Microsoft Edge Chromium vulnerabilities

205 known vulnerabilities affecting microsoft/edge_chromium.

Total CVEs
205
CISA KEV
9
actively exploited
Public exploits
3
Exploited in wild
7
Severity breakdown
CRITICAL11HIGH97MEDIUM90LOW7

Vulnerabilities

Page 4 of 11
CVE-2024-21423MEDIUMCVSS 4.8fixed in 122.0.2365.522024-02-23
CVE-2024-21423 [MEDIUM] CWE-693 CVE-2024-21423: Microsoft Edge (Chromium-based) Information Disclosure Vulnerability Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
nvd
CVE-2024-21399HIGHCVSS 8.3fixed in 121.0.2277.982024-02-02
CVE-2024-21399 [HIGH] CWE-416 CVE-2024-21399: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
nvd
CVE-2024-21388MEDIUMCVSS 6.5fixed in 121.0.2277.832024-01-30
CVE-2024-21388 [MEDIUM] CWE-20 CVE-2024-21388: Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
nvd
CVE-2024-21326CRITICALCVSS 9.6fixed in 121.0.2277.832024-01-26
CVE-2024-21326 [CRITICAL] CWE-416 CVE-2024-21326: Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
nvd
CVE-2024-21385HIGHCVSS 8.3fixed in 121.0.2277.832024-01-26
CVE-2024-21385 [HIGH] CWE-416 CVE-2024-21385: Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
nvd
CVE-2024-21382MEDIUMCVSS 4.3fixed in 121.0.2277.832024-01-26
CVE-2024-21382 [MEDIUM] CWE-942 CVE-2024-21382: Microsoft Edge for Android Information Disclosure Vulnerability Microsoft Edge for Android Information Disclosure Vulnerability
nvd
CVE-2024-21383LOWCVSS 3.3fixed in 121.0.2277.832024-01-26
CVE-2024-21383 [LOW] CWE-347 CVE-2024-21383: Microsoft Edge (Chromium-based) Spoofing Vulnerability Microsoft Edge (Chromium-based) Spoofing Vulnerability
nvd
CVE-2024-21336LOWCVSS 2.5fixed in 121.0.2277.832024-01-26
CVE-2024-21336 [LOW] CWE-357 CVE-2024-21336: Microsoft Edge (Chromium-based) Spoofing Vulnerability Microsoft Edge (Chromium-based) Spoofing Vulnerability
nvd
CVE-2024-20721MEDIUMCVSS 5.5fixed in 120.0.2210.1332024-01-15
CVE-2024-20721 [MEDIUM] CWE-20 CVE-2024-20721: Acrobat Reader T5 (MSFT Edge) versions 120.0.2210.91 and earlier are affected by an Improper Input V Acrobat Reader T5 (MSFT Edge) versions 120.0.2210.91 and earlier are affected by an Improper Input Validation vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a mal
nvd
CVE-2024-20709MEDIUMCVSS 5.5fixed in 120.0.2210.1332024-01-15
CVE-2024-20709 [MEDIUM] CWE-20 CVE-2024-20709: Acrobat Reader T5 (MSFT Edge) versions 120.0.2210.91 and earlier are affected by an Improper Input V Acrobat Reader T5 (MSFT Edge) versions 120.0.2210.91 and earlier are affected by an Improper Input Validation vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a mal
nvd
CVE-2024-21337MEDIUMCVSS 5.2fixed in 120.0.2210.1332024-01-11
CVE-2024-21337 [MEDIUM] CWE-122 CVE-2024-21337: Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
nvd
CVE-2024-20675MEDIUMCVSS 6.3fixed in 120.0.2210.1332024-01-11
CVE-2024-20675 [MEDIUM] CWE-284 CVE-2024-20675: Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
nvd
CVE-2023-36878MEDIUMCVSS 4.3fixed in 120.0.2210.772023-12-15
CVE-2023-36878 [MEDIUM] CVE-2023-36878: Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
nvd
CVE-2023-6702HIGHCVSS 8.8fixed in 120.0.2210.772023-12-14
CVE-2023-6702 [HIGH] CWE-843 CVE-2023-6702: Type confusion in V8 in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potential Type confusion in V8 in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2023-35618CRITICALCVSS 9.6fixed in 120.0.2210.612023-12-07
CVE-2023-35618 [CRITICAL] CWE-416 CVE-2023-35618: Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
nvd
CVE-2023-36880MEDIUMCVSS 4.8fixed in 120.0.2210.612023-12-07
CVE-2023-36880 [MEDIUM] CVE-2023-36880: Microsoft Edge (Chromium-based) Information Disclosure Vulnerability Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
nvd
CVE-2023-38174MEDIUMCVSS 4.3fixed in 120.0.2210.612023-12-07
CVE-2023-38174 [MEDIUM] CVE-2023-38174: Microsoft Edge (Chromium-based) Information Disclosure Vulnerability Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
nvd
CVE-2023-6345CRITICALCVSS 9.6KEVfixed in 119.0.2151.972023-11-29
CVE-2023-6345 [CRITICAL] CWE-190 CVE-2023-6345: Integer overflow in Skia in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had Integer overflow in Skia in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)
nvd
CVE-2023-36026MEDIUMCVSS 4.3fixed in 119.0.2151.722023-11-16
CVE-2023-36026 [MEDIUM] CVE-2023-36026: Microsoft Edge (Chromium-based) Spoofing Vulnerability Microsoft Edge (Chromium-based) Spoofing Vulnerability
nvd
CVE-2023-36008MEDIUMCVSS 6.6fixed in 119.0.2151.722023-11-16
CVE-2023-36008 [MEDIUM] CWE-416 CVE-2023-36008: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
nvd