Netgate kayıtları
netgate üreticisine ait 59 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 3 · %5,1
- Pre-auth RCE
- 6
- Düzeltme kaydı olan
- %5,1
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')27
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')7
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')4
- CWE-352 Cross-Site Request Forgery (CSRF)3
- CWE-428 Unquoted Search Path or Element2
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
59 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
67Bu hafta | CVE-2022-31814Silahlaştırılmış | pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metacharacters in the HTTP Hnetgate · pfblockerng · CWE-78 | Kritik9,8 | — | %91,9 | 5 Eyl 2022 |
62Bu hafta | CVE-2023-27253Silahlaştırılmış | A command injection vulnerability in the function restore_rrddata() of Netgate pfSense v2.7.0 allows authenticated attackers to execute arbinetgate · pfsense · CWE-91 | Yüksek8,8 | — | %89,5 | 17 Mar 2023 |
55Planlayın | CVE-2023-48123Kavram kanıtı | An issue in Netgate pfSense Plus v.23.05.1 and before and pfSense CE v.2.7.0 allows a remote attacker to execute arbitrary code via a craftenetgate · pfsense | Yüksek8,8 | — | %67,8 | 6 Ara 2023 |
54Planlayın | CVE-2023-42326Kavram kanıtı | An issue in Netgate pfSense v.2.7.0 allows a remote attacker to execute arbitrary code via a crafted request to the interfaces_gif_edit.php netgate · pfsense · CWE-77 | Yüksek8,8 | — | %64,0 | 14 Kas 2023 |
51Planlayın | CVE-2023-48795Kavram kanıtı | The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypasssh · ssh · CWE-354 | Orta5,9 | — | %93,5 | 18 Ara 2023 |
51Planlayın | CVE-2019-16667Kavram kanıtı | diag_command.php in pfSense 2.4.4-p3 allows CSRF via the txtCommand or txtRecallBuffer field, as demonstrated by executing OS commands.netgate · pfsense · CWE-352 | Yüksek8,8 | — | %54,5 | 26 Eyl 2019 |
50Planlayın | CVE-2018-4021İstismar yok | An exploitable command injection vulnerability exists in the way Netgate pfSense CE 2.4.4-RELEASE processes the parameters of a specific POSnetgate · pfsense · CWE-78 | Yüksek7,2 | — | %72,2 | 3 Ara 2018 |
47Planlayın | CVE-2015-2295Kavram kanıtı | Cross-site request forgery (CSRF) vulnerability in system_firmware_restorefullbackup.php in the WebGUI in pfSense before 2.2.1 allows remotenetgate · pfsense · CWE-352 | Orta6,8 | — | %65,7 | 10 Nis 2015 |
45Planlayın | CVE-2017-1000479Silahlaştırılmış | pfSense versions 2.4.1 and lower are vulnerable to clickjacking attacks in the CSRF error page resulting in privileged execution of arbitrarnetgate · pfsense · CWE-352 | Yüksek8,8 | — | %31,7 | 3 Oca 2018 |
43Planlayın | CVE-2024-46538Kavram kanıtı | A cross-site scripting (XSS) vulnerability in pfsense v2.5.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payloadnetgate · pfsense · CWE-79 | Orta4,8 | — | %81,6 | 22 Eki 2024 |
43Planlayın | CVE-2018-4019İstismar yok | An exploitable command injection vulnerability exists in the way Netgate pfSense CE 2.4.4-RELEASE processes the parameters of a specific POSnetgate · pfsense · CWE-78 | Yüksek7,2 | — | %48,7 | 3 Ara 2018 |
43Planlayın | CVE-2018-4020İstismar yok | An exploitable command injection vulnerability exists in the way Netgate pfSense CE 2.4.4-RELEASE processes the parameters of a specific POSnetgate · pfsense · CWE-78 | Yüksek7,2 | — | %48,7 | 3 Ara 2018 |
42Planlayın | CVE-2022-29273İstismar yok | pfSense CE through 2.6.0 and pfSense Plus before 22.05 allow XSS in the WebGUI via URL Table Alias URL parameters.netgate · pfsense · CWE-79 | Orta6,1 | — | %59,6 | 22 Şub 2023 |
42Planlayın | CVE-2019-12347Kavram kanıtı | In pfSense 2.4.4-p3, a stored XSS vulnerability occurs when attackers inject a payload into the Name or Description field via an acme_accounnetgate · pfsense · CWE-79 | Orta6,1 | — | %58,6 | 29 May 2019 |
