Netgate records
59 published records for vendor netgate.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 3 · 5.1%
- Pre-auth RCE
- 6
- With a fix record
- 5.1%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')27
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')7
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')4
- CWE-352 Cross-Site Request Forgery (CSRF)3
- CWE-428 Unquoted Search Path or Element2
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
59 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
67This week | CVE-2022-31814Weaponized | pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metacharacters in the HTTP Hnetgate · pfblockerng · CWE-78 | Critical9.8 | — | 91.9% | Sep 5, 2022 |
62This week | CVE-2023-27253Weaponized | A command injection vulnerability in the function restore_rrddata() of Netgate pfSense v2.7.0 allows authenticated attackers to execute arbinetgate · pfsense · CWE-91 | High8.8 | — | 89.5% | Mar 17, 2023 |
55Plan | CVE-2023-48123Proof of concept | An issue in Netgate pfSense Plus v.23.05.1 and before and pfSense CE v.2.7.0 allows a remote attacker to execute arbitrary code via a craftenetgate · pfsense | High8.8 | — | 67.8% | Dec 6, 2023 |
54Plan | CVE-2023-42326Proof of concept | An issue in Netgate pfSense v.2.7.0 allows a remote attacker to execute arbitrary code via a crafted request to the interfaces_gif_edit.php netgate · pfsense · CWE-77 | High8.8 | — | 64.0% | Nov 14, 2023 |
51Plan | CVE-2023-48795Proof of concept | The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypasssh · ssh · CWE-354 | Medium5.9 | — | 93.5% | Dec 18, 2023 |
51Plan | CVE-2019-16667Proof of concept | diag_command.php in pfSense 2.4.4-p3 allows CSRF via the txtCommand or txtRecallBuffer field, as demonstrated by executing OS commands.netgate · pfsense · CWE-352 | High8.8 | — | 54.5% | Sep 26, 2019 |
50Plan | CVE-2018-4021No exploit | An exploitable command injection vulnerability exists in the way Netgate pfSense CE 2.4.4-RELEASE processes the parameters of a specific POSnetgate · pfsense · CWE-78 | High7.2 | — | 72.2% | Dec 3, 2018 |
47Plan | CVE-2015-2295Proof of concept | Cross-site request forgery (CSRF) vulnerability in system_firmware_restorefullbackup.php in the WebGUI in pfSense before 2.2.1 allows remotenetgate · pfsense · CWE-352 | Medium6.8 | — | 65.7% | Apr 10, 2015 |
45Plan | CVE-2017-1000479Weaponized | pfSense versions 2.4.1 and lower are vulnerable to clickjacking attacks in the CSRF error page resulting in privileged execution of arbitrarnetgate · pfsense · CWE-352 | High8.8 | — | 31.7% | Jan 3, 2018 |
43Plan | CVE-2024-46538Proof of concept | A cross-site scripting (XSS) vulnerability in pfsense v2.5.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payloadnetgate · pfsense · CWE-79 | Medium4.8 | — | 81.6% | Oct 22, 2024 |
43Plan | CVE-2018-4019No exploit | An exploitable command injection vulnerability exists in the way Netgate pfSense CE 2.4.4-RELEASE processes the parameters of a specific POSnetgate · pfsense · CWE-78 | High7.2 | — | 48.7% | Dec 3, 2018 |
43Plan | CVE-2018-4020No exploit | An exploitable command injection vulnerability exists in the way Netgate pfSense CE 2.4.4-RELEASE processes the parameters of a specific POSnetgate · pfsense · CWE-78 | High7.2 | — | 48.7% | Dec 3, 2018 |
42Plan | CVE-2022-29273No exploit | pfSense CE through 2.6.0 and pfSense Plus before 22.05 allow XSS in the WebGUI via URL Table Alias URL parameters.netgate · pfsense · CWE-79 | Medium6.1 | — | 59.6% | Feb 22, 2023 |
42Plan | CVE-2019-12347Proof of concept | In pfSense 2.4.4-p3, a stored XSS vulnerability occurs when attackers inject a payload into the Name or Description field via an acme_accounnetgate · pfsense · CWE-79 | Medium6.1 | — | 58.6% | May 29, 2019 |
