cbcvebase.

Microsoft Edge vulnerabilities

349 known vulnerabilities affecting microsoft/microsoft_edge.

Total CVEs
349
CISA KEV
2
actively exploited
Public exploits
8
Exploited in wild
2
Severity breakdown
CRITICAL9HIGH168MEDIUM164LOW8

Vulnerabilities

Page 5 of 18
CVE-2026-58294P3HIGHCVSS 7.5≥ 1.0.0.0, < 150.0.4078.482026-07-03
CVE-2026-58294 [HIGH] CWE-416 CVE-2026-58294: Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code ov Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2019-0590P3HIGHCVSS 7.5vWindows 10 for 32-bit SystemsvWindows 10 for x64-based Systems+15 more2019-03-05
CVE-2019-0590 [HIGH] CWE-787 CVE-2019-0590: A remote code execution vulnerability exists in the way that the scripting engine handles objects in A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0591, CVE-2019-0593, CVE-2019-0605, CVE-2019-0607, CVE-2019-0610, CVE-2019-0640, CVE-2019-0642, CVE-2019-0644, CVE-2019-0651, CVE-2019-0
nvd
CVE-2019-0634P3HIGHCVSS 7.5vWindows 10 Version 1803 for 32-bit SystemsvWindows 10 Version 1803 for x64-based Systems+5 more2019-03-05
CVE-2019-0634 [HIGH] CWE-787 CVE-2019-0634: A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memo A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka 'Microsoft Edge Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0645, CVE-2019-0650.
nvd
CVE-2019-0565P3HIGHCVSS 7.5vWindows 10 Version 1803 for 32-bit SystemsvWindows 10 Version 1803 for ARM64-based Systems+5 more2019-01-08
CVE-2019-0565 [HIGH] CWE-787 CVE-2019-0565: A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memo A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka "Microsoft Edge Memory Corruption Vulnerability." This affects Microsoft Edge.
nvd
CVE-2026-58525P3HIGHCVSS 8.2≥ 1.0.0.0, < 150.0.4078.502026-07-08
CVE-2026-58525 [HIGH] CWE-284 CVE-2026-58525: Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.
nvd
CVE-2021-30610P3HIGHCVSS 8.8vunspecified2021-09-03
CVE-2021-30610 [HIGH] CWE-416 CVE-2021-30610: Chromium: CVE-2021-30610 Use after free in Extensions API Chromium: CVE-2021-30610 Use after free in Extensions API
nvd
CVE-2021-30620P3HIGHCVSS 8.8vunspecified2021-09-03
CVE-2021-30620 [HIGH] CVE-2021-30620: Chromium: CVE-2021-30620 Insufficient policy enforcement in Blink Chromium: CVE-2021-30620 Insufficient policy enforcement in Blink
nvd
CVE-2025-29815P3HIGHCVSS 7.6≥ 1.0.0.0, < 134.0.3124.662025-04-04
CVE-2025-29815 [HIGH] CWE-416 CVE-2025-29815: Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.
nvd
CVE-2026-58292P3HIGHCVSS 7.5≥ 1.0.0.0, < 150.0.4078.482026-07-03
CVE-2026-58292 [HIGH] CWE-20 CVE-2026-58292: Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to exec Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
nvd
CVE-2018-8583P3HIGHCVSS 7.5vWindows 10 for 32-bit SystemsvWindows 10 for x64-based Systems+15 more2018-12-12
CVE-2018-8583 [HIGH] CWE-787 CVE-2018-8583: A remote code execution vulnerability exists in the way that the Chakra scripting engine handles obj A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2018-8617, CVE-2018-8618, CVE-2018-8624, CVE-2018-8629.
nvd
CVE-2021-31982P3HIGHCVSS 8.8≥ 1.0.0, < 91.0.864.372023-07-01
CVE-2021-31982 [HIGH] CWE-693 CVE-2021-31982: Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
nvd
CVE-2021-26436P3HIGHCVSS 8.1≥ 1.0.0, < 93.0.961.382021-09-02
CVE-2021-26436 [HIGH] CVE-2021-26436: Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
nvd
CVE-2018-8357P3HIGHCVSS 8.3vWindows 10 for 32-bit SystemsvWindows 10 for x64-based Systems+9 more2018-08-15
CVE-2018-8357 [HIGH] CVE-2018-8357: An elevation of privilege vulnerability exists in Microsoft browsers allowing sandbox escape, aka "M An elevation of privilege vulnerability exists in Microsoft browsers allowing sandbox escape, aka "Microsoft Browser Elevation of Privilege Vulnerability." This affects Internet Explorer 11, Microsoft Edge.
nvd
CVE-2018-8377P3HIGHCVSS 7.5vWindows 10 Version 1803 for 32-bit SystemsvWindows 10 Version 1803 for x64-based Systems2018-08-15
CVE-2018-8377 [HIGH] CWE-787 CVE-2018-8377: A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memo A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka "Microsoft Edge Memory Corruption Vulnerability." This affects Microsoft Edge. This CVE ID is unique from CVE-2018-8387.
nvd
CVE-2019-0912P3HIGHCVSS 7.5vWindows 10 Version 1709 for 32-bit SystemsvWindows 10 Version 1709 for x64-based Systems+8 more2019-05-16
CVE-2019-0912 [HIGH] CWE-787 CVE-2019-0912: A remote code execution vulnerability exists in the way that the Chakra scripting engine handles obj A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0913, CVE-2019-0914, CVE-2019-0915, CVE-2019-0916, CVE-2019-0917, CVE-2019-0922, CVE-2019-0923, CVE-2019-0924, CVE-2019-09
nvd
CVE-2023-21775P3HIGHCVSS 8.3≥ 1.0.0, < 109.0.1518.492023-01-24
CVE-2023-21775 [HIGH] CVE-2023-21775: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
nvd
CVE-2019-0806P3HIGHCVSS 7.5vWindows 10 for 32-bit SystemsvWindows 10 for x64-based Systems+15 more2019-04-09
CVE-2019-0806 [HIGH] CWE-787 CVE-2019-0806: A remote code execution vulnerability exists in the way that the Chakra scripting engine handles obj A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-0810, CVE-2019-0812, CVE-2019-0829, CVE-2019-0860, CVE-2019-0861.
nvd
CVE-2019-1062P3HIGHCVSS 7.5vWindows 10 for 32-bit SystemsvWindows 10 for x64-based Systems+15 more2019-07-15
CVE-2019-1062 [HIGH] CWE-787 CVE-2019-1062: A remote code execution vulnerability exists in the way that the Chakra scripting engine handles obj A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka 'Chakra Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2019-1092, CVE-2019-1103, CVE-2019-1106, CVE-2019-1107.
nvd
CVE-2019-0926P3HIGHCVSS 7.5vWindows 10 Version 1809 for 32-bit SystemsvWindows 10 Version 1809 for x64-based Systems+2 more2019-05-16
CVE-2019-0926 [HIGH] CWE-787 CVE-2019-0926: A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memo A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka 'Microsoft Edge Memory Corruption Vulnerability'.
nvd
CVE-2019-0779P3HIGHCVSS 7.5vWindows Server 2016vWindows 10 Version 1607 for 32-bit Systems+6 more2019-04-09
CVE-2019-0779 [HIGH] CWE-787 CVE-2019-0779: A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memo A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka 'Microsoft Edge Memory Corruption Vulnerability'.
nvd
Microsoft Edge vulnerabilities | cvebase