Skip to content
Noroxi

pfSense records

31 published records for vendor pfsense.

All records

31 records
  • CVE-2021-41282
    61This week

    diag_routes.php in pfSense 2.5.2 allows sed data injection.

    HighCVSS 8.8WeaponizedEPSS 87%

    pfsense · pfsenseMar 1, 2022

  • pfSense before 2.3 allows remote authenticated users to execute arbitrary OS commands via a '|' character in the status_rrd_graph_img.php gr

    HighCVSS 8.8WeaponizedEPSS 34%

    pfsense · pfsenseJan 22, 2018

  • pfSense pfBlockerNG through 2.1.4_27 allows remote attackers to execute arbitrary OS commands as root via the HTTP Host header, a different

    CriticalCVSS 9.8Proof of conceptEPSS 17%

    pfsense · pfblockerngDec 20, 2022

  • Improper restriction of excessive authentication attempts in the SSHGuard component of Netgate pfSense Plus software v22.05.1 and pfSense CE

    CriticalCVSS 9.8Proof of conceptEPSS 10%

    netgate · pfsense plusMar 22, 2023

  • An issue discovered in Pfsense CE version 2.6.0 allows attackers to compromise user accounts via weak password requirements.

    CriticalCVSS 9.8No exploitEPSS 2%

    pfsense · pfsenseNov 8, 2023

  • Netgate pfSense CE 2.8.0 allows code execution in the XMLRPC API via pfsense.exec_php.

    CriticalCVSS 9.9No exploitEPSS 1%

    pfsense · pfsenseMay 8, 2026

  • Netgate pfSense CE 2.7.2 allows code execution by using the module installer with a backup file with a serialized PHP object containing the

    CriticalCVSS 9.1Proof of conceptEPSS 1%

    pfsense · pfsenseMay 8, 2026

  • pfSense 2.5.0 allows XSS via the services_wol_edit.php Description field.

    MediumCVSS 6.1No exploitEPSS 27%

    pfsense · pfsenseApr 28, 2021

  • Directory Traversal vulnerability found in Pfsense v.2.1.3 and Pfsense Suricata v.1.4.6 pkg v.1.0.1 allows a remote attacker to obtain sensi

    HighCVSS 7.5No exploitEPSS 3%

    pfsense · pfsenseApr 6, 2023

  • CVE-2011-4197
    31Monitor

    etc/inc/certs.inc in the PKI implementation in pfSense before 2.0.1 creates each X.509 certificate with a true value for the CA basic constr

    HighCVSS 7.5No exploitEPSS 2%

    pfsense · pfsenseJan 3, 2012

  • An issue discovered in Pfsense CE version 2.6.0 allows attackers to change the password of any user without verification.

    HighCVSS 7.2No exploitEPSS 2%

    pfsense · pfsenseNov 9, 2023

  • In Netgate pfSense CE 2.8.0, the "WebCfg - Diagnostics: Command" privilege allows reading arbitrary files via diag_command.php dlPath direct

    MediumCVSS 6.5Proof of conceptEPSS 2%

    pfsense · pfsenseJun 28, 2025

  • Directory traversal vulnerability in pfSense-pkg-WireGuard pfSense-pkg-WireGuard 0.1.5 versions prior to 0.1.5_4 and pfSense-pkg-WireGuard 0

    MediumCVSS 6.5No exploitEPSS 2%

    pfsense · pfsense-pkg-wireguardMar 10, 2022

  • Netgate pfSense CE Suricata Package v7.0.8_2 Directory Traversal Information Disclosure

    MediumCVSS 5.3No exploitEPSS 16%

    pfsense · pfsenseSep 9, 2025

  • Netgate pfSense CE Suricata package v7.0.8_2 Reflected Cross-Site Scripting

    MediumCVSS 5.1No exploitEPSS 16%

    pfsense · pfsenseSep 9, 2025

  • /usr/local/www/freeradius_view_config.php in the freeradius3 package before 0.15.7_3 for pfSense on FreeBSD allows a user with an XSS payloa

    MediumCVSS 6.1No exploitEPSS 4%

    pfsense · pfsense-pkg-freeradius3Nov 2, 2019

  • Cross-site scripting vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions 2.5.2 and earlier, and pfSense Plus software

    MediumCVSS 6.1No exploitEPSS 3%

    pfsense · pfsenseMar 31, 2022

  • pfSense v2.5.2 was discovered to contain a cross-site scripting (XSS) vulnerability in the browser.php component.

    MediumCVSS 6.1No exploitEPSS 3%

    pfsense · pfsenseOct 3, 2022

  • CVE-2014-4696
    24Monitor

    Multiple open redirect vulnerabilities in the Suricata package before 1.0.6 for pfSense through 2.1.4 allow remote attackers to redirect use

    MediumCVSS 5.8No exploitEPSS 2%

    pfsense · suricata packageJul 2, 2014

  • CVE-2014-4695
    24Monitor

    Multiple open redirect vulnerabilities in the Snort package before 3.0.13 for pfSense through 2.1.4 allow remote attackers to redirect users

    MediumCVSS 5.8No exploitEPSS 2%

    pfsense · snort packageJul 2, 2014

  • /usr/local/www/pkg.php in pfSense CE before 2.6.0 and pfSense Plus before 22.01 uses $_REQUEST['pkg_filter'] in a PHP echo call, causing XSS

    MediumCVSS 6.1No exploitEPSS 2%

    pfsense · pfsenseJan 26, 2022

  • Netgate pfSense CE Status_Traffic_Totals Package v2.3.2_7 Stored Cross-Site Scripting

    MediumCVSS 5.1No exploitEPSS 10%

    pfsense · pfsenseSep 9, 2025

  • A stored cross-site scripting (XSS) vulnerability was discovered in pfSense 2.4.5-p1 which allows an authenticated attacker to execute arbit

    MediumCVSS 5.4No exploitEPSS 5%

    pfsense · pfsenseJun 1, 2021

  • Netgate pfSense CE Suricata package v7.0.8_2 Stored Cross-Site Scripting

    MediumCVSS 5.1No exploitEPSS 4%

    pfsense · pfsenseSep 9, 2025

  • Netgate pfSense CE Snort package v4.1.6_25 Directory Traversal Information Disclosure

    MediumCVSS 5.3No exploitEPSS 1%

    pfsense · pfsenseSep 9, 2025