cbcvebase.

Microsoft Edge vulnerabilities

349 known vulnerabilities affecting microsoft/microsoft_edge.

Total CVEs
349
CISA KEV
2
actively exploited
Public exploits
8
Exploited in wild
2
Severity breakdown
CRITICAL9HIGH168MEDIUM164LOW8

Vulnerabilities

Page 10 of 18
CVE-2019-0678P3MEDIUMCVSS 6.8vWindows Server 2016vWindows 10 Version 1607 for 32-bit Systems+13 more2019-04-09
CVE-2019-0678 [MEDIUM] CWE-863 CVE-2019-0678: An elevation of privilege vulnerability exists when Microsoft Edge does not properly enforce cross-d An elevation of privilege vulnerability exists when Microsoft Edge does not properly enforce cross-domain policies, which could allow an attacker to access information from one domain and inject it into another domain.In a web-based attack scenario, an attacker could host a website that is used to attempt to exploit the vulnerability, aka 'Microsoft E
nvd
CVE-2025-60711P3MEDIUMCVSS 6.3≥ 1.0.0.0, < 142.0.3595.532025-10-31
CVE-2025-60711 [MEDIUM] CWE-693 CVE-2025-60711: Protection mechanism failure in Microsoft Edge (Chromium-based) allows an unauthorized attacker to e Protection mechanism failure in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-21223P3HIGHCVSS 7.1≥ 1.0.0.0, < 144.0.3719.822026-01-16
CVE-2026-21223 [HIGH] CWE-269 CVE-2026-21223: Improper privilege management in Microsoft Edge (Chromium-based) allows an authorized attacker to by Improper privilege management in Microsoft Edge (Chromium-based) allows an authorized attacker to bypass a security feature locally.
nvd
CVE-2023-38187P3MEDIUMCVSS 6.5≥ 1.0.0, < 115.0.1901.1832023-07-21
CVE-2023-38187 [MEDIUM] CWE-269 CVE-2023-38187: Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
nvd
CVE-2026-58523P3MEDIUMCVSS 6.5≥ 1.0.0.0, < 150.0.4078.482026-07-03
CVE-2026-58523 [MEDIUM] CWE-284 CVE-2026-58523: Improper access control in Microsoft Edge for Android allows an unauthorized attacker to bypass a se Improper access control in Microsoft Edge for Android allows an unauthorized attacker to bypass a security feature over a network.
nvd
CVE-2018-8351P3MEDIUMCVSS 6.5vWindows 10 for 32-bit SystemsvWindows 10 for x64-based Systems+2 more2018-08-15
CVE-2018-8351 [MEDIUM] CWE-829 CVE-2018-8351: An information disclosure vulnerability exists when affected Microsoft browsers improperly allow cro An information disclosure vulnerability exists when affected Microsoft browsers improperly allow cross-frame interaction, aka "Microsoft Browser Information Disclosure Vulnerability." This affects Internet Explorer 11, Microsoft Edge, Internet Explorer 10.
nvd
CVE-2025-29806P3MEDIUMCVSS 6.5≥ 1.0.0.0, < 129.0.2792.522025-03-23
CVE-2025-29806 [MEDIUM] CWE-843 CVE-2025-29806: No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2019-1023P3MEDIUMCVSS 6.5≥ 1.0..0, < publication2019-06-12
CVE-2019-1023 [MEDIUM] CWE-200 CVE-2019-1023: An information disclosure vulnerability exists when the scripting engine does not properly handle ob An information disclosure vulnerability exists when the scripting engine does not properly handle objects in memory in Microsoft Edge. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system. In a web-based attack scenario, an attacker could host a website in an attempt to exploit the v
nvd
CVE-2018-8276P3MEDIUMCVSS 6.5vWindows 10 Version 1703 for 32-bit SystemsvWindows 10 Version 1703 for x64-based Systems+4 more2018-07-11
