Opera Browser
282 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Opera Browser, a product in the consumer software space. Use it to gauge the current risk picture and drill into individual advisories.
Opera Browser CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 282 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical44
- High23
- Medium202
- Low13
Latest CVEs
The 15 most recently published vulnerabilities affecting Opera Browser.
- CVE-2018-18913Opera before 57.0.3098.106 is vulnerable to a DLL Search Order hijacking attack where an attacker can send a ZIP archive composed of an HTML page along with a malicious DLL to the target. Once the ...7.8
- CVE-2018-6608In the WebRTC component in Opera 51.0.2830.55, after visiting a web site that attempts to gather complete client information (such as https://ip.voidsec.com), the browser can disclose a private IP ...4.3
- CVE-2016-4075Opera Mini 13 and Opera Stable 36 allow remote attackers to spoof the displayed URL via a crafted HTML document, related to the about:blank URL.6.1
- CVE-2016-6908Characters from languages are such as Arabic, Hebrew are displayed from RTL (Right To Left) order in Opera 37.0.2192.105088 for Android, due to mishandling of several unicode characters such as U+F...6.1
- CVE-2016-7153The HTTP/2 protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by lev...5.3
- CVE-2015-4000The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to...3.7
- CVE-2014-1870Opera before 19 on Mac OS X allows user-assisted remote attackers to spoof the address bar via vectors involving a drag-and-drop operation.4.3
- CVE-2014-0815The intent: URL implementation in Opera before 18 on Android allows attackers to read local files by leveraging an interaction error, as demonstrated by reading stored cookies.4.3
- CVE-2013-4705Cross-site scripting (XSS) vulnerability in Opera before 15.00 allows remote attackers to inject arbitrary web script or HTML by leveraging UTF-8 encoding.4.3
- CVE-2013-3210Opera before 12.15 does not properly block top-level domains in Set-Cookie headers, which allows remote attackers to obtain sensitive information by leveraging control of a different web site in th...5.0
- CVE-2013-3211Unspecified vulnerability in Opera before 12.15 has unknown impact and attack vectors, related to a "moderately severe issue."10.0
- CVE-2013-1618The TLS implementation in Opera before 12.13 does not properly consider timing side-channel attacks on a MAC check operation during the processing of malformed CBC padding, which allows remote atta...4.0
- CVE-2013-1637Opera before 12.13 allows remote attackers to execute arbitrary code via vectors involving DOM events.9.3
- CVE-2013-1639Opera before 12.13 does not send CORS preflight requests in all required cases, which allows remote attackers to bypass a CSRF protection mechanism via a crafted web site that triggers a CORS request.6.8
- CVE-2013-1638Opera before 12.13 allows remote attackers to execute arbitrary code via crafted clipPaths in an SVG document.9.3
Product grouping is registry-driven, with AI assist and human review. How it works