42Planlayın | CVE-2023-27100Kavram kanıtı | Improper restriction of excessive authentication attempts in the SSHGuard component of Netgate pfSense Plus software v22.05.1 and pfSense CEnetgate · pfsense plus · CWE-307 | Kritik9,8 | — | %9,8 | 22 Mar 2023 |
41Planlayın | CVE-2019-16701Kavram kanıtı | pfSense through 2.3.4 through 2.4.4-p3 allows Remote Code Injection via a methodCall XML document with a pfsense.exec_php call containing shnetgate · pfsense · CWE-78 | Yüksek8,8 | — | %19,6 | 25 Eyl 2019 |
41Planlayın | CVE-2019-12585İstismar yok | Apcupsd 0.3.91_5, as used in pfSense through 2.4.4-RELEASE-p3 and other products, has an Arbitrary Command Execution issue in apcupsd_statusapcupsd · apcupsd · CWE-78 | Kritik9,8 | — | %5,0 | 2 Haz 2019 |
40Planlayın | CVE-2019-8953Kavram kanıtı | The HAProxy package before 0.59_16 for pfSense has XSS via the desc (aka Description) or table_actionsaclN parameter, related to haproxy_lisnetgate · haproxy · CWE-79 | Orta6,1 | — | %52,2 | 20 Şub 2019 |
40Planlayın | CVE-2019-16915İstismar yok | An issue was discovered in pfSense through 2.4.4-p3.netgate · pfsense · CWE-22 | Kritik9,8 | — | %3,7 | 26 Eyl 2019 |
39İzleyin | CVE-2024-54780İstismar yok | Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds are vulnerable to command injection in the OpenVPN widget duenetgate · pfsense ce · CWE-94 | Yüksek8,8 | — | %12,4 | 14 May 2025 |
38İzleyin | CVE-2023-42325İstismar yok | Cross Site Scripting (XSS) vulnerability in Netgate pfSense v.2.7.0 allows a remote attacker to gain privileges via a crafted url to the stanetgate · pfsense · CWE-79 | Orta5,4 | — | %57,9 | 14 Kas 2023 |
38İzleyin | CVE-2023-42327İstismar yok | Cross Site Scripting (XSS) vulnerability in Netgate pfSense v.2.7.0 allows a remote attacker to gain privileges via a crafted URL to the getnetgate · pfsense · CWE-79 | Orta5,4 | — | %55,4 | 14 Kas 2023 |
38İzleyin | CVE-2018-16055İstismar yok | An authenticated command injection vulnerability exists in status_interfaces.php via dhcp_relinquish_lease() in pfSense before 2.4.4 due to netgate · pfsense · CWE-78 | Yüksek8,8 | — | %11,2 | 26 Eyl 2018 |
38İzleyin | CVE-2020-21487İstismar yok | Cross Site Scripting vulnerability found in Netgate pfSense 2.4.4 and ACME package v.0.6.3 allows attackers to execute arbitrary code via thnetgate · pfsense · CWE-79 | Kritik9,6 | — | %0,7 | 4 Nis 2023 |
36İzleyin | CVE-2022-26019İstismar yok | Improper access control vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions prior to 2.6.0 and pfSense Plus software netgate · pfsense · CWE-22 | Yüksek8,8 | — | %4,5 | 31 Mar 2022 |
- CVE-2022-3181467Bu hafta
pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metacharacters in the HTTP H
KritikCVSS 9,8SilahlaştırılmışEPSS %92netgate · pfblockerng5 Eyl 2022
- CVE-2023-2725362Bu hafta
A command injection vulnerability in the function restore_rrddata() of Netgate pfSense v2.7.0 allows authenticated attackers to execute arbi
YüksekCVSS 8,8SilahlaştırılmışEPSS %90netgate · pfsense17 Mar 2023
- CVE-2023-4812355Planlayın
An issue in Netgate pfSense Plus v.23.05.1 and before and pfSense CE v.2.7.0 allows a remote attacker to execute arbitrary code via a crafte
YüksekCVSS 8,8Kavram kanıtıEPSS %68netgate · pfsense6 Ara 2023
- CVE-2023-4232654Planlayın
An issue in Netgate pfSense v.2.7.0 allows a remote attacker to execute arbitrary code via a crafted request to the interfaces_gif_edit.php
YüksekCVSS 8,8Kavram kanıtıEPSS %64netgate · pfsense14 Kas 2023
- CVE-2023-4879551Planlayın
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypas
OrtaCVSS 5,9Kavram kanıtıEPSS %94ssh · ssh18 Ara 2023
- CVE-2019-1666751Planlayın
diag_command.php in pfSense 2.4.4-p3 allows CSRF via the txtCommand or txtRecallBuffer field, as demonstrated by executing OS commands.
