Product of Microsoft
Internet Explorer
As of , 36 Microsoft Internet Explorer vulnerabilities are on CISA's list of exploited vulnerabilities, 6 of them used in ransomware campaigns; 2 were added in 2026. Patch first: CVE-2010-0249.
Patch first
| # | Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|---|
| 1 | CVE-2010-0249Use-After-Free | Microsoft Internet Explorer | Patch this weekMetasploit module; EPSS 0.92; verified Exploit-DB entry | 0.92 | ||
| 2 | CVE-2010-0806Use-After-Free | Microsoft Internet Explorer | Patch this weekMetasploit module; EPSS 0.82; verified Exploit-DB entry | 0.82 | ||
| 3 | CVE-2010-3962Uninitialized Memory Corruption | Microsoft Internet Explorer | Patch this weekMetasploit module; EPSS 0.97; verified Exploit-DB entry | 0.97 | ||
| 4 | CVE-2013-3893Resource Management Errors | Microsoft Internet Explorer | Patch this weekMetasploit module; EPSS 0.88; verified Exploit-DB entry | 0.88 | ||
| 5 | CVE-2012-4792Use-After-Free | Microsoft Internet Explorer | Patch this weekMetasploit module; EPSS 0.79; verified Exploit-DB entry | 0.79 | ||
| 6 | CVE-2013-3163Memory Corruption | Microsoft Internet Explorer | Patch this weekMetasploit module; EPSS 0.71; verified Exploit-DB entry | 0.71 | ||
| 7 | CVE-2012-4969Use-After-Free | Microsoft Internet Explorer | Patch this weekMetasploit module; EPSS 0.80; verified Exploit-DB entry | 0.80 | ||
| 8 | CVE-2014-0322Use-After-Free | Microsoft Internet Explorer | Patch this weekMetasploit module; EPSS 0.85; verified Exploit-DB entry | 0.85 | ||
| 9 | CVE-2013-2551Use-After-Free | Microsoft Internet Explorer | Patch this weekRansomware use; Metasploit module; EPSS 0.74; verified Exploit-DB entry | 0.74 | ||
| 10 | CVE-2013-1347Remote Code Execution | Microsoft Internet Explorer | Patch this weekMetasploit module; EPSS 0.78; verified Exploit-DB entry | 0.78 | ||
| 11 | CVE-2013-3897Use-After-Free | Microsoft Internet Explorer | Patch this weekMetasploit module; EPSS 0.77; verified Exploit-DB entry | 0.77 | ||
| 12 | CVE-2016-0189Memory Corruption | Microsoft Internet Explorer | Patch this weekRansomware use; Metasploit module; EPSS 0.94 | 0.94 | ||
| 13 | CVE-2013-7331Information Disclosure | Microsoft Internet Explorer | Patch this weekMetasploit module; EPSS 0.50 | 0.50 | ||
| 14 | CVE-2017-0059Information Disclosure | Microsoft Internet Explorer | Patch this weekEPSS 0.62; verified Exploit-DB entry | 0.62 | ||
| 15 | CVE-2019-1429Scripting Engine Memory Corruption | Microsoft Internet Explorer | Patch this weekEPSS 0.77; verified Exploit-DB entry | 0.77 | ||
| 16 | CVE-2019-0752Type Confusion | Microsoft Internet Explorer | Patch this weekRansomware use; EPSS 0.82 | 0.82 | ||
| 17 | CVE-2014-1776Memory Corruption | Microsoft Internet Explorer | Patch this weekEPSS 0.83 | 0.83 | ||
| 18 | CVE-2020-0674Scripting Engine Memory Corruption | Microsoft Internet Explorer | Patch this weekEPSS 0.87 | 0.87 | ||
| 19 | CVE-2021-26411Memory Corruption | Microsoft Internet Explorer | Patch this weekRansomware use; EPSS 0.81 | 0.81 | ||
| 20 | CVE-2015-2502Memory Corruption | Microsoft Internet Explorer | Patch this weekEPSS 0.51 | 0.51 | ||
| 21 | CVE-2015-2419Memory Corruption | Microsoft Internet Explorer | Patch this weekEPSS 0.53 | 0.53 | ||
| 22 | CVE-2019-1367Scripting Engine Memory Corruption | Microsoft Internet Explorer | Patch this weekRansomware use; EPSS 0.52 | 0.52 | ||
| 23 | CVE-2020-0968Scripting Engine Memory Corruption | Microsoft Internet Explorer | Patch this weekRansomware use | 0.31 | ||
| 24 | CVE-2014-4123Privilege Escalation | Microsoft Internet Explorer | Patch soon | 0.47 | ||
| 25 | CVE-2015-0071ASLR Bypass | Microsoft Internet Explorer | Patch soon | 0.34 |
Added each year
Show the numbers
| Period | entries added |
|---|---|
| 2021 | 8 |
| 2022 | 22 |
| 2023 | 1 |
| 2024 | 1 |
| 2025 | 2 |
| 2026 | 2 |