edge vulnerabilities
CVEs whose affected-version data names the edge package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
11 CVEsRSS
CVE-2026-66310High· 7.7External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.
External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.
CVE-2024-38093Medium· 4.3Microsoft Edge (Chromium-based) Spoofing Vulnerability
Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2024-38082Medium· 4.7Microsoft Edge (Chromium-based) Spoofing Vulnerability
Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2024-30057Medium· 5.4Microsoft Edge for iOS Spoofing Vulnerability
Microsoft Edge for iOS Spoofing Vulnerability
CVE-2021-26411High· 8.8CISA KEV0dayPoCInternet Explorer Memory Corruption Vulnerability
Internet Explorer Memory Corruption Vulnerability
CVE-2020-1096Medium· 4.2A remote code execution vulnerability exists when Microsoft Edge PDF Reader improperly handles objects in memory
A remote code execution vulnerability exists when Microsoft Edge PDF Reader improperly handles objects in memory. The vulnerability could corrupt memory in such a way that enables an attacker to execute arbitrary code in the context of t…
CVE-2020-1065Medium· 4.2A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory
A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of …
CVE-2020-1059Medium· 4.3A spoofing vulnerability exists when Microsoft Edge does not properly parse HTTP content
A spoofing vulnerability exists when Microsoft Edge does not properly parse HTTP content. An attacker who successfully exploited this vulnerability could trick a user by redirecting the user to a specially crafted website. The specially …
CVE-2020-1056Medium· 5.4An elevation of privilege vulnerability exists when Microsoft Edge does not properly enforce cross-domain policies, which could allow an attacker to access information from one domain and inject it into another domain. In a web-based att…
An elevation of privilege vulnerability exists when Microsoft Edge does not properly enforce cross-domain policies, which could allow an attacker to access information from one domain and inject it into another domain. In a web-based att…
CVE-2020-1037Medium· 4.2A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based)
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitr…
CVE-2016-3351Medium· 6.5CISA KEV0dayMicrosoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to obtain sensitive information via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability."
Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to obtain sensitive information via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability."