Skip to content
Noroxi

Netgate records

59 published records for vendor netgate.

All records

59 records
  • CVE-2022-31814
    67This week

    pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metacharacters in the HTTP H

    CriticalCVSS 9.8WeaponizedEPSS 92%

    netgate · pfblockerngSep 5, 2022

  • CVE-2023-27253
    62This week

    A command injection vulnerability in the function restore_rrddata() of Netgate pfSense v2.7.0 allows authenticated attackers to execute arbi

    HighCVSS 8.8WeaponizedEPSS 90%

    netgate · pfsenseMar 17, 2023

  • An issue in Netgate pfSense Plus v.23.05.1 and before and pfSense CE v.2.7.0 allows a remote attacker to execute arbitrary code via a crafte

    HighCVSS 8.8Proof of conceptEPSS 68%

    netgate · pfsenseDec 6, 2023

  • An issue in Netgate pfSense v.2.7.0 allows a remote attacker to execute arbitrary code via a crafted request to the interfaces_gif_edit.php

    HighCVSS 8.8Proof of conceptEPSS 64%

    netgate · pfsenseNov 14, 2023

  • The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypas

    MediumCVSS 5.9Proof of conceptEPSS 94%

    ssh · sshDec 18, 2023

  • diag_command.php in pfSense 2.4.4-p3 allows CSRF via the txtCommand or txtRecallBuffer field, as demonstrated by executing OS commands.

    HighCVSS 8.8Proof of conceptEPSS 55%

    netgate · pfsenseSep 26, 2019

  • An exploitable command injection vulnerability exists in the way Netgate pfSense CE 2.4.4-RELEASE processes the parameters of a specific POS

    HighCVSS 7.2No exploitEPSS 72%

    netgate · pfsenseDec 3, 2018

  • Cross-site request forgery (CSRF) vulnerability in system_firmware_restorefullbackup.php in the WebGUI in pfSense before 2.2.1 allows remote

    MediumCVSS 6.8Proof of conceptEPSS 66%

    netgate · pfsenseApr 10, 2015

  • pfSense versions 2.4.1 and lower are vulnerable to clickjacking attacks in the CSRF error page resulting in privileged execution of arbitrar

    HighCVSS 8.8WeaponizedEPSS 32%

    netgate · pfsenseJan 3, 2018

  • A cross-site scripting (XSS) vulnerability in pfsense v2.5.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload

    MediumCVSS 4.8Proof of conceptEPSS 82%

    netgate · pfsenseOct 22, 2024

  • An exploitable command injection vulnerability exists in the way Netgate pfSense CE 2.4.4-RELEASE processes the parameters of a specific POS

    HighCVSS 7.2No exploitEPSS 49%

    netgate · pfsenseDec 3, 2018

  • An exploitable command injection vulnerability exists in the way Netgate pfSense CE 2.4.4-RELEASE processes the parameters of a specific POS

    HighCVSS 7.2No exploitEPSS 49%

    netgate · pfsenseDec 3, 2018

  • pfSense CE through 2.6.0 and pfSense Plus before 22.05 allow XSS in the WebGUI via URL Table Alias URL parameters.

    MediumCVSS 6.1No exploitEPSS 60%

    netgate · pfsenseFeb 22, 2023

  • In pfSense 2.4.4-p3, a stored XSS vulnerability occurs when attackers inject a payload into the Name or Description field via an acme_accoun

    MediumCVSS 6.1Proof of conceptEPSS 59%

    netgate · pfsenseMay 29, 2019

  • Improper restriction of excessive authentication attempts in the SSHGuard component of Netgate pfSense Plus software v22.05.1 and pfSense CE

    CriticalCVSS 9.8Proof of conceptEPSS 10%

    netgate · pfsense plusMar 22, 2023

  • pfSense through 2.3.4 through 2.4.4-p3 allows Remote Code Injection via a methodCall XML document with a pfsense.exec_php call containing sh

    HighCVSS 8.8Proof of conceptEPSS 20%

    netgate · pfsenseSep 25, 2019

  • Apcupsd 0.3.91_5, as used in pfSense through 2.4.4-RELEASE-p3 and other products, has an Arbitrary Command Execution issue in apcupsd_status

    CriticalCVSS 9.8No exploitEPSS 5%

    apcupsd · apcupsdJun 2, 2019

  • The HAProxy package before 0.59_16 for pfSense has XSS via the desc (aka Description) or table_actionsaclN parameter, related to haproxy_lis

    MediumCVSS 6.1Proof of conceptEPSS 52%

    netgate · haproxyFeb 20, 2019

  • An issue was discovered in pfSense through 2.4.4-p3.

    CriticalCVSS 9.8No exploitEPSS 4%

    netgate · pfsenseSep 26, 2019

  • Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds are vulnerable to command injection in the OpenVPN widget due

    HighCVSS 8.8No exploitEPSS 12%

    netgate · pfsense ceMay 14, 2025

  • Cross Site Scripting (XSS) vulnerability in Netgate pfSense v.2.7.0 allows a remote attacker to gain privileges via a crafted url to the sta

    MediumCVSS 5.4No exploitEPSS 58%

    netgate · pfsenseNov 14, 2023

  • Cross Site Scripting (XSS) vulnerability in Netgate pfSense v.2.7.0 allows a remote attacker to gain privileges via a crafted URL to the get

    MediumCVSS 5.4No exploitEPSS 55%

    netgate · pfsenseNov 14, 2023

  • An authenticated command injection vulnerability exists in status_interfaces.php via dhcp_relinquish_lease() in pfSense before 2.4.4 due to

    HighCVSS 8.8No exploitEPSS 11%

    netgate · pfsenseSep 26, 2018

  • Cross Site Scripting vulnerability found in Netgate pfSense 2.4.4 and ACME package v.0.6.3 allows attackers to execute arbitrary code via th

    CriticalCVSS 9.6No exploitEPSS 1%

    netgate · pfsenseApr 4, 2023

  • Improper access control vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions prior to 2.6.0 and pfSense Plus software

    HighCVSS 8.8No exploitEPSS 4%

    netgate · pfsenseMar 31, 2022