42Plan | CVE-2023-27100Proof of concept | Improper restriction of excessive authentication attempts in the SSHGuard component of Netgate pfSense Plus software v22.05.1 and pfSense CEnetgate · pfsense plus · CWE-307 | Critical9.8 | — | 9.8% | Mar 22, 2023 |
41Plan | CVE-2019-16701Proof of concept | pfSense through 2.3.4 through 2.4.4-p3 allows Remote Code Injection via a methodCall XML document with a pfsense.exec_php call containing shnetgate · pfsense · CWE-78 | High8.8 | — | 19.6% | Sep 25, 2019 |
41Plan | CVE-2019-12585No exploit | Apcupsd 0.3.91_5, as used in pfSense through 2.4.4-RELEASE-p3 and other products, has an Arbitrary Command Execution issue in apcupsd_statusapcupsd · apcupsd · CWE-78 | Critical9.8 | — | 5.0% | Jun 2, 2019 |
40Plan | CVE-2019-8953Proof of concept | The HAProxy package before 0.59_16 for pfSense has XSS via the desc (aka Description) or table_actionsaclN parameter, related to haproxy_lisnetgate · haproxy · CWE-79 | Medium6.1 | — | 52.2% | Feb 20, 2019 |
40Plan | CVE-2019-16915No exploit | An issue was discovered in pfSense through 2.4.4-p3.netgate · pfsense · CWE-22 | Critical9.8 | — | 3.7% | Sep 26, 2019 |
39Monitor | CVE-2024-54780No exploit | Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds are vulnerable to command injection in the OpenVPN widget duenetgate · pfsense ce · CWE-94 | High8.8 | — | 12.4% | May 14, 2025 |
38Monitor | CVE-2023-42325No exploit | Cross Site Scripting (XSS) vulnerability in Netgate pfSense v.2.7.0 allows a remote attacker to gain privileges via a crafted url to the stanetgate · pfsense · CWE-79 | Medium5.4 | — | 57.9% | Nov 14, 2023 |
38Monitor | CVE-2023-42327No exploit | Cross Site Scripting (XSS) vulnerability in Netgate pfSense v.2.7.0 allows a remote attacker to gain privileges via a crafted URL to the getnetgate · pfsense · CWE-79 | Medium5.4 | — | 55.4% | Nov 14, 2023 |
38Monitor | CVE-2018-16055No exploit | An authenticated command injection vulnerability exists in status_interfaces.php via dhcp_relinquish_lease() in pfSense before 2.4.4 due to netgate · pfsense · CWE-78 | High8.8 | — | 11.2% | Sep 26, 2018 |
38Monitor | CVE-2020-21487No exploit | Cross Site Scripting vulnerability found in Netgate pfSense 2.4.4 and ACME package v.0.6.3 allows attackers to execute arbitrary code via thnetgate · pfsense · CWE-79 | Critical9.6 | — | 0.7% | Apr 4, 2023 |
36Monitor | CVE-2022-26019No exploit | Improper access control vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions prior to 2.6.0 and pfSense Plus software netgate · pfsense · CWE-22 | High8.8 | — | 4.5% | Mar 31, 2022 |
- CVE-2022-3181467This week
pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metacharacters in the HTTP H
CriticalCVSS 9.8WeaponizedEPSS 92%netgate · pfblockerngSep 5, 2022
- CVE-2023-2725362This week
A command injection vulnerability in the function restore_rrddata() of Netgate pfSense v2.7.0 allows authenticated attackers to execute arbi
HighCVSS 8.8WeaponizedEPSS 90%netgate · pfsenseMar 17, 2023
- CVE-2023-4812355Plan
An issue in Netgate pfSense Plus v.23.05.1 and before and pfSense CE v.2.7.0 allows a remote attacker to execute arbitrary code via a crafte
HighCVSS 8.8Proof of conceptEPSS 68%netgate · pfsenseDec 6, 2023
- CVE-2023-4232654Plan
An issue in Netgate pfSense v.2.7.0 allows a remote attacker to execute arbitrary code via a crafted request to the interfaces_gif_edit.php
HighCVSS 8.8Proof of conceptEPSS 64%netgate · pfsenseNov 14, 2023
- CVE-2023-4879551Plan
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypas
MediumCVSS 5.9Proof of conceptEPSS 94%ssh · sshDec 18, 2023
- CVE-2019-1666751Plan
diag_command.php in pfSense 2.4.4-p3 allows CSRF via the txtCommand or txtRecallBuffer field, as demonstrated by executing OS commands.
