cbcvebase.

Microsoft Edge vulnerabilities

349 known vulnerabilities affecting microsoft/microsoft_edge.

Total CVEs
349
CISA KEV
2
actively exploited
Public exploits
8
Exploited in wild
2
Severity breakdown
CRITICAL9HIGH168MEDIUM164LOW8

Vulnerabilities

Page 2 of 18
CVE-2025-21279P3HIGHCVSS 8.8≥ 1.0.0.0, < 133.0.3065.512025-02-06
CVE-2025-21279 [HIGH] CWE-843 CVE-2025-21279: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
nvd
CVE-2026-56645P3HIGHCVSS 8.8≥ 1.0.0.0, < 150.0.4078.482026-07-03
CVE-2026-56645 [HIGH] CWE-122 CVE-2026-56645: Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to exe Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2019-0592P3HIGHCVSS 7.5vWindows 10 Version 1703 for 32-bit SystemsvWindows 10 Version 1703 for x64-based Systems+10 more2019-04-08
CVE-2019-0592 [HIGH] CWE-787 CVE-2019-0592: A remote code execution vulnerability exists in the way that the Chakra scripting engine handles obj A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0611.
nvd
CVE-2025-21283P3HIGHCVSS 8.8≥ 1.0.0.0, < 133.0.3065.512025-02-06
CVE-2025-21283 [HIGH] CWE-1222 CVE-2025-21283: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
nvd
CVE-2025-21408P3HIGHCVSS 8.8≥ 1.0.0.0, < 133.0.3065.512025-02-06
CVE-2025-21408 [HIGH] CWE-843 CVE-2025-21408: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
nvd
CVE-2025-21342P3HIGHCVSS 8.8≥ 1.0.0.0, < 133.0.3065.512025-02-06
CVE-2025-21342 [HIGH] CWE-843 CVE-2025-21342: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
nvd
CVE-2024-43596P3HIGHCVSS 8.8≥ 1.0.0, < 130.0.2849.462024-10-17
CVE-2024-43596 [HIGH] CWE-843 CVE-2024-43596: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
nvd
CVE-2024-43595P3HIGHCVSS 8.8≥ 1.0.0, < 130.0.2849.462024-10-17
CVE-2024-43595 [HIGH] CWE-126 CVE-2024-43595: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
nvd
CVE-2024-43496P3HIGHCVSS 8.8≥ 1.0.0, < 129.0.2792.522024-09-19
CVE-2024-43496 [HIGH] CWE-787 CVE-2024-43496: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
nvd
CVE-2026-57974P3HIGHCVSS 8.8≥ 1.0.0.0, < 150.0.4078.482026-07-03
CVE-2026-57974 [HIGH] CWE-190 CVE-2026-57974: Integer overflow or wraparound in Microsoft Edge (Chromium-based) allows an unauthorized attacker to Integer overflow or wraparound in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-58284P3HIGHCVSS 8.3≥ 1.0.0.0, < 150.0.4078.482026-07-03
CVE-2026-58284 [HIGH] CWE-285 CVE-2026-58284: Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2023-35618P3CRITICALCVSS 9.6≥ 1.0.0, < 120.0.2210.612023-12-07
CVE-2023-35618 [CRITICAL] CWE-416 CVE-2023-35618: Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
nvd
CVE-2020-1555P3HIGHCVSS 8.8≥ 1.0..0, < publication2020-08-17
CVE-2020-1555 [HIGH] CWE-787 CVE-2020-1555: A remote code execution vulnerability exists in the way that the scripting engine handles objects in A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same use
nvd
CVE-2018-8125P3HIGHCVSS 7.5vWindows 10 Version 1709 for 32-bit SystemsvWindows 10 Version 1709 for x64-based Systems+2 more2018-07-11
CVE-2018-8125 [HIGH] CWE-787 CVE-2018-8125: A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memo A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka "Microsoft Edge Memory Corruption Vulnerability." This affects Microsoft Edge. This CVE ID is unique from CVE-2018-8262, CVE-2018-8274, CVE-2018-8275, CVE-2018-8279, CVE-2018-8301.
nvd
CVE-2025-25000P3HIGHCVSS 8.8≥ 1.0.0.0, < 135.0.3179.542025-04-04
CVE-2025-25000 [HIGH] CWE-843 CVE-2025-25000: Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) all Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2024-43489P3HIGHCVSS 8.8≥ 1.0.0, < 129.0.2792.522024-09-19
CVE-2024-43489 [HIGH] CWE-843 CVE-2024-43489: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
nvd
CVE-2025-49713P3HIGHCVSS 8.8≥ 1.0.0.0, < 138.0.3351.652025-07-02
CVE-2025-49713 [HIGH] CWE-843 CVE-2025-49713: Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) all Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-58281P3HIGHCVSS 8.3≥ 1.0.0.0, < 150.0.4078.482026-07-11
CVE-2026-58281 [HIGH] CWE-502 CVE-2026-58281: Deserialization of untrusted data in Microsoft Edge (Chromium-based) allows an unauthorized attacker Deserialization of untrusted data in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2026-58289P3HIGHCVSS 8.3≥ 1.0.0.0, < 150.0.4078.482026-07-03
CVE-2026-58289 [HIGH] CWE-843 CVE-2026-58289: Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) all Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2018-8280P3HIGHCVSS 7.5vWindows 10 Version 1803 for 32-bit SystemsvWindows 10 Version 1803 for x64-based Systems2018-07-11
CVE-2018-8280 [HIGH] CWE-787 CVE-2018-8280: A remote code execution vulnerability exists in the way that the Chakra scripting engine handles obj A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2018-8286, CVE-2018-8290, CVE-2018-8294.
nvd
Microsoft Edge vulnerabilities | cvebase