VulnSea

edge vulnerabilities

CVEs whose affected-version data names the edge package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

11 CVEsRSS

CVE-2026-66310High· 7.7
1mo ago

External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.

External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.

Twilightmicrosoft · edgeEPSS 0.22%via NVD
CVE-2024-38093Medium· 4.3
2y ago

Microsoft Edge (Chromium-based) Spoofing Vulnerability

Microsoft Edge (Chromium-based) Spoofing Vulnerability

Sunlitmicrosoft · edgeEPSS 0.50%via NVD
CVE-2024-38082Medium· 4.7
2y ago

Microsoft Edge (Chromium-based) Spoofing Vulnerability

Microsoft Edge (Chromium-based) Spoofing Vulnerability

Sunlitmicrosoft · edgeEPSS 0.50%via NVD
CVE-2024-30057Medium· 5.4
2y ago

Microsoft Edge for iOS Spoofing Vulnerability

Microsoft Edge for iOS Spoofing Vulnerability

Sunlitmicrosoft · edgeEPSS 0.41%via NVD
CVE-2021-26411High· 8.8CISA KEV0dayPoC
5y ago

Internet Explorer Memory Corruption Vulnerability

Internet Explorer Memory Corruption Vulnerability

Abyssalmicrosoft · edgeEPSS 81%via NVD
CVE-2020-1096Medium· 4.2
6y ago

A remote code execution vulnerability exists when Microsoft Edge PDF Reader improperly handles objects in memory

A remote code execution vulnerability exists when Microsoft Edge PDF Reader improperly handles objects in memory. The vulnerability could corrupt memory in such a way that enables an attacker to execute arbitrary code in the context of t…

Sunlitmicrosoft · edgeEPSS 2.0%via NVD
CVE-2020-1065Medium· 4.2
6y ago

A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory

A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of …

Sunlitmicrosoft · chakracoreEPSS 2.2%via NVD
CVE-2020-1059Medium· 4.3
6y ago

A spoofing vulnerability exists when Microsoft Edge does not properly parse HTTP content

A spoofing vulnerability exists when Microsoft Edge does not properly parse HTTP content. An attacker who successfully exploited this vulnerability could trick a user by redirecting the user to a specially crafted website. The specially …

Sunlitmicrosoft · edgeEPSS 2.1%via NVD
CVE-2020-1056Medium· 5.4
6y ago

An elevation of privilege vulnerability exists when Microsoft Edge does not properly enforce cross-domain policies, which could allow an attacker to access information from one domain and inject it into another domain. In a web-based att…

An elevation of privilege vulnerability exists when Microsoft Edge does not properly enforce cross-domain policies, which could allow an attacker to access information from one domain and inject it into another domain. In a web-based att…

Sunlitmicrosoft · edgeEPSS 2.1%via NVD
CVE-2020-1037Medium· 4.2
6y ago

A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based)

A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitr…

Sunlitmicrosoft · edgeEPSS 2.2%via NVD
CVE-2016-3351Medium· 6.5CISA KEV0day
10y ago

Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to obtain sensitive information via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability."

Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to obtain sensitive information via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability."

Midnightmicrosoft · internet_explorerEPSS 26%via NVD
edge vulnerabilities (CVEs) · VulnSea