Microsoft
Microsoft Edge: vulnerabilidades y CVE
Microsoft Edge tiene 785 vulnerabilidades publicadas, 32 de ellas en los últimos 12 meses. 11 son críticas y 12 figuran en el catálogo de explotación activa de CISA.
CVE785
Últimos 12 meses32
Críticas11
Explotadas activamente12
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-7971 | Crítica (9.6) | 21% | ⚠ Explotación activa | 21 ago 2024 | Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
| CVE-2023-5217 | Alta (8.8) | 49% | ⚠ Explotación activa | 28 sept 2023 | Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security… |
| CVE-2022-4135 | Crítica (9.6) | 32% | ⚠ Explotación activa | 25 nov 2022 | Heap buffer overflow in GPU in Google Chrome prior to 107.0.5304.121 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security… |
| CVE-2016-3351 | Media (6.5) | 26% | ⚠ Explotación activa | 14 sept 2016 | Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to obtain sensitive information via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability." |
| CVE-2015-0311 | Crítica (9.8) | 86% | ⚠ Explotación activa | 23 ene 2015 | Unspecified vulnerability in Adobe Flash Player through 13.0.0.262 and 14.x, 15.x, and 16.x through 16.0.0.287 on Windows and OS X and through 11.2.202.438 on Linux allows remote attackers to execute arbitrary code via… |
| CVE-2015-0313 | Crítica (9.8) | 95% | ⚠ Explotación activa | 2 feb 2015 | Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows remote attackers to execute arbitrary code via… |
| CVE-2017-0037 | Alta (8.1) | 80% | ⚠ Explotación activa | 26 feb 2017 | Microsoft Internet Explorer 10 and 11 and Microsoft Edge have a type confusion issue in the Layout::MultiColumnBoxBuilder::HandleColumnBreakOnColumnSpanningElement function in mshtml.dll, which allows remote attackers… |
| CVE-2016-7201 | Alta (8.8) | 80% | ⚠ Explotación activa | 10 nov 2016 | The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption… |
| CVE-2016-7200 | Alta (8.8) | 83% | ⚠ Explotación activa | 10 nov 2016 | The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption… |
| CVE-2020-16009 | Alta (8.8) | 48% | ⚠ Explotación activa | 3 nov 2020 | Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
| CVE-2020-0878 | Alta (7.5) | 2.7% | ⚠ Explotación activa | 11 sept 2020 | <p>A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory. The vulnerability could corrupt memory in a way that could allow an attacker to execute arbitrary code in the… |
| CVE-2021-26411 | Alta (8.8) | 81% | ⚠ Explotación activa | 11 mar 2021 | Internet Explorer Memory Corruption Vulnerability |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-95385 | Sin puntuar | 0.23% | — | 29 sept 2026 | Inappropriate implementation in PlatformIntegration in Google Chrome on on Windows prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML… |
| CVE-2026-95384 | Media (5.3) | 0.21% | — | 29 sept 2026 | Race condition in Transactions Platform in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to potentially leak sensitive information via a crafted HTML page. (Chromium security severity: Medium) |
| CVE-2026-95382 | Media (6.5) | 0.28% | — | 29 sept 2026 | Improper input validation in Auth in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to obtain sensitive information via a crafted… |
| CVE-2026-95381 | Alta (8.3) | 0.40% | — | 29 sept 2026 | Improper input validation in Printing in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted… |
| CVE-2026-95380 | Alta (8.8) | 0.40% | — | 29 sept 2026 | Type confusion in V8 in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security… |
| CVE-2026-95376 | Alta (8) | 0.17% | — | 29 sept 2026 | Externally controlled reference in DevTools in Google Chrome prior to 154.0.8037.57 allowed an adjacent attacker leveraging social engineering to bypass system access restrictions via crafted network traffic. (Chromium… |
| CVE-2026-95374 | Sin puntuar | 0.24% | — | 29 sept 2026 | Incorrect authorization in Network in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium) |
