VendorsMicrosoftedge_chromiumall versions
Vulnerabilities

Microsoft Edge

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

305CVEs
CVE-2026-57983
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
Published 2026-07-03 · Analyzed
10.0EPSS 0.006
CVE-2024-43566
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Published 2024-10-17 · Analyzed
9.8EPSS 0.011
CVE-2026-45495
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Published 2026-05-18 · Modified
9.8EPSS 0.010
CVE-2022-4135
Heap buffer overflow in GPU in Google Chrome prior to 107.0.5304.121 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Published 2022-11-25 · Analyzed
9.6KEVEPSS 0.319
CVE-2021-21132
Inappropriate implementation in DevTools in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially perform a sandbox escape via a crafted Chrome Extension.
Published 2021-02-09 · Modified
9.6EPSS 0.234
CVE-2023-6345
Integer overflow in Skia in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)
Published 2023-11-29 · Analyzed
9.6KEVEPSS 0.165
CVE-2021-21124
Potential user after free in Speech Recognizer in Google Chrome on Android prior to 88.0.4324.96 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
Published 2021-02-09 · Modified
9.6EPSS 0.079
CVE-2021-21121
Use after free in Omnibox in Google Chrome on Linux prior to 88.0.4324.96 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
Published 2021-02-09 · Modified
9.6EPSS 0.062
CVE-2023-35618
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
Published 2023-12-07 · Modified
9.6EPSS 0.029
CVE-2022-33649
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
Published 2022-08-09 · Modified
9.6EPSS 0.023
CVE-2023-36735
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
Published 2023-09-15 · Modified
9.6EPSS 0.021
CVE-2024-21326
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
Published 2024-01-26 · Modified
9.6EPSS 0.012
CVE-2026-66321
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Published 2026-08-03 · Analyzed
9.6EPSS 0.005
CVE-2026-58289
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Published 2026-07-03 · Analyzed
9.01 PoCEPSS 0.020
CVE-2024-38219
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
Published 2024-08-08 · Analyzed
9.0EPSS 0.009
CVE-2023-4863
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)
Published 2023-09-12 · Analyzed
8.8KEVEPSS 1.000
CVE-2023-5217
Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Published 2023-09-28 · Analyzed
8.8KEVEPSS 0.490
CVE-2020-16009
Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Published 2020-11-03 · Analyzed
8.8KEVEPSS 0.483
CVE-2023-6702
Type confusion in V8 in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Published 2023-12-14 · Modified
8.8EPSS 0.438
CVE-2023-4762
Type Confusion in V8 in Google Chrome prior to 116.0.5845.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
Published 2023-09-05 · Analyzed
8.8KEVEPSS 0.411
CVE-2025-14174
Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
Published 2025-12-12 · Analyzed
8.8KEVEPSS 0.223
CVE-2024-7965
Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Published 2024-08-21 · Analyzed
8.8KEVEPSS 0.185
CVE-2021-21118
Insufficient data validation in V8 in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
Published 2021-02-09 · Modified
8.8EPSS 0.168
CVE-2021-21157
Use after free in Web Sockets in Google Chrome on Linux prior to 88.0.4324.182 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Published 2021-02-22 · Modified
8.8EPSS 0.095
CVE-2025-5419
Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Published 2025-06-02 · Analyzed
8.8KEVEPSS 0.078
CVE-2021-21122
Use after free in Blink in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Published 2021-02-09 · Modified
8.8EPSS 0.070
CVE-2021-21120
Use after free in WebSQL in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Published 2021-02-09 · Modified
8.8EPSS 0.069
CVE-2021-21119
Use after free in Media in Google Chrome prior to 88.0.4324.96 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
Published 2021-02-09 · Modified
8.8EPSS 0.068
CVE-2021-21128
Heap buffer overflow in Blink in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Published 2021-02-09 · Modified
8.8EPSS 0.065
CVE-2021-21127
Insufficient policy enforcement in extensions in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass content security policy via a crafted Chrome Extension.
Published 2021-02-09 · Modified
8.8EPSS 0.059
CVE-2021-30614
Chromium: CVE-2021-30614 Heap buffer overflow in TabStrip
Published 2021-09-03 · Modified
8.8EPSS 0.045
CVE-2021-30616
Chromium: CVE-2021-30616 Use after free in Media
Published 2021-09-03 · Modified
8.8EPSS 0.041
CVE-2021-30609
Chromium: CVE-2021-30609 Use after free in Sign-In
Published 2021-09-03 · Modified
8.8EPSS 0.041
CVE-2021-30610
Chromium: CVE-2021-30610 Use after free in Extensions API
Published 2021-09-03 · Modified
8.8EPSS 0.041
CVE-2021-30613
Chromium: CVE-2021-30613 Use after free in Base internals
Published 2021-09-03 · Modified
8.8EPSS 0.041
CVE-2021-30618
Chromium: CVE-2021-30618 Inappropriate implementation in DevTools
Published 2021-09-03 · Modified
8.8EPSS 0.041
CVE-2021-30620
Chromium: CVE-2021-30620 Insufficient policy enforcement in Blink
Published 2021-09-03 · Modified
8.8EPSS 0.041
CVE-2021-30624
Chromium: CVE-2021-30624 Use after free in Autofill
Published 2021-09-03 · Modified
8.8EPSS 0.041
CVE-2021-30606
Chromium: CVE-2021-30606 Use after free in Blink
Published 2021-09-03 · Modified
8.8EPSS 0.041
CVE-2021-30607
Chromium: CVE-2021-30607 Use after free in Permissions
Published 2021-09-03 · Modified
8.8EPSS 0.041
1 / 8Next →