 | 6.1 | 0.01 | Jun 7, 2023 | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | ||
| CVE-2023-28286 | Med | 0.40 | 6.1 | 0.01 | Apr 27, 2023 | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability |
- risk 0.42cvss 7.5epss 0.09
ChakraCore and Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique…
- risk 0.42cvss 7.5epss 0.09
ChakraCore and Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique…
- risk 0.42cvss 7.5epss 0.09
ChakraCore and Microsoft Edge in Windows 10 1703 allows an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from…
- risk 0.42cvss 7.5epss 0.09
ChakraCore and Microsoft Edge in Microsoft Windows 10 1703 allow an attacker to execute arbitrary code in the context of the current user, due to how the scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique…
- risk 0.41cvss 6.3epss 0.00
Protection mechanism failure in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
- risk 0.41cvss 6.3epss 0.01
No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
- risk 0.41cvss 6.3epss 0.00
Microsoft Edge (HTML-based) Memory Corruption Vulnerability
- risk 0.41cvss 6.3epss 0.00
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
- risk 0.41cvss 6.3epss 0.01
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
- risk 0.41cvss 6.3epss 0.01
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
- risk 0.41cvss 6.3epss 0.03
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
- risk 0.40cvss 6.1epss 0.00
Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
- risk 0.40cvss 6.2epss 0.00
Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally.
- risk 0.40cvss 6.1epss 0.00
Improper control of generation of code ('code injection') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
- risk 0.40cvss 6.1epss 0.00
Microsoft Edge for Android Spoofing Vulnerability
- risk 0.40cvss 6.1epss 0.00
Microsoft Edge (Chromium-based) Spoofing Vulnerability
- risk 0.40cvss 6.1epss 0.01
Microsoft Edge (Chromium-based) Spoofing Vulnerability
- risk 0.40cvss 6.1epss 0.02
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
- risk 0.40cvss 6.1epss 0.01
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
- risk 0.40cvss 6.1epss 0.01
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
Page 33 of 48