Edge
by Microsoft
Source repositories
CVEs (965)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-0891 | Med | 0.32 | 4.3 | 0.15 | Mar 14, 2018 | ChakraCore, and Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, and Internet Explorer and Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allow… | ||
| CVE-2017-8644 | Med | 0.32 | 4.3 | 0.16 | Aug 8, 2017 | Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to disclose information due to the way that Microsoft Edge handles objects in memory, aka "Microsoft Edge Information Disclosure Vulnerability". This CVE ID is unique from… | ||
| CVE-2025-47967 | Med | 0.31 | 4.7 | 0.00 | Sep 16, 2025 | Insufficient ui warning of dangerous operations in Microsoft Edge for Android allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2025-53791 | Med | 0.31 | 4.7 | 0.00 | Sep 5, 2025 | Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network. | ||
| CVE-2025-29796 | Med | 0.31 | 4.7 | 0.01 | Apr 4, 2025 | User interface (ui) misrepresentation of critical information in Microsoft Edge for iOS allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2024-38082 | Med | 0.31 | 4.7 | 0.01 | Jun 20, 2024 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | ||
| CVE-2024-26247 | Med | 0.31 | 4.7 | 0.01 | Mar 22, 2024 | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | ||
| CVE-2024-26163 | Med | 0.31 | 4.7 | 0.02 | Mar 14, 2024 | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | ||
| CVE-2024-21423 | Med | 0.31 | 4.8 | 0.01 | Feb 23, 2024 | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | ||
| CVE-2023-36880 | Med | 0.31 | 4.8 | 0.02 | Dec 7, 2023 | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | ||
| CVE-2023-35392 | Med | 0.31 | 4.7 | 0.01 | Jul 21, 2023 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | ||
| CVE-2022-23264 | Med | 0.31 | 4.7 | 0.01 | Jun 29, 2023 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | ||
| CVE-2023-29354 | Med | 0.31 | 4.7 | 0.01 | May 5, 2023 | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | ||
| CVE-2017-0011 | Med | 0.31 | 4.3 | 0.38 | Mar 17, 2017 | Microsoft Edge allows remote attackers to obtain sensitive information via a crafted web site, aka "Microsoft Edge Information Disclosure Vulnerability." This vulnerability is different from those described in CVE-2017-0009, CVE-2017-0017, CVE-2017-0065, and CVE-2017-0068. | ||
| CVE-2021-26439 | Med | 0.30 | 4.6 | 0.03 | Sep 2, 2021 | Microsoft Edge for Android Information Disclosure Vulnerability | ||
| CVE-2017-0140 | Med | 0.30 | 4.2 | 0.28 | Mar 17, 2017 | Microsoft Edge allows remote attackers to bypass the Same Origin Policy for HTML elements in other browser windows, aka "Microsoft Edge Security Feature Bypass Vulnerability." This vulnerability is different from those described in CVE-2017-0066 and CVE-2017-0135. | ||
| CVE-2017-0066 | Med | 0.30 | 4.2 | 0.29 | Mar 17, 2017 | Microsoft Edge allows remote attackers to bypass the Same Origin Policy for HTML elements in other browser windows, aka "Microsoft Edge Security Feature Bypass Vulnerability." This vulnerability is different from those described in CVE-2017-0135 and CVE-2017-0140. | ||
| CVE-2017-0065 | Med | 0.30 | 4.3 | 0.27 | Mar 17, 2017 | Microsoft Edge allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability." This vulnerability is different from those described in CVE-2017-0009, CVE-2017-0011, CVE-2017-0017,… | ||
| CVE-2026-58616 | Med | 0.29 | 4.4 | 0.00 | Aug 28, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Copilot Chat (Microsoft Edge) allows an authorized attacker to disclose information over a network. | ||
| CVE-2025-21401 | Med | 0.29 | 4.5 | 0.00 | Feb 15, 2025 | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability |
- risk 0.32cvss 4.3epss 0.15
ChakraCore, and Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, and Internet Explorer and Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allow…
- risk 0.32cvss 4.3epss 0.16
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to disclose information due to the way that Microsoft Edge handles objects in memory, aka "Microsoft Edge Information Disclosure Vulnerability". This CVE ID is unique from…
- risk 0.31cvss 4.7epss 0.00
Insufficient ui warning of dangerous operations in Microsoft Edge for Android allows an unauthorized attacker to perform spoofing over a network.
- risk 0.31cvss 4.7epss 0.00
Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.
- risk 0.31cvss 4.7epss 0.01
User interface (ui) misrepresentation of critical information in Microsoft Edge for iOS allows an unauthorized attacker to perform spoofing over a network.
- risk 0.31cvss 4.7epss 0.01
Microsoft Edge (Chromium-based) Spoofing Vulnerability
- risk 0.31cvss 4.7epss 0.01
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
- risk 0.31cvss 4.7epss 0.02
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
- risk 0.31cvss 4.8epss 0.01
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
- risk 0.31cvss 4.8epss 0.02
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
- risk 0.31cvss 4.7epss 0.01
Microsoft Edge (Chromium-based) Spoofing Vulnerability
- risk 0.31cvss 4.7epss 0.01
Microsoft Edge (Chromium-based) Spoofing Vulnerability
- risk 0.31cvss 4.7epss 0.01
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
- risk 0.31cvss 4.3epss 0.38
Microsoft Edge allows remote attackers to obtain sensitive information via a crafted web site, aka "Microsoft Edge Information Disclosure Vulnerability." This vulnerability is different from those described in CVE-2017-0009, CVE-2017-0017, CVE-2017-0065, and CVE-2017-0068.
- risk 0.30cvss 4.6epss 0.03
Microsoft Edge for Android Information Disclosure Vulnerability
- risk 0.30cvss 4.2epss 0.28
Microsoft Edge allows remote attackers to bypass the Same Origin Policy for HTML elements in other browser windows, aka "Microsoft Edge Security Feature Bypass Vulnerability." This vulnerability is different from those described in CVE-2017-0066 and CVE-2017-0135.
- risk 0.30cvss 4.2epss 0.29
Microsoft Edge allows remote attackers to bypass the Same Origin Policy for HTML elements in other browser windows, aka "Microsoft Edge Security Feature Bypass Vulnerability." This vulnerability is different from those described in CVE-2017-0135 and CVE-2017-0140.
- risk 0.30cvss 4.3epss 0.27
Microsoft Edge allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability." This vulnerability is different from those described in CVE-2017-0009, CVE-2017-0011, CVE-2017-0017,…
- risk 0.29cvss 4.4epss 0.00
Concurrent execution using shared resource with improper synchronization ('race condition') in Copilot Chat (Microsoft Edge) allows an authorized attacker to disclose information over a network.
- risk 0.29cvss 4.5epss 0.00
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
Page 38 of 49