İçeriğe atla
Noroxi

Netgate kayıtları

netgate üreticisine ait 59 yayımlanmış kayıt.

Tüm kayıtlar

59 kayıt
  • CVE-2022-31814
    67Bu hafta

    pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metacharacters in the HTTP H

    KritikCVSS 9,8SilahlaştırılmışEPSS %92

    netgate · pfblockerng5 Eyl 2022

  • CVE-2023-27253
    62Bu hafta

    A command injection vulnerability in the function restore_rrddata() of Netgate pfSense v2.7.0 allows authenticated attackers to execute arbi

    YüksekCVSS 8,8SilahlaştırılmışEPSS %90

    netgate · pfsense17 Mar 2023

  • CVE-2023-48123
    55Planlayın

    An issue in Netgate pfSense Plus v.23.05.1 and before and pfSense CE v.2.7.0 allows a remote attacker to execute arbitrary code via a crafte

    YüksekCVSS 8,8Kavram kanıtıEPSS %68

    netgate · pfsense6 Ara 2023

  • CVE-2023-42326
    54Planlayın

    An issue in Netgate pfSense v.2.7.0 allows a remote attacker to execute arbitrary code via a crafted request to the interfaces_gif_edit.php

    YüksekCVSS 8,8Kavram kanıtıEPSS %64

    netgate · pfsense14 Kas 2023

  • CVE-2023-48795
    51Planlayın

    The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypas

    OrtaCVSS 5,9Kavram kanıtıEPSS %94

    ssh · ssh18 Ara 2023

  • CVE-2019-16667
    51Planlayın

    diag_command.php in pfSense 2.4.4-p3 allows CSRF via the txtCommand or txtRecallBuffer field, as demonstrated by executing OS commands.

    YüksekCVSS 8,8Kavram kanıtıEPSS %55

    netgate · pfsense26 Eyl 2019

  • CVE-2018-4021
    50Planlayın

    An exploitable command injection vulnerability exists in the way Netgate pfSense CE 2.4.4-RELEASE processes the parameters of a specific POS

    YüksekCVSS 7,2İstismar yokEPSS %72

    netgate · pfsense3 Ara 2018

  • CVE-2015-2295
    47Planlayın

    Cross-site request forgery (CSRF) vulnerability in system_firmware_restorefullbackup.php in the WebGUI in pfSense before 2.2.1 allows remote

    OrtaCVSS 6,8Kavram kanıtıEPSS %66

    netgate · pfsense10 Nis 2015

  • CVE-2017-1000479
    45Planlayın

    pfSense versions 2.4.1 and lower are vulnerable to clickjacking attacks in the CSRF error page resulting in privileged execution of arbitrar

    YüksekCVSS 8,8SilahlaştırılmışEPSS %32

    netgate · pfsense3 Oca 2018

  • CVE-2024-46538
    43Planlayın

    A cross-site scripting (XSS) vulnerability in pfsense v2.5.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload

    OrtaCVSS 4,8Kavram kanıtıEPSS %82

    netgate · pfsense22 Eki 2024

  • CVE-2018-4019
    43Planlayın

    An exploitable command injection vulnerability exists in the way Netgate pfSense CE 2.4.4-RELEASE processes the parameters of a specific POS

    YüksekCVSS 7,2İstismar yokEPSS %49

    netgate · pfsense3 Ara 2018

  • CVE-2018-4020
    43Planlayın

    An exploitable command injection vulnerability exists in the way Netgate pfSense CE 2.4.4-RELEASE processes the parameters of a specific POS

    YüksekCVSS 7,2İstismar yokEPSS %49

    netgate · pfsense3 Ara 2018

  • CVE-2022-29273
    42Planlayın

    pfSense CE through 2.6.0 and pfSense Plus before 22.05 allow XSS in the WebGUI via URL Table Alias URL parameters.

    OrtaCVSS 6,1İstismar yokEPSS %60

    netgate · pfsense22 Şub 2023

  • CVE-2019-12347
    42Planlayın

    In pfSense 2.4.4-p3, a stored XSS vulnerability occurs when attackers inject a payload into the Name or Description field via an acme_accoun

    OrtaCVSS 6,1Kavram kanıtıEPSS %59

    netgate · pfsense29 May 2019

  • CVE-2023-27100
    42Planlayın

    Improper restriction of excessive authentication attempts in the SSHGuard component of Netgate pfSense Plus software v22.05.1 and pfSense CE

    KritikCVSS 9,8Kavram kanıtıEPSS %10

    netgate · pfsense plus22 Mar 2023

  • CVE-2019-16701
    41Planlayın

    pfSense through 2.3.4 through 2.4.4-p3 allows Remote Code Injection via a methodCall XML document with a pfsense.exec_php call containing sh

    YüksekCVSS 8,8Kavram kanıtıEPSS %20

    netgate · pfsense25 Eyl 2019

  • CVE-2019-12585
    41Planlayın

    Apcupsd 0.3.91_5, as used in pfSense through 2.4.4-RELEASE-p3 and other products, has an Arbitrary Command Execution issue in apcupsd_status

    KritikCVSS 9,8İstismar yokEPSS %5

    apcupsd · apcupsd2 Haz 2019

  • CVE-2019-8953
    40Planlayın

    The HAProxy package before 0.59_16 for pfSense has XSS via the desc (aka Description) or table_actionsaclN parameter, related to haproxy_lis

    OrtaCVSS 6,1Kavram kanıtıEPSS %52

    netgate · haproxy20 Şub 2019

  • CVE-2019-16915
    40Planlayın

    An issue was discovered in pfSense through 2.4.4-p3.

    KritikCVSS 9,8İstismar yokEPSS %4

    netgate · pfsense26 Eyl 2019

  • CVE-2024-54780
    39İzleyin

    Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds are vulnerable to command injection in the OpenVPN widget due

    YüksekCVSS 8,8İstismar yokEPSS %12

    netgate · pfsense ce14 May 2025

  • CVE-2023-42325
    38İzleyin

    Cross Site Scripting (XSS) vulnerability in Netgate pfSense v.2.7.0 allows a remote attacker to gain privileges via a crafted url to the sta

    OrtaCVSS 5,4İstismar yokEPSS %58

    netgate · pfsense14 Kas 2023

  • CVE-2023-42327
    38İzleyin

    Cross Site Scripting (XSS) vulnerability in Netgate pfSense v.2.7.0 allows a remote attacker to gain privileges via a crafted URL to the get

    OrtaCVSS 5,4İstismar yokEPSS %55

    netgate · pfsense14 Kas 2023

  • CVE-2018-16055
    38İzleyin

    An authenticated command injection vulnerability exists in status_interfaces.php via dhcp_relinquish_lease() in pfSense before 2.4.4 due to

    YüksekCVSS 8,8İstismar yokEPSS %11

    netgate · pfsense26 Eyl 2018

  • CVE-2020-21487
    38İzleyin

    Cross Site Scripting vulnerability found in Netgate pfSense 2.4.4 and ACME package v.0.6.3 allows attackers to execute arbitrary code via th

    KritikCVSS 9,6İstismar yokEPSS %1

    netgate · pfsense4 Nis 2023

  • CVE-2022-26019
    36İzleyin

    Improper access control vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions prior to 2.6.0 and pfSense Plus software

    YüksekCVSS 8,8İstismar yokEPSS %4

    netgate · pfsense31 Mar 2022