Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2614▼ 473 respecto a la semana anterior
Críticas / altas1270▼ 74 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)243▼ 274 respecto a la semana anterior
15 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 2.6% | — | Securifi Almond 2015 FirmwareSecurifi Almond+firmwareSecurifi Almond Firmware | 18/6/2019 | 17/6/2026 | An issue was discovered on Securifi Almond, Almond+, and Almond 2015 devices with firmware AL-R096. The device provides a user with the capability of executing various actions on the web management interface. It seems that the device does not implement any Origin header check which allows an attacker who can trick a… | |
| Modificada | Alta (8) | 0.93% | — | Securifi Almond 2015 FirmwareSecurifi Almond+firmwareSecurifi Almond Firmware | 18/6/2019 | 17/6/2026 | An issue was discovered on Securifi Almond, Almond+, and Almond 2015 devices with firmware AL-R096. The device provides a user with the capability of blocking IP addresses using the web management interface. It seems that the device does not implement any cross-site scripting forgery protection mechanism which allows… | |
| Modificada | Alta (8.8) | 2.9% | — | Securifi Almond 2015 FirmwareSecurifi Almond+firmwareSecurifi Almond Firmware | 18/6/2019 | 17/6/2026 | An issue was discovered on Securifi Almond, Almond+, and Almond 2015 devices with firmware AL-R096. The device provides a user with the capability of blocking key words passing in the web traffic to prevent kids from watching content that might be deemed unsafe using the web management interface. It seems that the… | |
| Modificada | Media (6.5) | 1.5% | — | Securifi Almond 2015 FirmwareSecurifi Almond+firmwareSecurifi Almond Firmware | 18/6/2019 | 17/6/2026 | An issue was discovered on Securifi Almond, Almond+, and Almond 2015 devices with firmware AL-R096. The device provides a UPnP functionality for devices to interface with the router and interact with the device. It seems that the "NewInMessage" SOAP parameter passed with a huge payload results in crashing the process.… | |
| Modificada | Alta (8.8) | 1.4% | — | Securifi Almond 2015 FirmwareSecurifi Almond+firmwareSecurifi Almond Firmware | 18/6/2019 | 17/6/2026 | An issue was discovered on Securifi Almond, Almond+, and Almond 2015 devices with firmware AL-R096. The device provides a user with the capability of changing the administrative password for the web management interface. It seems that the device does not implement any cross site request forgery protection mechanism… | |
| Modificada | Alta (8.8) | 7.1% | — | Securifi Almond 2015 FirmwareSecurifi Almond+firmwareSecurifi Almond Firmware | 18/6/2019 | 17/6/2026 | An issue was discovered on Securifi Almond, Almond+, and Almond 2015 devices with firmware AL-R096. The device provides a user with the capability of adding new routes to the device. It seems that the POST parameters passed in this request to set up routes on the device can be set in such a way that would result in… | |
| Modificada | Alta (8.8) | 7.0% | — | Securifi Almond 2015 FirmwareSecurifi Almond+firmwareSecurifi Almond Firmware | 18/6/2019 | 17/6/2026 | An issue was discovered on Securifi Almond, Almond+, and Almond 2015 devices with firmware AL-R096. The device provides a user with the capability of adding new port forwarding rules to the device. It seems that the POST parameters passed in this request to set up routes on the device can be set in such a way that… | |
| Modificada | Media (6.4) | 2.0% | — | Securifi Almond 2015 FirmwareSecurifi Almond+firmwareSecurifi Almond Firmware | 18/6/2019 | 17/6/2026 | An issue was discovered on Securifi Almond, Almond+, and Almond 2015 devices with firmware AL-R096. The device provides a user with the capability of setting a name for the wireless network. These values are stored by the device in NVRAM (Non-volatile RAM). It seems that the POST parameters passed in this request to… | |
| Modificada | Alta (8.8) | 2.7% | — | Securifi Almond 2015 FirmwareSecurifi Almond+firmwareSecurifi Almond Firmware | 18/6/2019 | 17/6/2026 | An issue was discovered on Securifi Almond, Almond+, and Almond 2015 devices with firmware AL-R096. The device provides a user with the capability of adding new routes to the device. It seems that the POST parameters passed in this request to set up routes on the device can be set in such a way that would result in… | |
| Modificada | Alta (8) | 2.1% | — | Securifi Almond 2015 FirmwareSecurifi Almond+firmwareSecurifi Almond Firmware | 18/6/2019 | 17/6/2026 | An issue was discovered on Securifi Almond, Almond+, and Almond 2015 devices with firmware AL-R096. The device provides a user with the capability of setting name for wireless network. These values are stored by the device in NVRAM (Non-volatile RAM). It seems that the POST parameters passed in this request to set up… | |
| Modificada | Media (4.3) | 1.2% | — | Securifi Almond FirmwareSecurifi Almond-2015 Firmware | 21/9/2015 | 17/6/2026 | Securifi Almond devices with firmware before AL1-R201EXP10-L304-W34 and Almond-2015 devices with firmware before AL2-R088M use a linear algorithm for selecting the ID value in the header of a DNS query performed on behalf of the device itself, which makes it easier for remote attackers to spoof responses by including… | |
| Modificada | Media (4.3) | 0.90% | — | Securifi Almond FirmwareSecurifi Almond-2015 Firmware | 21/9/2015 | 17/6/2026 | Securifi Almond devices with firmware before AL1-R201EXP10-L304-W34 and Almond-2015 devices with firmware before AL2-R088M unintentionally omit the X-Frame-Options HTTP header, which makes it easier for remote attackers to conduct clickjacking attacks via a crafted web site that contains a (1) FRAME, (2) IFRAME, or… | |
| Modificada | Media (6.8) | 0.66% | — | Securifi Almond-2015 FirmwareSecurifi Almond Firmware | 21/9/2015 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability on Securifi Almond devices with firmware before AL1-R201EXP10-L304-W34 and Almond-2015 devices with firmware before AL2-R088M allows remote attackers to hijack the authentication of arbitrary users. | |
| Modificada | Alta (7.3) | 0.86% | — | Securifi Almond FirmwareSecurifi Almond-2015 Firmware | 21/9/2015 | 17/6/2026 | Securifi Almond devices with firmware before AL1-R201EXP10-L304-W34 and Almond-2015 devices with firmware before AL2-R088M have a default password of admin for the admin account, which allows remote attackers to obtain web-management access by leveraging the ability to authenticate from the intranet. | |
| Modificada | Media (5) | 1.5% | — | Securifi Almond FirmwareSecurifi Almond-2015 Firmware | 21/9/2015 | 17/6/2026 | Securifi Almond devices with firmware before AL1-R201EXP10-L304-W34 and Almond-2015 devices with firmware before AL2-R088M use a fixed source-port number in outbound DNS queries performed on behalf of any device, which makes it easier for remote attackers to spoof responses by using this number for the destination… |