CVE Tools

Brave

7 CVEs tracked since 2017. Since May 2017, none of them reached CISA KEV.

Brave CVEs per month

May 2017 to Dec 2022. Point at a month, or focus the strip and use the arrow keys.
Brave CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2017-0520
2017-06null or fewer
2017-07null or fewer
2017-08null or fewer
2017-09null or fewer
2017-10null or fewer
2017-11null or fewer
2017-12null or fewer
2018-01null or fewer
2018-02null or fewer
2018-03null or fewer
2018-04null or fewer
2018-05null or fewer
2018-06null or fewer
2018-07null or fewer
2018-08null or fewer
2018-09null or fewer
2018-10null or fewer
2018-11null or fewer
2018-12null or fewer
2019-01null or fewer
2019-02null or fewer
2019-03null or fewer
2019-04null or fewer
2019-05null or fewer
2019-06null or fewer
2019-07null or fewer
2019-08null or fewer
2019-09null or fewer
2019-10null or fewer
2019-11null or fewer
2019-12null or fewer
2020-01null or fewer
2020-02null or fewer
2020-03null or fewer
2020-04null or fewer
2020-05null or fewer
2020-06null or fewer
2020-07null or fewer
2020-08null or fewer
2020-09null or fewer
2020-10null or fewer
2020-11null or fewer
2020-12null or fewer
2021-01null or fewer
2021-02null or fewer
2021-03null or fewer
2021-04null or fewer
2021-05null or fewer
2021-06null or fewer
2021-0720
2021-08null or fewer
2021-09null or fewer
2021-10null or fewer
2021-11null or fewer
2021-12null or fewer
2022-01null or fewer
2022-02null or fewer
2022-03null or fewer
2022-04null or fewer
2022-05null or fewer
2022-06null or fewer
2022-07null or fewer
2022-08null or fewer
2022-09null or fewer
2022-10null or fewer
2022-11null or fewer
2022-1230

Products

The products that kept showing up in Brave's monthly top three, with their CVEs summed over those months.

  1. Brave63 months
  2. Browser11 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Brave.

  1. CVE-2025-68508WordPress Brave plugin <= 0.8.3 - Broken Access Control vulnerability5.3
  2. CVE-2025-48980In Brave Browser Desktop versions prior to 1.83.10 that have the split view feature enabled, the "Open Link in Split View" context menu item did not respect the SameSite cookie attribute. Therefore...6.5
  3. CVE-2025-7710Brave Conversion Engine (PRO) <= 0.7.7 - Authentication Bypass to Administrator9.8
  4. CVE-2025-23086On most desktop platforms, Brave Browser versions 1.70.x-1.73.x included a feature to show a site's origin on the OS-provided file selector dialog when a site prompts the user to upload or download...6.1
  5. CVE-2024-37406In Brave Android prior to v1.67.116, domains in the Brave Shields popup are elided from the right instead of the left, which may lead to domain confusion.7.5
  6. CVE-2024-43337WordPress Brave plugin <= 0.7.0 - Cross Site Request Forgery (CSRF) vulnerability4.3
  7. CVE-2024-35655WordPress Brave – Interactive Content plugin <= 0.6.9 - Cross Site Scripting (XSS) vulnerability5.9
  8. CVE-2024-30453WordPress Brave plugin <= 0.6.5 - Server Side Request Forgery (SSRF) vulnerability5.4
  9. CVE-2023-51534WordPress Brave Popup Builder Plugin <= 0.6.2 is vulnerable to Cross Site Scripting (XSS)5.9
  10. CVE-2023-52263Brave Browser before 1.59.40 does not properly restrict the schema for WebUI factory and redirect. This is related to browser/brave_content_browser_client.cc and browser/ui/webui/brave_web_ui_contr...6.1
  11. CVE-2023-28364An Open Redirect vulnerability exists prior to version 1.52.117, where the built-in QR scanner in Brave Browser Android navigated to scanned URLs automatically without showing the URL first. Now th...6.1
  12. CVE-2023-28360An omission of security-relevant information vulnerability exists in Brave desktop prior to version 1.48.171 when a user was saving a file there was no download safety check dialog presented to the...4.3
  13. CVE-2023-22798Prior to commit 51867e0d15a6d7f80d5b714fd0e9976b9c160bb0, https://github.com/brave/adblock-lists removed redirect interceptors on some websites like Facebook in which the redirect interceptor may h...6.1
  14. CVE-2022-47934Brave Browser before 1.43.88 allowed a remote attacker to cause a denial of service in private and guest windows via a crafted HTML file that mentions an ipfs:// or ipns:// URL. This is caused by a...6.5
  15. CVE-2022-47933Brave Browser before 1.42.51 allowed a remote attacker to cause a denial of service via a crafted HTML file that references the IPFS scheme. This vulnerability is caused by an uncaught exception in...6.5

The record

Peak rank
#128 in May 2017
Busiest month shown
Dec 2022, 3 CVEs
Months with a KEV entry
0 since May 2017
Monthly snapshots
3 since 2017
Brave's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store