HighCVSS 8.8Proof of conceptEPSS 55%netgate · pfsenseSep 26, 2019
- CVE-2018-402150Plan
An exploitable command injection vulnerability exists in the way Netgate pfSense CE 2.4.4-RELEASE processes the parameters of a specific POS
HighCVSS 7.2No exploitEPSS 72%netgate · pfsenseDec 3, 2018
- CVE-2015-229547Plan
Cross-site request forgery (CSRF) vulnerability in system_firmware_restorefullbackup.php in the WebGUI in pfSense before 2.2.1 allows remote
MediumCVSS 6.8Proof of conceptEPSS 66%netgate · pfsenseApr 10, 2015
- CVE-2017-100047945Plan
pfSense versions 2.4.1 and lower are vulnerable to clickjacking attacks in the CSRF error page resulting in privileged execution of arbitrar
HighCVSS 8.8WeaponizedEPSS 32%netgate · pfsenseJan 3, 2018
- CVE-2024-4653843Plan
A cross-site scripting (XSS) vulnerability in pfsense v2.5.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload
MediumCVSS 4.8Proof of conceptEPSS 82%netgate · pfsenseOct 22, 2024
- CVE-2018-401943Plan
An exploitable command injection vulnerability exists in the way Netgate pfSense CE 2.4.4-RELEASE processes the parameters of a specific POS
HighCVSS 7.2No exploitEPSS 49%netgate · pfsenseDec 3, 2018
- CVE-2018-402043Plan
An exploitable command injection vulnerability exists in the way Netgate pfSense CE 2.4.4-RELEASE processes the parameters of a specific POS
HighCVSS 7.2No exploitEPSS 49%netgate · pfsenseDec 3, 2018
- CVE-2022-2927342Plan
pfSense CE through 2.6.0 and pfSense Plus before 22.05 allow XSS in the WebGUI via URL Table Alias URL parameters.
MediumCVSS 6.1No exploitEPSS 60%netgate · pfsenseFeb 22, 2023
- CVE-2019-1234742Plan
In pfSense 2.4.4-p3, a stored XSS vulnerability occurs when attackers inject a payload into the Name or Description field via an acme_accoun
MediumCVSS 6.1Proof of conceptEPSS 59%netgate · pfsenseMay 29, 2019
- CVE-2023-2710042Plan
Improper restriction of excessive authentication attempts in the SSHGuard component of Netgate pfSense Plus software v22.05.1 and pfSense CE
CriticalCVSS 9.8Proof of conceptEPSS 10%netgate · pfsense plusMar 22, 2023
- CVE-2019-1670141Plan
pfSense through 2.3.4 through 2.4.4-p3 allows Remote Code Injection via a methodCall XML document with a pfsense.exec_php call containing sh
HighCVSS 8.8Proof of conceptEPSS 20%netgate · pfsenseSep 25, 2019
- CVE-2019-1258541Plan
Apcupsd 0.3.91_5, as used in pfSense through 2.4.4-RELEASE-p3 and other products, has an Arbitrary Command Execution issue in apcupsd_status
CriticalCVSS 9.8No exploitEPSS 5%apcupsd · apcupsdJun 2, 2019
- CVE-2019-895340Plan
The HAProxy package before 0.59_16 for pfSense has XSS via the desc (aka Description) or table_actionsaclN parameter, related to haproxy_lis
MediumCVSS 6.1Proof of conceptEPSS 52%netgate · haproxyFeb 20, 2019
- CVE-2019-1691540Plan
An issue was discovered in pfSense through 2.4.4-p3.
CriticalCVSS 9.8No exploitEPSS 4%netgate · pfsenseSep 26, 2019
- CVE-2024-5478039Monitor
Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds are vulnerable to command injection in the OpenVPN widget due
HighCVSS 8.8No exploitEPSS 12%netgate · pfsense ceMay 14, 2025
- CVE-2023-4232538Monitor
Cross Site Scripting (XSS) vulnerability in Netgate pfSense v.2.7.0 allows a remote attacker to gain privileges via a crafted url to the sta
MediumCVSS 5.4No exploitEPSS 58%netgate · pfsenseNov 14, 2023
- CVE-2023-4232738Monitor
Cross Site Scripting (XSS) vulnerability in Netgate pfSense v.2.7.0 allows a remote attacker to gain privileges via a crafted URL to the get
MediumCVSS 5.4No exploitEPSS 55%netgate · pfsenseNov 14, 2023
- CVE-2018-1605538Monitor
An authenticated command injection vulnerability exists in status_interfaces.php via dhcp_relinquish_lease() in pfSense before 2.4.4 due to
HighCVSS 8.8No exploitEPSS 11%netgate · pfsenseSep 26, 2018
- CVE-2020-2148738Monitor
Cross Site Scripting vulnerability found in Netgate pfSense 2.4.4 and ACME package v.0.6.3 allows attackers to execute arbitrary code via th
CriticalCVSS 9.6No exploitEPSS 1%netgate · pfsenseApr 4, 2023
- CVE-2022-2601936Monitor
Improper access control vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions prior to 2.6.0 and pfSense Plus software
HighCVSS 8.8No exploitEPSS 4%netgate · pfsenseMar 31, 2022