CVE-2018-8276 [MEDIUM] CVE-2018-8276: A security feature bypass vulnerability exists in the Microsoft Chakra scripting engine that allows A security feature bypass vulnerability exists in the Microsoft Chakra scripting engine that allows Control Flow Guard (CFG) to be bypassed, aka "Scripting Engine Security Feature Bypass Vulnerability." This affects Microsoft Edge, ChakraCore.
nvd
CVE-2019-1193P4MEDIUMCVSS 6.4≥ 1.0..0, < publication2019-08-14
CVE-2019-1193 [MEDIUM] CWE-787 CVE-2019-1193: A remote code execution vulnerability exists in the way that Microsoft browsers access objects in me A remote code execution vulnerability exists in the way that Microsoft browsers access objects in memory. The vulnerability could corrupt memory in a way that could allow an attacker to execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user
nvd
CVE-2023-38157P4MEDIUMCVSS 6.5≥ 1.0.0, < 115.0.1901.2002023-08-07
CVE-2023-38157 [MEDIUM] CWE-693 CVE-2023-38157: Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
nvd
CVE-2019-0833P3MEDIUMCVSS 6.5vWindows 10 Version 1809 for 32-bit SystemsvWindows 10 Version 1809 for x64-based Systems+2 more2019-04-09
CVE-2019-0833 [MEDIUM] CVE-2019-0833: An information disclosure vulnerability exists when Microsoft Edge improperly handles objects in mem An information disclosure vulnerability exists when Microsoft Edge improperly handles objects in memory, aka 'Microsoft Edge Information Disclosure Vulnerability'.
nvd
CVE-2021-30615P3MEDIUMCVSS 6.5vunspecified2021-09-03
CVE-2021-30615 [MEDIUM] CVE-2021-30615: Chromium: CVE-2021-30615 Cross-origin data leak in Navigation Chromium: CVE-2021-30615 Cross-origin data leak in Navigation
nvd
CVE-2026-58291P4MEDIUMCVSS 6.1≥ 1.0.0.0, < 150.0.4078.482026-07-03
CVE-2026-58291 [MEDIUM] CWE-672 CVE-2026-58291: Operation on a resource after expiration or release in Microsoft Edge (Chromium-based) allows an una Operation on a resource after expiration or release in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2023-36024P4HIGHCVSS 7.1≥ 1.0.0, < 119.0.2151.582023-11-10
CVE-2023-36024 [HIGH] CWE-269 CVE-2023-36024: Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
nvd
CVE-2023-36562P4HIGHCVSS 7.1≥ 1.0.0, < 117.0.2045.312023-09-15
CVE-2023-36562 [HIGH] CWE-416 CVE-2023-36562: Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
nvd
CVE-2023-21719P3MEDIUMCVSS 6.5≥ 1.0.0, < 109.0.1518.612023-01-24
CVE-2023-21719 [MEDIUM] CWE-863 CVE-2023-21719: Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
nvd
CVE-2025-21185P4MEDIUMCVSS 6.5≥ 1.0.0.0, < 132.0.2957.1152025-01-17
CVE-2025-21185 [MEDIUM] CWE-284 CVE-2025-21185: Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
nvd
CVE-2019-0746P4MEDIUMCVSS 6.5vWindows Server 20122019-04-09
CVE-2019-0746 [MEDIUM] CVE-2019-0746: An information disclosure vulnerability exists when the scripting engine does not properly handle ob An information disclosure vulnerability exists when the scripting engine does not properly handle objects in memory in Microsoft Edge, aka 'Scripting Engine Information Disclosure Vulnerability'.
nvd
CVE-2025-47963P3MEDIUMCVSS 6.5≥ 1.0.0.0, < 138.0.3351.552025-07-11
CVE-2025-47963 [MEDIUM] CWE-451 CVE-2025-47963: No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
nvd
Microsoft Edge vulnerabilities | cvebase