| CVE-2026-95373 | Alta (8.8) | 0.37% | — | 29 sept 2026 | Use after free in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security… |
| CVE-2026-95372 | Alta (8.3) | 0.38% | — | 29 sept 2026 | Use after free in Chromecast in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page.… |
| CVE-2026-95363 | Media (5.4) | 0.22% | — | 29 sept 2026 | UI misrepresentation in FileSystem in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium) |
| CVE-2026-95361 | Media (4.3) | 0.27% | — | 29 sept 2026 | Confused deputy in DevTools in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low) |
| CVE-2026-95360 | Media (5.3) | 0.21% | — | 29 sept 2026 | Race condition in Editing in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium) |
| CVE-2026-95358 | Media (4.4) | 0.10% | — | 29 sept 2026 | Incorrect authorization in Mobile in Google Chrome on on Android prior to 154.0.8037.57 allowed a local attacker to bypass system access restrictions into a privileged page via a co-installed app. (Chromium security… |
| CVE-2026-95330 | Media (6.5) | 0.31% | — | 29 sept 2026 | Improper state validation in Downloads in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium) |
| CVE-2026-95326 | Sin puntuar | 0.25% | — | 29 sept 2026 | Incomplete cleanup in Bluetooth in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity:… |
| CVE-2026-95314 | Sin puntuar | 0.22% | — | 29 sept 2026 | Incorrect authorization in HID in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium security… |
| CVE-2026-95303 | Sin puntuar | 0.25% | — | 29 sept 2026 | Incomplete cleanup in SmartCard in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity:… |
| CVE-2026-95295 | Media (4.6) | 0.12% | — | 29 sept 2026 | Information leak in Mobile in Google Chrome on on iOS prior to 154.0.8037.57 allowed a local attacker to leak sensitive information via physical access. (Chromium security severity: Medium) |
| CVE-2026-95285 | Sin puntuar | 0.24% | — | 29 sept 2026 | Missing authorization in WebView in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium… |
| CVE-2026-95278 | Sin puntuar | 0.22% | — | 29 sept 2026 | Missing authorization in WakeLock in Google Chrome prior to 154.0.8037.57 allowed a remote attacker who had compromised the renderer process to bypass system access restrictions via a crafted HTML page. (Chromium… |
| CVE-2026-95275 | Sin puntuar | 0.25% | — | 29 sept 2026 | Incorrect reference resolution in MediaStream in Google Chrome prior to 154.0.8037.57 allowed a remote attacker to bypass web origin policy into a privileged page via a crafted HTML page. (Chromium security severity:… |
| CVE-2026-95284 | Crítica (9.6) | 0.29% | — | 29 sept 2026 | Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical) |
| CVE-2026-47252 | Crítica (9) | 0.70% | — | 17 sept 2026 | Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, authenticated users with INSERT or UPDATE access to affected macOS virtual tables can execute operating-system commands because the Chrome plugin… |
| CVE-2026-70341 | Alta (8.5) | 0.66% | — | 11 sept 2026 | Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network. |
| CVE-2026-70331 | Media (5.4) | 0.41% | — | 28 ago 2026 | Improper neutralization of input used for llm prompting in Microsoft Edge for iOS allows an unauthorized attacker to perform spoofing over a network. |
| CVE-2026-66310 | Alta (7.1) | 0.36% | — | 4 ago 2026 | External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally. |
| CVE-2026-62828 | Media (5.4) | 0.41% | — | 28 jul 2026 | Improper input validation in Microsoft Edge for Android allows an unauthorized attacker to perform tampering over a network. |
| CVE-2026-35429 | Media (4.3) | 0.70% | — | 12 may 2026 | User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. |
| CVE-2026-33119 | Media (5.4) | 0.41% | — | 10 abr 2026 | User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. |
| CVE-2026-26133 | Alta (7.1) | 0.54% | — | 16 mar 2026 | AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.