Edge

Vendor:

First CVE: Jan 23, 2015 · Active for 11 years

761
Total CVEs
More Total CVEs than 100% of tracked products
63.4
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
6.9
Avg CVSS
Higher Avg CVSS than 39% of tracked products
1.6%
KEV Rate
Higher KEV Rate than 96% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Edge over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 23, 2015
11 years ago
Most Recent CVE
May 12, 2026
74 days ago

CVE Severity & Scoring

Edge761 CVEs
All CVEs352,427 CVEs
LowMediumHighCritical
Attack Vector
Local7 (0.9%)
Network725 (95.3%)
Unknown27 (3.5%)
Physical2 (0.3%)
Adjacent Network0 (0.0%)
Attack Complexity
Low213 (28.0%)
High521 (68.5%)
Unknown27 (3.5%)
User Interaction
None30 (3.9%)
Unknown27 (3.5%)
Required704 (92.5%)
Privileges Required
Low5 (0.7%)
High3 (0.4%)
None726 (95.4%)
Unknown27 (3.5%)

Top CVEs

Signals from CVEs in this product scope (761 CVEs).

761 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows remote atta
Feb 2, 20159.898YESYES
Unspecified vulnerability in Adobe Flash Player through 13.0.0.262 and 14.x, 15.x, and 16.x through 16.0.0.287 on Windows and OS X and through 11.2.202.438 on Linux allows remote a
Jan 23, 20159.897YESYES
The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site,
Nov 10, 20168.895YESYES
The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site,
Nov 10, 20168.895YESYES
Microsoft Internet Explorer 10 and 11 and Microsoft Edge have a type confusion issue in the Layout::MultiColumnBoxBuilder::HandleColumnBreakOnColumnSpanningElement function in msht
Feb 26, 20178.194YESYES
Internet Explorer Memory Corruption Vulnerability
Mar 11, 20218.893YESNO
Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a cra
Sep 28, 20238.887YESNO
Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Nov 3, 20208.885YESNO
Heap buffer overflow in GPU in Google Chrome prior to 107.0.5304.121 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via
Nov 25, 20229.684YESNO
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption
Jan 8, 20197.582NOYES

Exploit Exposure

Signals from CVEs in this product scope (761 CVEs).

CISA KEV
12 CVEs
1.6% of CVEs· 96th percentile
Metasploit
2 CVEs
0.3% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
110 CVEs
14.5% of CVEs· 89th percentile

Social Chatter

Signals from CVEs in this product scope (761 CVEs).

Media Mentions

Signals from CVEs in this product scope (761 CVEs).

Top CNAs Publishing CVEs For Edge

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
117.0.2045.4718.849.0%10
116.0.1938.9818.849.0%10