Edge
by Microsoft
Source repositories
CVEs (950)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-45492 | Med | 0.35 | 5.4 | 0.00 | May 18, 2026 | Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network. | ||
| CVE-2026-42838 | Med | 0.35 | 5.4 | 0.00 | May 12, 2026 | Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2026-33119 | Med | 0.35 | 5.4 | 0.00 | Apr 10, 2026 | User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2025-47964 | Med | 0.35 | 5.4 | 0.00 | Jul 11, 2025 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | ||
| CVE-2025-26643 | Med | 0.35 | 5.4 | 0.01 | Mar 7, 2025 | The UI performs the wrong action in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2025-21253 | Med | 0.35 | 5.3 | 0.01 | Feb 6, 2025 | Microsoft Edge for IOS and Android Spoofing Vulnerability | ||
| CVE-2025-21262 | Med | 0.35 | 5.4 | 0.00 | Jan 24, 2025 | User Interface (UI) Misrepresentation of Critical Information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network | ||
| CVE-2024-49025 | Med | 0.35 | 5.4 | 0.01 | Nov 14, 2024 | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | ||
| CVE-2024-43580 | Med | 0.35 | 5.4 | 0.00 | Oct 17, 2024 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | ||
| CVE-2024-30057 | Med | 0.35 | 5.4 | 0.00 | Jun 13, 2024 | Microsoft Edge for iOS Spoofing Vulnerability | ||
| CVE-2021-34475 | Med | 0.35 | 5.4 | 0.01 | Jul 1, 2023 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | ||
| CVE-2023-21720 | Med | 0.35 | 5.3 | 0.01 | Feb 14, 2023 | Microsoft Edge (Chromium-based) Tampering Vulnerability | ||
| CVE-2022-23261 | Med | 0.35 | 5.3 | 0.02 | Feb 7, 2022 | Microsoft Edge (Chromium-based) Tampering Vulnerability | ||
| CVE-2021-36930 | Med | 0.35 | 5.3 | 0.01 | Sep 2, 2021 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | ||
| CVE-2021-24113 | Med | 0.35 | 5.4 | 0.01 | Feb 25, 2021 | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | ||
| CVE-2020-1242 | Med | 0.35 | 5.3 | 0.04 | Jun 9, 2020 | An information disclosure vulnerability exists in the way that Microsoft Edge handles cross-origin requests, aka 'Microsoft Edge Information Disclosure Vulnerability'. | ||
| CVE-2018-8567 | Med | 0.35 | 5.4 | 0.03 | Nov 14, 2018 | An elevation of privilege vulnerability exists when Microsoft Edge does not properly enforce cross-domain policies, which could allow an attacker to access information from one domain and inject it into another domain, aka "Microsoft Edge Elevation of Privilege Vulnerability."… | ||
| CVE-2018-8512 | Med | 0.35 | 5.4 | 0.03 | Oct 10, 2018 | A security feature bypass vulnerability exists in Microsoft Edge when the Edge Content Security Policy (CSP) fails to properly validate certain specially crafted documents, aka "Microsoft Edge Security Feature Bypass Vulnerability." This affects Microsoft Edge. This CVE ID is… | ||
| CVE-2018-0800 | Med | 0.35 | 5.3 | 0.07 | Jan 4, 2018 | Microsoft Edge in Microsoft Windows 10 1709 allows an attacker to obtain information to further compromise the user's system, due to how the scripting engine handles objects in memory, aka "Scripting Engine Information Disclosure Vulnerability". This CVE ID is unique from… | ||
| CVE-2017-11919 | Med | 0.35 | 5.3 | 0.06 | Dec 12, 2017 | ChakraCore, and Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 R2, and Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016, and Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and… |
- risk 0.35cvss 5.4epss 0.00
Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.
- risk 0.35cvss 5.4epss 0.00
Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network.
- risk 0.35cvss 5.4epss 0.00
User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
- risk 0.35cvss 5.4epss 0.00
Microsoft Edge (Chromium-based) Spoofing Vulnerability
- risk 0.35cvss 5.4epss 0.01
The UI performs the wrong action in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
- risk 0.35cvss 5.3epss 0.01
Microsoft Edge for IOS and Android Spoofing Vulnerability
- risk 0.35cvss 5.4epss 0.00
User Interface (UI) Misrepresentation of Critical Information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network
- risk 0.35cvss 5.4epss 0.01
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
- risk 0.35cvss 5.4epss 0.00
Microsoft Edge (Chromium-based) Spoofing Vulnerability
- risk 0.35cvss 5.4epss 0.00
Microsoft Edge for iOS Spoofing Vulnerability
- risk 0.35cvss 5.4epss 0.01
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
- risk 0.35cvss 5.3epss 0.01
Microsoft Edge (Chromium-based) Tampering Vulnerability
- risk 0.35cvss 5.3epss 0.02
Microsoft Edge (Chromium-based) Tampering Vulnerability
- risk 0.35cvss 5.3epss 0.01
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
- risk 0.35cvss 5.4epss 0.01
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
- risk 0.35cvss 5.3epss 0.04
An information disclosure vulnerability exists in the way that Microsoft Edge handles cross-origin requests, aka 'Microsoft Edge Information Disclosure Vulnerability'.
- risk 0.35cvss 5.4epss 0.03
An elevation of privilege vulnerability exists when Microsoft Edge does not properly enforce cross-domain policies, which could allow an attacker to access information from one domain and inject it into another domain, aka "Microsoft Edge Elevation of Privilege Vulnerability."…
- risk 0.35cvss 5.4epss 0.03
A security feature bypass vulnerability exists in Microsoft Edge when the Edge Content Security Policy (CSP) fails to properly validate certain specially crafted documents, aka "Microsoft Edge Security Feature Bypass Vulnerability." This affects Microsoft Edge. This CVE ID is…
- risk 0.35cvss 5.3epss 0.07
Microsoft Edge in Microsoft Windows 10 1709 allows an attacker to obtain information to further compromise the user's system, due to how the scripting engine handles objects in memory, aka "Scripting Engine Information Disclosure Vulnerability". This CVE ID is unique from…
- risk 0.35cvss 5.3epss 0.06
ChakraCore, and Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 R2, and Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016, and Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and…
Page 36 of 48