Edge Chromium
by Microsoft
CVEs (324)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-36026 | Med | 0.28 | 4.3 | 0.01 | Nov 16, 2023 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | ||
| CVE-2023-38173 | Med | 0.28 | 4.3 | 0.01 | Jul 21, 2023 | Microsoft Edge for Android Spoofing Vulnerability | ||
| CVE-2021-42307 | Med | 0.28 | 4.3 | 0.01 | Jul 1, 2023 | Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | ||
| CVE-2023-29334 | Med | 0.28 | 4.3 | 0.01 | Apr 28, 2023 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | ||
| CVE-2023-21794 | Med | 0.28 | 4.3 | 0.01 | Feb 14, 2023 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | ||
| CVE-2022-44688 | Med | 0.28 | 4.3 | 0.01 | Dec 13, 2022 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | ||
| CVE-2022-26905 | Med | 0.28 | 4.3 | 0.02 | Jun 1, 2022 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | ||
| CVE-2022-24523 | Med | 0.28 | 4.3 | 0.01 | Apr 5, 2022 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | ||
| CVE-2024-29049 | Med | 0.27 | 4.1 | 0.01 | Apr 4, 2024 | Microsoft Edge (Chromium-based) Webview2 Spoofing Vulnerability | ||
| CVE-2023-36559 | Med | 0.27 | 4.2 | 0.01 | Oct 13, 2023 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | ||
| CVE-2022-21931 | Med | 0.27 | 4.2 | 0.01 | Jan 11, 2022 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | ||
| CVE-2022-21930 | Med | 0.27 | 4.2 | 0.01 | Jan 11, 2022 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | ||
| CVE-2021-43221 | Med | 0.27 | 4.2 | 0.01 | Nov 24, 2021 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | ||
| CVE-2020-16884 | Med | 0.27 | 4.2 | 0.02 | Sep 11, 2020 | A remote code execution vulnerability exists in the way that the IEToEdge Browser Helper Object (BHO) plugin on Internet Explorer handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of… | ||
| CVE-2019-1081 | Med | 0.27 | 4.2 | 0.02 | Jun 12, 2019 | An information disclosure vulnerability exists when affected Microsoft browsers improperly handle objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system. To exploit the vulnerability, in a… | ||
| CVE-2019-1002 | Med | 0.27 | 4.2 | 0.02 | Jun 12, 2019 | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current… | ||
| CVE-2024-21383 | Low | 0.21 | 3.3 | 0.00 | Jan 26, 2024 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | ||
| CVE-2019-1051 | Med | 0.21 | 4.2 | 0.04 | Jun 12, 2019 | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current… | ||
| CVE-2019-0992 | Med | 0.21 | 4.2 | 0.03 | Jun 12, 2019 | A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current… | ||
| CVE-2026-0102 | Low | 0.20 | 3.1 | 0.00 | Feb 17, 2026 | Under specific conditions, a malicious webpage may trigger autofill population after two consecutive taps, potentially without clear or intentional user consent. This could result in disclosure of stored autofill data such as addresses, email, or phone number metadata. |
- risk 0.28cvss 4.3epss 0.01
Microsoft Edge (Chromium-based) Spoofing Vulnerability
- risk 0.28cvss 4.3epss 0.01
Microsoft Edge for Android Spoofing Vulnerability
- risk 0.28cvss 4.3epss 0.01
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
- risk 0.28cvss 4.3epss 0.01
Microsoft Edge (Chromium-based) Spoofing Vulnerability
- risk 0.28cvss 4.3epss 0.01
Microsoft Edge (Chromium-based) Spoofing Vulnerability
- risk 0.28cvss 4.3epss 0.01
Microsoft Edge (Chromium-based) Spoofing Vulnerability
- risk 0.28cvss 4.3epss 0.02
Microsoft Edge (Chromium-based) Spoofing Vulnerability
- risk 0.28cvss 4.3epss 0.01
Microsoft Edge (Chromium-based) Spoofing Vulnerability
- risk 0.27cvss 4.1epss 0.01
Microsoft Edge (Chromium-based) Webview2 Spoofing Vulnerability
- risk 0.27cvss 4.2epss 0.01
Microsoft Edge (Chromium-based) Spoofing Vulnerability
- risk 0.27cvss 4.2epss 0.01
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
- risk 0.27cvss 4.2epss 0.01
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
- risk 0.27cvss 4.2epss 0.01
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
- risk 0.27cvss 4.2epss 0.02
A remote code execution vulnerability exists in the way that the IEToEdge Browser Helper Object (BHO) plugin on Internet Explorer handles objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of…
- risk 0.27cvss 4.2epss 0.02
An information disclosure vulnerability exists when affected Microsoft browsers improperly handle objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system. To exploit the vulnerability, in a…
- risk 0.27cvss 4.2epss 0.02
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current…
- risk 0.21cvss 3.3epss 0.00
Microsoft Edge (Chromium-based) Spoofing Vulnerability
- risk 0.21cvss 4.2epss 0.04
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current…
- risk 0.21cvss 4.2epss 0.03
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge (HTML-based). The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current…
- risk 0.20cvss 3.1epss 0.00
Under specific conditions, a malicious webpage may trigger autofill population after two consecutive taps, potentially without clear or intentional user consent. This could result in disclosure of stored autofill data such as addresses, email, or phone number metadata.
Page 13 of 17