YüksekCVSS 8,8Kavram kanıtıEPSS %55netgate · pfsense26 Eyl 2019
- CVE-2018-402150Planlayın
An exploitable command injection vulnerability exists in the way Netgate pfSense CE 2.4.4-RELEASE processes the parameters of a specific POS
YüksekCVSS 7,2İstismar yokEPSS %72netgate · pfsense3 Ara 2018
- CVE-2015-229547Planlayın
Cross-site request forgery (CSRF) vulnerability in system_firmware_restorefullbackup.php in the WebGUI in pfSense before 2.2.1 allows remote
OrtaCVSS 6,8Kavram kanıtıEPSS %66netgate · pfsense10 Nis 2015
- CVE-2017-100047945Planlayın
pfSense versions 2.4.1 and lower are vulnerable to clickjacking attacks in the CSRF error page resulting in privileged execution of arbitrar
YüksekCVSS 8,8SilahlaştırılmışEPSS %32netgate · pfsense3 Oca 2018
- CVE-2024-4653843Planlayın
A cross-site scripting (XSS) vulnerability in pfsense v2.5.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload
OrtaCVSS 4,8Kavram kanıtıEPSS %82netgate · pfsense22 Eki 2024
- CVE-2018-401943Planlayın
An exploitable command injection vulnerability exists in the way Netgate pfSense CE 2.4.4-RELEASE processes the parameters of a specific POS
YüksekCVSS 7,2İstismar yokEPSS %49netgate · pfsense3 Ara 2018
- CVE-2018-402043Planlayın
An exploitable command injection vulnerability exists in the way Netgate pfSense CE 2.4.4-RELEASE processes the parameters of a specific POS
YüksekCVSS 7,2İstismar yokEPSS %49netgate · pfsense3 Ara 2018
- CVE-2022-2927342Planlayın
pfSense CE through 2.6.0 and pfSense Plus before 22.05 allow XSS in the WebGUI via URL Table Alias URL parameters.
OrtaCVSS 6,1İstismar yokEPSS %60netgate · pfsense22 Şub 2023
- CVE-2019-1234742Planlayın
In pfSense 2.4.4-p3, a stored XSS vulnerability occurs when attackers inject a payload into the Name or Description field via an acme_accoun
OrtaCVSS 6,1Kavram kanıtıEPSS %59netgate · pfsense29 May 2019
- CVE-2023-2710042Planlayın
Improper restriction of excessive authentication attempts in the SSHGuard component of Netgate pfSense Plus software v22.05.1 and pfSense CE
KritikCVSS 9,8Kavram kanıtıEPSS %10netgate · pfsense plus22 Mar 2023
- CVE-2019-1670141Planlayın
pfSense through 2.3.4 through 2.4.4-p3 allows Remote Code Injection via a methodCall XML document with a pfsense.exec_php call containing sh
YüksekCVSS 8,8Kavram kanıtıEPSS %20netgate · pfsense25 Eyl 2019
- CVE-2019-1258541Planlayın
Apcupsd 0.3.91_5, as used in pfSense through 2.4.4-RELEASE-p3 and other products, has an Arbitrary Command Execution issue in apcupsd_status
KritikCVSS 9,8İstismar yokEPSS %5apcupsd · apcupsd2 Haz 2019
- CVE-2019-895340Planlayın
The HAProxy package before 0.59_16 for pfSense has XSS via the desc (aka Description) or table_actionsaclN parameter, related to haproxy_lis
OrtaCVSS 6,1Kavram kanıtıEPSS %52netgate · haproxy20 Şub 2019
- CVE-2019-1691540Planlayın
An issue was discovered in pfSense through 2.4.4-p3.
KritikCVSS 9,8İstismar yokEPSS %4netgate · pfsense26 Eyl 2019
- CVE-2024-5478039İzleyin
Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds are vulnerable to command injection in the OpenVPN widget due
YüksekCVSS 8,8İstismar yokEPSS %12netgate · pfsense ce14 May 2025
- CVE-2023-4232538İzleyin
Cross Site Scripting (XSS) vulnerability in Netgate pfSense v.2.7.0 allows a remote attacker to gain privileges via a crafted url to the sta
OrtaCVSS 5,4İstismar yokEPSS %58netgate · pfsense14 Kas 2023
- CVE-2023-4232738İzleyin
Cross Site Scripting (XSS) vulnerability in Netgate pfSense v.2.7.0 allows a remote attacker to gain privileges via a crafted URL to the get
OrtaCVSS 5,4İstismar yokEPSS %55netgate · pfsense14 Kas 2023
- CVE-2018-1605538İzleyin
An authenticated command injection vulnerability exists in status_interfaces.php via dhcp_relinquish_lease() in pfSense before 2.4.4 due to
YüksekCVSS 8,8İstismar yokEPSS %11netgate · pfsense26 Eyl 2018
- CVE-2020-2148738İzleyin
Cross Site Scripting vulnerability found in Netgate pfSense 2.4.4 and ACME package v.0.6.3 allows attackers to execute arbitrary code via th
KritikCVSS 9,6İstismar yokEPSS %1netgate · pfsense4 Nis 2023
- CVE-2022-2601936İzleyin
Improper access control vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions prior to 2.6.0 and pfSense Plus software
YüksekCVSS 8,8İstismar yokEPSS %4netgate · pfsense31 Mar 2022