Edge
by Microsoft
Source repositories
CVEs (965)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2016-7239 | Low | 0.21 | 3.1 | 0.12 | Nov 10, 2016 | The RegEx class in the XSS filter in Microsoft Internet Explorer 9 through 11 and Microsoft Edge allows remote attackers to conduct cross-site scripting (XSS) attacks and obtain sensitive information via unspecified vectors, aka "Microsoft Browser Information Disclosure… | ||
| CVE-2016-7227 | Low | 0.21 | 3.1 | 0.12 | Nov 10, 2016 | The scripting engines in Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to determine the existence of local files via unspecified vectors, aka "Microsoft Browser Information Disclosure Vulnerability." | ||
| CVE-2016-7204 | Low | 0.21 | 3.1 | 0.11 | Nov 10, 2016 | Microsoft Edge allows remote attackers to access arbitrary "My Documents" files via a crafted web site, aka "Microsoft Edge Information Disclosure Vulnerability." | ||
| CVE-2016-7199 | Low | 0.21 | 3.1 | 0.13 | Nov 10, 2016 | Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to bypass the Same Origin Policy and obtain sensitive window-state information via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability." | ||
| CVE-2016-3276 | Low | 0.21 | 3.1 | 0.07 | Jul 13, 2016 | Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to conduct content-spoofing attacks via a crafted URL, aka "Microsoft Browser Spoofing Vulnerability." | ||
| CVE-2016-3274 | Low | 0.21 | 3.1 | 0.08 | Jul 13, 2016 | Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to conduct content-spoofing attacks via a crafted URL, aka "Microsoft Browser Spoofing Vulnerability." | ||
| CVE-2016-0125 | Low | 0.21 | 3.1 | 0.12 | Mar 9, 2016 | Microsoft Edge mishandles the Referer policy, which allows remote attackers to obtain sensitive browser-history and request information via a crafted HTTPS web site, aka "Microsoft Edge Information Disclosure Vulnerability." | ||
| CVE-2026-0102 | Low | 0.20 | 3.1 | 0.00 | Feb 17, 2026 | Under specific conditions, a malicious webpage may trigger autofill population after two consecutive taps, potentially without clear or intentional user consent. This could result in disclosure of stored autofill data such as addresses, email, or phone number metadata. | ||
| CVE-2025-65046 | Low | 0.20 | 3.1 | 0.00 | Dec 18, 2025 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | ||
| CVE-2023-38158 | Low | 0.20 | 3.1 | 0.01 | Aug 21, 2023 | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | ||
| CVE-2022-29147 | Low | 0.20 | 3.1 | 0.01 | Jun 29, 2023 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | ||
| CVE-2021-43220 | Low | 0.20 | 3.1 | 0.01 | Nov 24, 2021 | Microsoft Edge for iOS Spoofing Vulnerability | ||
| CVE-2021-42308 | Low | 0.20 | 3.1 | 0.01 | Nov 24, 2021 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | ||
| CVE-2020-1195 | Low | 0.20 | 3.1 | 0.02 | May 21, 2020 | An elevation of privilege vulnerability exists in Microsoft Edge (Chromium-based) when the Feedback extension improperly validates input. An attacker who successfully exploited this vulnerability could write files to arbitrary locations and gain elevated privileges. The… | ||
| CVE-2020-1065 | Med | 0.20 | 4.2 | 0.02 | May 21, 2020 | A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who… | ||
| CVE-2020-1037 | Med | 0.20 | 4.2 | 0.02 | May 21, 2020 | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current… | ||
| CVE-2019-1197 | Med | 0.20 | 4.2 | 0.02 | Aug 14, 2019 | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current… | ||
| CVE-2019-1196 | Med | 0.20 | 4.2 | 0.02 | Aug 14, 2019 | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current… | ||
| CVE-2019-1195 | Med | 0.20 | 4.2 | 0.02 | Aug 14, 2019 | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current… | ||
| CVE-2019-1141 | Med | 0.20 | 4.2 | 0.02 | Aug 14, 2019 | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current… |
- risk 0.21cvss 3.1epss 0.12
The RegEx class in the XSS filter in Microsoft Internet Explorer 9 through 11 and Microsoft Edge allows remote attackers to conduct cross-site scripting (XSS) attacks and obtain sensitive information via unspecified vectors, aka "Microsoft Browser Information Disclosure…
- risk 0.21cvss 3.1epss 0.12
The scripting engines in Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to determine the existence of local files via unspecified vectors, aka "Microsoft Browser Information Disclosure Vulnerability."
- risk 0.21cvss 3.1epss 0.11
Microsoft Edge allows remote attackers to access arbitrary "My Documents" files via a crafted web site, aka "Microsoft Edge Information Disclosure Vulnerability."
- risk 0.21cvss 3.1epss 0.13
Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to bypass the Same Origin Policy and obtain sensitive window-state information via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability."
- risk 0.21cvss 3.1epss 0.07
Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to conduct content-spoofing attacks via a crafted URL, aka "Microsoft Browser Spoofing Vulnerability."
- risk 0.21cvss 3.1epss 0.08
Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to conduct content-spoofing attacks via a crafted URL, aka "Microsoft Browser Spoofing Vulnerability."
- risk 0.21cvss 3.1epss 0.12
Microsoft Edge mishandles the Referer policy, which allows remote attackers to obtain sensitive browser-history and request information via a crafted HTTPS web site, aka "Microsoft Edge Information Disclosure Vulnerability."
- risk 0.20cvss 3.1epss 0.00
Under specific conditions, a malicious webpage may trigger autofill population after two consecutive taps, potentially without clear or intentional user consent. This could result in disclosure of stored autofill data such as addresses, email, or phone number metadata.
- risk 0.20cvss 3.1epss 0.00
Microsoft Edge (Chromium-based) Spoofing Vulnerability
- risk 0.20cvss 3.1epss 0.01
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
- risk 0.20cvss 3.1epss 0.01
Microsoft Edge (Chromium-based) Spoofing Vulnerability
- risk 0.20cvss 3.1epss 0.01
Microsoft Edge for iOS Spoofing Vulnerability
- risk 0.20cvss 3.1epss 0.01
Microsoft Edge (Chromium-based) Spoofing Vulnerability
- risk 0.20cvss 3.1epss 0.02
An elevation of privilege vulnerability exists in Microsoft Edge (Chromium-based) when the Feedback extension improperly validates input. An attacker who successfully exploited this vulnerability could write files to arbitrary locations and gain elevated privileges. The…
- risk 0.20cvss 4.2epss 0.02
A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who…
- risk 0.20cvss 4.2epss 0.02
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current…
- risk 0.20cvss 4.2epss 0.02
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current…
- risk 0.20cvss 4.2epss 0.02
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current…
- risk 0.20cvss 4.2epss 0.02
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current…
- risk 0.20cvss 4.2epss 0.02
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current…
Page 46 of 49