Product of Microsoft

Internet Explorer

As of , 36 Microsoft Internet Explorer vulnerabilities are on CISA's list of exploited vulnerabilities, 6 of them used in ransomware campaigns; 2 were added in 2026. Patch first: CVE-2010-0249.

Patch first

Patch first
#VulnerabilityProductOur groupListedDeadlineEPSS
1CVE-2010-0249Use-After-FreeMicrosoft Internet ExplorerPatch this weekMetasploit module; EPSS 0.92; verified Exploit-DB entry0.92
2CVE-2010-0806Use-After-FreeMicrosoft Internet ExplorerPatch this weekMetasploit module; EPSS 0.82; verified Exploit-DB entry0.82
3CVE-2010-3962Uninitialized Memory CorruptionMicrosoft Internet ExplorerPatch this weekMetasploit module; EPSS 0.97; verified Exploit-DB entry0.97
4CVE-2013-3893Resource Management ErrorsMicrosoft Internet ExplorerPatch this weekMetasploit module; EPSS 0.88; verified Exploit-DB entry0.88
5CVE-2012-4792Use-After-FreeMicrosoft Internet ExplorerPatch this weekMetasploit module; EPSS 0.79; verified Exploit-DB entry0.79
6CVE-2013-3163Memory CorruptionMicrosoft Internet ExplorerPatch this weekMetasploit module; EPSS 0.71; verified Exploit-DB entry0.71
7CVE-2012-4969Use-After-FreeMicrosoft Internet ExplorerPatch this weekMetasploit module; EPSS 0.80; verified Exploit-DB entry0.80
8CVE-2014-0322Use-After-FreeMicrosoft Internet ExplorerPatch this weekMetasploit module; EPSS 0.85; verified Exploit-DB entry0.85
9CVE-2013-2551Use-After-FreeMicrosoft Internet ExplorerPatch this weekRansomware use; Metasploit module; EPSS 0.74; verified Exploit-DB entry0.74
10CVE-2013-1347Remote Code ExecutionMicrosoft Internet ExplorerPatch this weekMetasploit module; EPSS 0.78; verified Exploit-DB entry0.78
11CVE-2013-3897Use-After-FreeMicrosoft Internet ExplorerPatch this weekMetasploit module; EPSS 0.77; verified Exploit-DB entry0.77
12CVE-2016-0189Memory CorruptionMicrosoft Internet ExplorerPatch this weekRansomware use; Metasploit module; EPSS 0.940.94
13CVE-2013-7331Information DisclosureMicrosoft Internet ExplorerPatch this weekMetasploit module; EPSS 0.500.50
14CVE-2017-0059Information DisclosureMicrosoft Internet ExplorerPatch this weekEPSS 0.62; verified Exploit-DB entry0.62
15CVE-2019-1429Scripting Engine Memory CorruptionMicrosoft Internet ExplorerPatch this weekEPSS 0.77; verified Exploit-DB entry0.77
16CVE-2019-0752Type ConfusionMicrosoft Internet ExplorerPatch this weekRansomware use; EPSS 0.820.82
17CVE-2014-1776Memory CorruptionMicrosoft Internet ExplorerPatch this weekEPSS 0.830.83
18CVE-2020-0674Scripting Engine Memory CorruptionMicrosoft Internet ExplorerPatch this weekEPSS 0.870.87
19CVE-2021-26411Memory CorruptionMicrosoft Internet ExplorerPatch this weekRansomware use; EPSS 0.810.81
20CVE-2015-2502Memory CorruptionMicrosoft Internet ExplorerPatch this weekEPSS 0.510.51
21CVE-2015-2419Memory CorruptionMicrosoft Internet ExplorerPatch this weekEPSS 0.530.53
22CVE-2019-1367Scripting Engine Memory CorruptionMicrosoft Internet ExplorerPatch this weekRansomware use; EPSS 0.520.52
23CVE-2020-0968Scripting Engine Memory CorruptionMicrosoft Internet ExplorerPatch this weekRansomware use0.31
24CVE-2014-4123Privilege EscalationMicrosoft Internet ExplorerPatch soon0.47
25CVE-2015-0071ASLR BypassMicrosoft Internet ExplorerPatch soon0.34

The next 11, from number 26

Added each year

1020302021: 8820212022: 222220222023: 1120232024: 1120242025: 2220252026: 222026
Entries CISA added each year, removed ones included. Source: CISA KEV.
Show the numbers
Periodentries added
20218
202222
20231
20241
20252
20262

Used in ransomware

Changes CISA made to these entries

  1. CVE-2020-0968 Microsoft Internet ExplorerRansomware use: Unknown to Known.
  2. CVE-2016-0189 Microsoft Internet ExplorerRansomware use: Unknown to Known.

Every change we recorded