Vulnerability index

Browse CVEs

19 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Browser MEDIUM 6.1
CVE-2023-52263

Brave Browser before 1.59.40 does not properly restrict the schema for WebUI factory and redirect. This is related to browser/brave_content_browser_c…

Fix: 1.59.40+
Fix from $1,600 2023-12-30
Browser MEDIUM 6.1
CVE-2023-28364

An Open Redirect vulnerability exists prior to version 1.52.117, where the built-in QR scanner in Brave Browser Android navigated to scanned URLs aut…

Fix: 1.52.117+
Fix from $1,600 2023-07-01
Adblock Lists MEDIUM 6.1
CVE-2023-22798

Prior to commit 51867e0d15a6d7f80d5b714fd0e9976b9c160bb0, https://github.com/brave/adblock-lists removed redirect interceptors on some websites like …

Fix: 2022-05-25+
Fix from $1,600 2023-02-09
Brave MEDIUM 6.5
CVE-2022-47932

Brave Browser before 1.43.34 allowed a remote attacker to cause a denial of service via a crafted HTML file that mentions an ipfs:// or ipns:// URL. …

Fix: 1.42.51+
Fix from $1,600 2022-12-24
Brave MEDIUM 6.5
CVE-2022-47933

Brave Browser before 1.42.51 allowed a remote attacker to cause a denial of service via a crafted HTML file that references the IPFS scheme. This vul…

Fix: 1.42.51+
Fix from $1,600 2022-12-24
Brave MEDIUM 6.5
CVE-2022-47934

Brave Browser before 1.43.88 allowed a remote attacker to cause a denial of service in private and guest windows via a crafted HTML file that mention…

Fix: 1.43.88+
Fix from $1,600 2022-12-24
Brave MEDIUM 5.3
CVE-2022-30334

Brave before 1.34, when a Private Window with Tor Connectivity is used, leaks .onion URLs in Referer and Origin headers. NOTE: although this was fixe…

Fix: 1.34+
Fix from $1,600 2022-05-07
Brave HIGH 7.5
CVE-2021-45884

In Brave Desktop 1.17 through 1.33 before 1.33.106, when CNAME-based adblocking and a proxying extension with a SOCKS fallback are enabled, additiona…

Fix: after 1.33.106
Fix from $1,950 2021-12-27
Brave MEDIUM 6.1
CVE-2021-22929

An information disclosure exists in Brave Browser Desktop prior to version 1.28.62, where logged warning messages that included timestamps of connect…

Fix: 1.28.62+
Fix from $1,600 2021-08-31
Browser MEDIUM 6.5
CVE-2021-22917

Brave Browser Desktop between versions 1.17 and 1.20 is vulnerable to information disclosure by way of DNS requests in Tor windows not flowing throug…

Fix: 1.20+
Fix from $1,600 2021-07-12
Brave MEDIUM 5.9
CVE-2021-22916

In Brave Desktop between versions 1.17 and 1.26.60, when adblocking is enabled and a proxy browser extension is installed, the CNAME adblocking featu…

Fix: after 1.26.60
Fix from $1,600 2021-07-12
Brave MEDIUM 5.3
CVE-2021-21323

Brave is an open source web browser with a focus on privacy and security. In Brave versions 1.17.73-1.20.103, the CNAME adblocking feature added in B…

Fix: after 1.20.103
Fix from $1,600 2021-02-23
Brave MEDIUM 5.5
CVE-2020-8276

The implementation of Brave Desktop's privacy-preserving analytics system (P3A) between 1.1 and 1.18.35 logged the timestamp of when the user last op…

Fix: after 1.18.35
Fix from $1,600 2020-11-09
Brave MEDIUM 6.5
CVE-2018-10798

A hang issue was discovered in Brave before 0.14.0 (on, for example, Linux). The vulnerability is caused by mishandling of JavaScript code that trigg…

Fix: 0.14.0+
Fix from $1,600 2018-05-08
Brave MEDIUM 6.5
CVE-2018-10799

A hang issue was discovered in Brave before 0.14.0 (on, for example, Linux). This vulnerability is caused by the mishandling of a long URL formed by …

Fix: 0.14.0+
Fix from $1,600 2018-05-08
Brave Browser HIGH 7.5
CVE-2016-10718EPSS 12%

Brave Browser before 0.13.0 allows a tab to close itself even if the tab was not opened by a script, resulting in denial of service.

Fix: 0.13.0+
Fix from $1,950 2018-04-04
Brave Browser MEDIUM 6.5
CVE-2017-18256

Brave Browser before 0.13.0 allows remote attackers to cause a denial of service (resource consumption) via a long alert() argument in JavaScript cod…

Fix: 0.13.0+
Fix from $1,600 2018-04-04
Brave MEDIUM 6.5
CVE-2017-8458

Brave 0.12.4 has a URI Obfuscation issue in which a string such as https://[email protected]/ is displayed without a clear UI indic…

Patch available
Fix from $1,600 2017-05-03
Brave MEDIUM 5.3
CVE-2017-8459

Brave 0.12.4 has a Status Bar Obfuscation issue in which a redirection target is shown in a possibly unexpected way. NOTE: third parties dispute this…

No fix yet
Fix from $1,600 2017-05-03