Microsoft Edge vulnerabilities
349 known vulnerabilities affecting microsoft/microsoft_edge.
Total CVEs
349
CISA KEV
2
actively exploited
Public exploits
8
Exploited in wild
2
Severity breakdown
CRITICAL9HIGH168MEDIUM164LOW8
Vulnerabilities
Page 12 of 18
CVE-2021-34506P4MEDIUMCVSS 6.1≥ 1.0.0, < 91.0.864.592023-07-01
CVE-2021-34506 [MEDIUM] CVE-2021-34506: Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
nvd
CVE-2019-1051P4MEDIUMCVSS 4.2≥ 1.0..0, < publication2019-06-12
CVE-2019-1051 [MEDIUM] CWE-787 CVE-2019-1051: A remote code execution vulnerability exists in the way that the Chakra scripting engine handles obj
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the
nvd
CVE-2022-21954P4MEDIUMCVSS 6.1≥ 1.0.0, < 97.0.1072.552022-01-11
CVE-2022-21954 [MEDIUM] CVE-2022-21954: Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
nvd
CVE-2023-28261P4MEDIUMCVSS 5.7≥ 1.0.0, < 111.0.1661.542023-04-27
CVE-2023-28261 [MEDIUM] CWE-269 CVE-2023-28261: Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
nvd
CVE-2019-1054P4MEDIUMCVSS 5.0≥ 1.0..0, < publication2019-06-12
CVE-2019-1054 [MEDIUM] CVE-2019-1054: A security feature bypass vulnerability exists in Edge that allows for bypassing Mark of the Web Tag
A security feature bypass vulnerability exists in Edge that allows for bypassing Mark of the Web Tagging (MOTW). Failing to set the MOTW means that a large number of Microsoft security technologies are bypassed.
In a web-based attack scenario, an attacker could host a malicious website that is designed to exploit the security feature bypass. Alternatively, in
nvd
CVE-2026-58300P4MEDIUMCVSS 5.5≥ 1.0.0.0, < 150.0.4078.482026-07-03
CVE-2026-58300 [MEDIUM] CWE-36 CVE-2026-58300: Absolute path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose in
Absolute path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.
nvd
CVE-2026-58522P4MEDIUMCVSS 5.5≥ 1.0.0.0, < 150.0.4078.482026-07-03
CVE-2026-58522 [MEDIUM] CWE-23 CVE-2026-58522: Relative path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose in
Relative path traversal in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally.
nvd
CVE-2018-8512P4MEDIUMCVSS 5.4vWindows 10 Version 1703 for 32-bit SystemsvWindows 10 Version 1703 for x64-based Systems+4 more2018-10-10
CVE-2018-8512 [MEDIUM] CWE-20 CVE-2018-8512: A security feature bypass vulnerability exists in Microsoft Edge when the Edge Content Security Poli
A security feature bypass vulnerability exists in Microsoft Edge when the Edge Content Security Policy (CSP) fails to properly validate certain specially crafted documents, aka "Microsoft Edge Security Feature Bypass Vulnerability." This affects Microsoft Edge. This CVE ID is unique from CVE-2018-8530.
nvd
CVE-2018-8567P4MEDIUMCVSS 5.4vWindows 10 Version 1709 for 32-bit SystemsvWindows 10 Version 1709 for ARM64-based Systems+8 more2018-11-14
CVE-2018-8567 [MEDIUM] CVE-2018-8567: An elevation of privilege vulnerability exists when Microsoft Edge does not properly enforce cross-d
An elevation of privilege vulnerability exists when Microsoft Edge does not properly enforce cross-domain policies, which could allow an attacker to access information from one domain and inject it into another domain, aka "Microsoft Edge Elevation of Privilege Vulnerability." This affects Microsoft Edge.
nvd
CVE-2023-29345P4MEDIUMCVSS 6.1≥ 1.0.0, < 114.0.1823.372023-06-07
CVE-2023-29345 [MEDIUM] CWE-79 CVE-2023-29345: Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
nvd
CVE-2026-45494P4MEDIUMCVSS 6.1≥ 1.0.0.0, < 148.0.3967.702026-05-18
CVE-2026-45494 [MEDIUM] CWE-79 CVE-2026-45494: Microsoft Edge (Chromium-based) Spoofing Vulnerability
Microsoft Edge (Chromium-based) Spoofing Vulnerability
nvd
CVE-2026-58524P4MEDIUMCVSS 6.1≥ 1.0.0.0, < 150.0.4078.482026-07-03
CVE-2026-58524 [MEDIUM] CWE-79 CVE-2026-58524: Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Ed
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
nvd
CVE-2026-58298P4MEDIUMCVSS 6.1≥ 1.0.0.0, < 150.0.4078.482026-07-03
CVE-2026-58298 [MEDIUM] CWE-79 CVE-2026-58298: Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Ed
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
nvd
CVE-2024-38103P4MEDIUMCVSS 5.9≥ 1.0.0, < 127.0.2651.742024-07-25
CVE-2024-38103 [MEDIUM] CWE-359 CVE-2024-38103: Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
nvd
CVE-2022-23261P4MEDIUMCVSS 5.3≥ 1.0.0, < 98.0.1108.432022-02-07
CVE-2022-23261 [MEDIUM] CVE-2022-23261: Microsoft Edge (Chromium-based) Tampering Vulnerability
Microsoft Edge (Chromium-based) Tampering Vulnerability
nvd
CVE-2025-47182P4MEDIUMCVSS 5.6≥ 1.0.0.0, < 138.0.3351.552025-07-11
CVE-2025-47182 [MEDIUM] CWE-20 CVE-2025-47182: Improper input validation in Microsoft Edge (Chromium-based) allows an authorized attacker to bypass
Improper input validation in Microsoft Edge (Chromium-based) allows an authorized attacker to bypass a security feature locally.
nvd
CVE-2025-26643P4MEDIUMCVSS 5.4≥ 1.0.0.0, < 134.0.3124.512025-03-07
CVE-2025-26643 [MEDIUM] CWE-449 CVE-2025-26643: The UI performs the wrong action in Microsoft Edge (Chromium-based) allows an unauthorized attacker
The UI performs the wrong action in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
nvd
CVE-2026-32208P4MEDIUMCVSS 5.4v-2026-06-19
CVE-2026-32208 [MEDIUM] CWE-79 CVE-2026-32208: Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft En
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Entra ID allows an authorized attacker to perform spoofing over a network.
nvd
CVE-2023-28286P4MEDIUMCVSS 6.1≥ 1.0.0, < 111.0.1661.542023-04-27
CVE-2023-28286 [MEDIUM] CWE-693 CVE-2023-28286: Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
nvd
CVE-2021-24113P4MEDIUMCVSS 5.4≥ 1.0.0, < publication2021-02-25
CVE-2021-24113 [MEDIUM] CVE-2021-24113: Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
nvd