Edge
Vendor:
First CVE: Jan 23, 2015 · Active for 11 years
761
Total CVEs
More Total CVEs than 100% of tracked products
63.4
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
6.9
Avg CVSS
Higher Avg CVSS than 39% of tracked products
1.6%
KEV Rate
Higher KEV Rate than 96% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Edge over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 23, 2015
11 years ago
Most Recent CVE
May 12, 2026
74 days ago
CVE Severity & Scoring
Edge761 CVEs
27%
70%
All CVEs352,427 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local7 (0.9%)
Network725 (95.3%)
Unknown27 (3.5%)
Physical2 (0.3%)
Adjacent Network0 (0.0%)
Attack Complexity
Low213 (28.0%)
High521 (68.5%)
Unknown27 (3.5%)
User Interaction
None30 (3.9%)
Unknown27 (3.5%)
Required704 (92.5%)
Privileges Required
Low5 (0.7%)
High3 (0.4%)
None726 (95.4%)
Unknown27 (3.5%)
Top CVEs
Signals from CVEs in this product scope (761 CVEs).
761 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-0313CRITICAL Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows remote atta | Feb 2, 2015 | 9.8 | 98 | YES | YES |
CVE-2015-0311CRITICAL Unspecified vulnerability in Adobe Flash Player through 13.0.0.262 and 14.x, 15.x, and 16.x through 16.0.0.287 on Windows and OS X and through 11.2.202.438 on Linux allows remote a | Jan 23, 2015 | 9.8 | 97 | YES | YES |
CVE-2016-7201HIGH The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, | Nov 10, 2016 | 8.8 | 95 | YES | YES |
CVE-2016-7200HIGH The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, | Nov 10, 2016 | 8.8 | 95 | YES | YES |
CVE-2017-0037HIGH Microsoft Internet Explorer 10 and 11 and Microsoft Edge have a type confusion issue in the Layout::MultiColumnBoxBuilder::HandleColumnBreakOnColumnSpanningElement function in msht | Feb 26, 2017 | 8.1 | 94 | YES | YES |
CVE-2021-26411HIGH Internet Explorer Memory Corruption Vulnerability | Mar 11, 2021 | 8.8 | 93 | YES | NO |
CVE-2023-5217HIGH Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a cra | Sep 28, 2023 | 8.8 | 87 | YES | NO |
CVE-2020-16009HIGH Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | Nov 3, 2020 | 8.8 | 85 | YES | NO |
CVE-2022-4135CRITICAL Heap buffer overflow in GPU in Google Chrome prior to 107.0.5304.121 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via | Nov 25, 2022 | 9.6 | 84 | YES | NO |
CVE-2019-0539HIGH A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption | Jan 8, 2019 | 7.5 | 82 | NO | YES |
Exploit Exposure
Signals from CVEs in this product scope (761 CVEs).
CISA KEV
12 CVEs
1.6% of CVEs· 96th percentile
Metasploit
2 CVEs
0.3% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
110 CVEs
14.5% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (761 CVEs).
Media Mentions
Signals from CVEs in this product scope (761 CVEs).
Top CNAs Publishing CVEs For Edge
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 117.0.2045.47 | 1 | 8.8 | 49.0% | 1 | 0 |
| 116.0.1938.98 | 1 | 8.8 | 49.0% | 1 | 0 |