cbcvebase.

Microsoft Edge vulnerabilities

349 known vulnerabilities affecting microsoft/microsoft_edge.

Total CVEs
349
CISA KEV
2
actively exploited
Public exploits
8
Exploited in wild
2
Severity breakdown
CRITICAL9HIGH168MEDIUM164LOW8

Vulnerabilities

Page 9 of 18
CVE-2022-29144P3HIGHCVSS 7.5≥ 1.0.0, < 100.0.1185.442023-06-29
CVE-2022-29144 [HIGH] CVE-2022-29144: Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
nvd
CVE-2023-36014P3HIGHCVSS 7.3≥ 1.0.0, < 119.0.2151.582023-11-10
CVE-2023-36014 [HIGH] CWE-94 CVE-2023-36014: Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
nvd
CVE-2019-0990P3MEDIUMCVSS 6.5≥ 1.0..0, < publication2019-06-12
CVE-2019-0990 [MEDIUM] CWE-200 CVE-2019-0990: A remote code execution vulnerability exists in the way that the Chakra scripting engine handles obj A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the
nvd
CVE-2021-1705P3HIGHCVSS 7.5≥ 1.0..0, < publication2021-01-12
CVE-2021-1705 [HIGH] CVE-2021-1705: Microsoft Edge (HTML-based) Memory Corruption Vulnerability Microsoft Edge (HTML-based) Memory Corruption Vulnerability
nvd
CVE-2023-33143P3HIGHCVSS 7.5≥ 1.0.0, < 114.0.1823.372023-06-03
CVE-2023-33143 [HIGH] CVE-2023-33143: Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
nvd
CVE-2026-57990P3HIGHCVSS 7.4v-2026-07-26
CVE-2026-57990 [HIGH] CWE-552 CVE-2026-57990: Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an una Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2024-26192P3HIGHCVSS 8.2≥ 1.0.0, < 122.0.2365.522024-02-23
CVE-2024-26192 [HIGH] CWE-359 CVE-2024-26192: Microsoft Edge (Chromium-based) Information Disclosure Vulnerability Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
nvd
CVE-2021-36931P3HIGHCVSS 7.8≥ 1.0.0, < 92.0.902.552021-08-26
CVE-2021-36931 [HIGH] CWE-269 CVE-2021-36931: Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
nvd
CVE-2020-17131P3HIGHCVSS 7.5≥ 1.0..0, < publication2020-12-10
CVE-2020-17131 [HIGH] CWE-787 CVE-2020-17131: Chakra Scripting Engine Memory Corruption Vulnerability Chakra Scripting Engine Memory Corruption Vulnerability
nvd
CVE-2020-17054P3HIGHCVSS 7.5≥ 1.0..0, < publication2020-11-11
CVE-2020-17054 [HIGH] CWE-787 CVE-2020-17054: Chakra Scripting Engine Memory Corruption Vulnerability Chakra Scripting Engine Memory Corruption Vulnerability
nvd
CVE-2026-56646P3MEDIUMCVSS 6.5≥ 1.0.0.0, < 150.0.4078.482026-07-03
CVE-2026-56646 [MEDIUM] CWE-200 CVE-2026-56646: Exposure of sensitive information to an unauthorized actor in Microsoft Edge (Chromium-based) allows Exposure of sensitive information to an unauthorized actor in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
nvd
CVE-2026-57987P3MEDIUMCVSS 6.5≥ 1.0.0.0, < 150.0.4078.482026-07-03
CVE-2026-57987 [MEDIUM] CWE-918 CVE-2026-57987: Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacke Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
nvd
CVE-2022-23263P3HIGHCVSS 7.7≥ 1.0.0, < 98.0.1108.432022-02-07
CVE-2022-23263 [HIGH] CVE-2022-23263: Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
nvd
CVE-2021-42308P3HIGHCVSS 7.5≥ 1.0.0, < 96.0 1954.292021-11-24
CVE-2021-42308 [HIGH] CWE-290 CVE-2021-42308: Microsoft Edge (Chromium-based) Spoofing Vulnerability Microsoft Edge (Chromium-based) Spoofing Vulnerability
nvd
CVE-2026-57989P3HIGHCVSS 7.4≥ 1.0.0.0, < 150.0.4078.992026-07-26
CVE-2026-57989 [HIGH] CWE-346 CVE-2026-57989: Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclo Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2026-58297P3HIGHCVSS 7.1≥ 1.0.0.0, < 150.0.4078.482026-07-03
CVE-2026-58297 [HIGH] CWE-359 CVE-2026-58297: Exposure of private personal information to an unauthorized actor in Microsoft Edge for Android allo Exposure of private personal information to an unauthorized actor in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2026-58296P3HIGHCVSS 7.1≥ 1.0.0.0, < 150.0.4078.482026-07-03
CVE-2026-58296 [HIGH] CWE-359 CVE-2026-58296: Exposure of private personal information to an unauthorized actor in Microsoft Edge for Android allo Exposure of private personal information to an unauthorized actor in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network.
nvd
CVE-2026-58283P3MEDIUMCVSS 6.9≥ 1.0.0.0, < 150.0.4078.482026-07-03
CVE-2026-58283 [MEDIUM] CWE-843 CVE-2026-58283: Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) all Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
nvd
CVE-2026-58286P3MEDIUMCVSS 6.9≥ 1.0.0.0, < 150.0.4078.482026-07-03
CVE-2026-58286 [MEDIUM] CWE-284 CVE-2026-58286: Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perfor Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
nvd
CVE-2026-58282P3MEDIUMCVSS 6.9≥ 1.0.0.0, < 150.0.4078.482026-07-03
CVE-2026-58282 [MEDIUM] CWE-284 CVE-2026-58282: Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perfor Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.
nvd
Microsoft Edge vulnerabilities | cvebase