Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

736 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaBaja (2.6)1.8%—Opera Browser14/6/201216/6/2026
Opera before 11.65 does not ensure that the address field corresponds to the displayed web page during unusually timed changes to this field, which makes it easier for user-assisted remote attackers to conduct spoofing attacks via vectors involving navigation, reloads, and redirects.
ModificadaMedia (5)1.7%—Opera Browser14/6/201216/6/2026
Opera before 11.65 does not properly restrict the reading of JSON strings, which allows remote attackers to perform cross-domain loading of JSON resources and consequently obtain sensitive information via a crafted web site.
ModificadaAlta (9.3)3.7%—Opera Browser14/6/201216/6/2026
Opera before 11.65 does not properly restrict the opening of a pop-up window in response to the first click of a double-click action, which makes it easier for user-assisted remote attackers to conduct cross-site scripting (XSS) attacks or execute arbitrary code via a crafted web site.
ModificadaAlta (7.6)3.8%—Opera Browser14/6/201216/6/2026
Opera before 11.65 does not ensure that keyboard sequences are associated with a visible window, which makes it easier for user-assisted remote attackers to conduct cross-site scripting (XSS) attacks or execute arbitrary code via a crafted web site, related to a "hidden keyboard navigation" issue.
ModificadaMedia (5.8)0.61%—Opera Browser4/6/201216/6/2026
Opera before 9.63 does not properly verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (4.6)0.38%—Opera Browser28/3/201216/6/2026
Opera before 11.62 on UNIX, when used in conjunction with an unspecified printing application, allows local users to overwrite arbitrary files via a symlink attack on a temporary file during printing.
ModificadaMedia (4.6)0.38%—Opera Browser28/3/201216/6/2026
Opera before 11.62 on UNIX uses world-readable permissions for temporary files during printing, which allows local users to obtain sensitive information by reading these files.
ModificadaMedia (6.4)1.7%—Opera Browser28/3/201216/6/2026
Opera before 11.62 on Mac OS X allows remote attackers to spoof the address field and security dialogs via crafted styling that causes page content to be displayed outside of the intended content area.
ModificadaMedia (6.4)2.7%—Opera Browser28/3/201216/6/2026
Opera before 11.62 allows remote attackers to spoof the address field by triggering a page reload followed by a redirect to a different domain.
ModificadaMedia (6.4)2.7%—Opera Browser28/3/201216/6/2026
Opera before 11.62 allows remote attackers to spoof the address field by triggering the launch of a dialog window associated with a different domain.
ModificadaMedia (5)2.5%—Opera Browser28/3/201216/6/2026
Opera before 11.62 allows remote attackers to bypass the Same Origin Policy via the (1) history.pushState and (2) history.replaceState functions in conjunction with cross-domain frames, leading to unintended read access to history.state information.
ModificadaMedia (6.8)2.3%—Opera Browser28/3/201216/6/2026
Opera before 11.62 does not ensure that a dialog window is placed on top of content windows, which makes it easier for user-assisted remote attackers to trick users into downloading and executing arbitrary files via a download dialog located under other windows.
ModificadaMedia (6.8)2.3%—Opera Browser28/3/201216/6/2026
Opera before 11.62 allows user-assisted remote attackers to trick users into downloading and executing arbitrary files via a small window for the download dialog.
ModificadaAlta (10)2.2%—Netfrontlife Netfront Life Browser15/3/201216/6/2026
Unspecified vulnerability in the NetFront Life Browser (com.access_company.android.nflifebrowser.lite) application 2.2.0 and 2.3.0 for Android has unknown impact and attack vectors.
ModificadaAlta (10)1.4%—Dolphin-browser Dolphin Browser Mini7/3/201216/6/2026
Unspecified vulnerability in the Dolphin Browser Mini (com.dolphin.browser) application 2.2 for Android has unknown impact and attack vectors.
ModificadaAlta (10)1.4%—Dolphin-browser Dolphin Browser CN7/3/201216/6/2026
Unspecified vulnerability in the Dolphin Browser CN (com.dolphin.browser.cn) application 6.3.1 and 7.2.1 for Android has unknown impact and attack vectors.
ModificadaAlta (10)1.4%—Dolphin-browser Dolphin Browser HD7/3/201216/6/2026
Unspecified vulnerability in the Dolphin Browser HD (mobi.mgeek.TunnyBrowser) application 6.2.0, 7.2.1, 7.3.0, and 7.4.0 for Android has unknown impact and attack vectors.
ModificadaMedia (5)1.1%—Opera Browser7/2/201216/6/2026
Multiple integer overflows in Opera 11.60 and earlier allow remote attackers to cause a denial of service (application crash) via a large integer argument to the (1) Int32Array, (2) Float32Array, (3) Float64Array, (4) Uint32Array, (5) Int16Array, or (6) ArrayBuffer function. NOTE: the vendor reportedly characterizes…
ModificadaMedia (6.8)2.6%—Luratech Lurawave JP2 Browser Plug-in2/2/201216/6/2026
Stack-based buffer overflow in npjp2.dll in LuraWave JP2 Browser Plug-In 1.1.1.11 and other versions before 2.1.1.11 allows remote attackers to execute arbitrary code via a JPEG2000 (JP2) file with a crafted Quantization Default (QCD) marker segment.
ModificadaMedia (4)2.6%💥 ExploitDavid Azoulay WEB File Browser15/12/201116/6/2026
Directory traversal vulnerability in webFileBrowser.php in Web File Browser 0.4b14 allows remote authenticated users to read arbitrary files via a ..%2f (encoded dot dot) in the file parameter in a download action.
ModificadaMedia (5)1.1%—Opera Browser7/12/201116/6/2026
Opera 11.60 and earlier does not prevent capture of data about the times of Same Origin Policy violations during IFRAME loading attempts, which makes it easier for remote attackers to determine whether a document exists in the browser cache via crafted JavaScript code.
ModificadaMedia (5)2.3%—Opera Browser7/12/201116/6/2026
Opera before 11.60 allows remote attackers to cause a denial of service (CPU and memory consumption) via unspecified content on a web page, as demonstrated by a page under the cisco.com home page.
ModificadaMedia (5)2.2%—Opera Browser7/12/201116/6/2026
Unspecified vulnerability in the Web Workers implementation in Opera before 11.60 allows remote attackers to cause a denial of service (application crash) via unknown vectors.
ModificadaMedia (5)2.2%—Opera Browser7/12/201116/6/2026
Dragonfly in Opera before 11.60 allows remote attackers to cause a denial of service (application crash) via unspecified content on a web page, as demonstrated by forbes.com.
ModificadaAlta (10)5.7%💥 ExploitOpera Browser7/12/201116/6/2026
Opera before 11.60 does not properly handle certificate revocation, which has unspecified impact and remote attack vectors related to "corner cases."
Orbitaley — Vulnerabilidades